Can Apple retroactively identify apps that might have exploited these vulnerabilities to exfiltrate personal data? In my understanding they receive the full source code of an app for review, so they probably have an archive with all revisions that they could go through using automated tools to identify exploit code? Would be good to know if these exploits have been used in the wild, being able to exfiltrate the entir…
There is no way they could prove that an app HASN'T exploited this. They don't get source code, only compiled binaries, and with objective-c's extremely dynamic nature, any app could technically receive a HTTP response containing strings containing class and method names to dynamically look up and invoke, maybe even based on the app's IP address or only on specific dates. So calls to these exploitable APIs could have…
Disclosure of three 0-day iOS vulnerabilities
341–350 of 464 posts
Re: Disclosure of three 0-day iOS vulnerabilities
#342I'm not defending Apple but looking at the code published here, it's clear that most, if not all, of these bugs could be caught via static analysis which Apple obviously uses as part of its approval process. Frankly, I'm a lot more concerned with bugs that have to deal with input handling than SDK bugs that developers can use to do bad things. This is likely a non-issue for those of us who haven't jailbroken our devi…
This analysis is a joke, it just scans strings inside binaries against the list of symbols corresponding to what Apple considers to be Private API. Gamed exploit can be uploaded to the App Store and binary will pass their analysis with flying colors
Re: Disclosure of three 0-day iOS vulnerabilities
#343Re: Disclosure of three 0-day iOS vulnerabilities
#344This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…
Besides, why focus on something as superficial as keeping your private data safe when the new iPhone now comes in a gorgeous pink finish. And with Ceramic Shield and the lightning-fast A15 chip? It’s truly the best iPhone they’ve ever made.
These puppies sell themselves without all that expensive privacy talk.
Honestly their attitude to the bug bounty makes me wonder if there’s not a small group of engineers that keep screaming about this problem just to have the door closed behind them and a “lol nerds” giggle heard from the execs on the other side of the door.
Re: Disclosure of three 0-day iOS vulnerabilities
#345Earlier quoted context omitted.
There is no way they could prove that an app HASN'T exploited this. They don't get source code, only compiled binaries, and with objective-c's extremely dynamic nature, any app could technically receive a HTTP response containing strings containing class and method names to dynamically look up and invoke, maybe even based on the app's IP address or only on specific dates. So calls to these exploitable APIs could have…
Furthermore, no one stops you from developing an app and planting RCE vulnerability inside the binary. Then you can exploit it remotely when necessary and execute the code that exploits any iOS vulnerabilities known to you.
Re: Disclosure of three 0-day iOS vulnerabilities
#346At least the Game Center one is something an app developer could easily stumble upon. I don’t want to know how many apps are already exploiting this.
Re: Disclosure of three 0-day iOS vulnerabilities
#347If your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data leaking vulnerabilities within 90 days, or pay out everyone who bought your product. I just updated to iOS 15 and it now tells you which sites you have been compromised on, or had your passwords/info compromised on. To be clear, I use a password manager with a…
Hang on, you have a coffee machine that is capable of being compromised? How exactly? Further to this, you claim that you have been compromised on HUNDREDS of sites even though you use a unique password everywhere? How is this happening to you? Isn't this a huge concern?
It’s not too far-fetched.
I’ve been compromised on dozens of sites out of ~1.500 sites on which I have accounts, all of them with unique email addresses and unique passwords. Those dozens accounts are just those I happen to know about (through HIBP, incoming email spam, or the occasional site owner’s disclosure) so they’re probably just the tip of the iceberg.
Sites are being breached left and right. If you’re lucky, the site owner tells you. Many won’t.
Re: Disclosure of three 0-day iOS vulnerabilities
#348Earlier quoted context omitted.
> recently the wealthiest company on the planet … They could slow down their software development process, focus less on adding new features, and prioritize fewer security holes. My inner cynic¹ has a slightly different take on that: You don't get to be the wealthiest company on the planet by doing the right thing at the expense of the profitable things. ¹ He says, pretending it isn't also his outer and all-consuming…
Ah, then the cynical part of you will recognize that selling a widget is more lucrative then avoiding the loss of someone else's private data. Or at least that's what I just realized.
Re: Disclosure of three 0-day iOS vulnerabilities
#349Until we understand and push through a system (whether law or practice) that makes harming others, especially against their will and intentionally, far more costly than the massive returns and profits they today produce, NONE of these kinds of behaviors will ever cease. The examples are numerous; * Violation of human right to privacy and property * Violation of human right to not being tracked * Illegitimate wars * P…
I’m convinced that the modern role of US political parties is to simply keep the masses squabbling. I wish we could get rid of gerrymandering and the two party dominance.
Re: Disclosure of three 0-day iOS vulnerabilities
#350Earlier quoted context omitted.
This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…
I hate blaming people and pointing fingers. It seems to me, that the current CEO, who was the CFO at the same company before, would be well advised to drop the "numbers & metrics" MBA mindset. Written five years ago but sadly still relevant: https://steveblank.com/2016/10/24/why-tim-cook-is-steve-ball...