Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

361–370 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#361

With these Apple-related vulnerability annoucements on HN, usually we see response from a satisified Apple owner along the lines of "This is fixed in [some new version number]". The thing is, the problem isnt whether something is fixed, its that it was broken to begin with. It passed "QA" at a trillion dollar company and its a pre-installed fixture^1 on some relatively expensive hardware item. If there is such an "it…

No os/mobile platform is free of security bugs. No amount of “QA” will be enough. Just look at the number of vulnerabilities literally any OS has, or even any component such as Chrome or Safari.

It is a shame that the author didn’t get replies in time and felt the need to disclose. I’m sure it’ll at least get quickly patched now.

Re: Disclosure of three 0-day iOS vulnerabilities

#362
post #339
post #238

Earlier quoted context omitted.

The whole point of Swift is to be next generation Objective-C and C on Apple platforms, no need to drop down to other languages. In fact, the prof of concepts shown in the article are all written in Swift.

I wasn't clear. It is dynamically constructing an API call that Objective-C allows. The objc_msgSend stuff.

Which you can call directly from Swift.

Re: Disclosure of three 0-day iOS vulnerabilities

#363

Earlier quoted context omitted.

So, is this the lack of grandmas working at Apple in software development? This is nothing you can fix by following some diversity ideology. This is a question of respecting different requirements from different user groups. You cannot mirror every user group in the development teams. How do you represent people of old age, with illnesses, or certain disabilities in a development team? How do you represent people liv…

Now that you mention it, I think there's a real lack of grandmas in tech... maybe I shouldn't be saying this publicly, but we don't have any at our company.

One of our product managers is a grandmother (she is actually taking an early retirement soon because her 4th grandchild is on the way).

We are in the B2B/B2EDU space so the "As a grandmother, I think..." line of thought does not apply. However, she has frequently had insights and observations that none of us would have come up with. Once implemented, they have been very successful/profitable.

So yes, absolutely, unless your company wants to be in a very specific niche, the lack of true diversity in your company is a drag on your success.

PS - my grandfather had a tech job in Sunnyvale. He passed away last year at the age of 92. Point is - everyone alive has lived in a world with pervasive technology and computing. "They're old and can't understand this stuff" is pure BS.

Re: Disclosure of three 0-day iOS vulnerabilities

#364
> ... one was fixed in 14.7, but Apple decided to cover it up and not list it on the security content page. When I confronted them, they apologized, assured me it happened due to a processing issue and promised to list it on the security content page of the next update. There were three releases since then and they broke their promise each time.

I think this is 100% intentional.

Re: Disclosure of three 0-day iOS vulnerabilities

#365
post #352
post #281

Earlier quoted context omitted.

I understand the change would be a patch, but that's separate from the question of how you encode and ship it, surely? How are you suggesting a small patch would be shipped?

In the simplest way, not unlike Windows Update: snapshot filesystem, start filesystem transaction, unzip changed binary files, check new files integrity, end transaction. Indeed, Apple used to distribute patches this way in the past. You also could ship a list of updated system files hashes, compare to the installed files and just download the changed ones, like rsync. Better than shipping a whole new disk image ever…

Yeah, I'm sure it's theoretically doable, but it's one of those things which would almost certainly require substantial work given the massively complex edifice of iOS. (And the iOS IPSW format, or even iOS DMGs/ADIs, are very different from the OS X patches you mentioned.)

Re: Disclosure of three 0-day iOS vulnerabilities

#366

Earlier quoted context omitted.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…

The other day I tried to update my Macbook over a personal hotspot and it happily downloaded about 2GB before the computer went to sleep and I was greeted with a "Whoopsie, failed to download the update, try again" message when I woke it and, of course, it would just start over again. They don't even support resuming the download! That's just embarrassing.

I’ve now tried three times to update Safari. The first two times I left the laptop on charge with the lid open (I have it set to auto update). The third time I did it manually and watched. It got the download ok, but failed during install. It told me the update failed, but with no reason or suggestion regarding what to do next.

Re: Disclosure of three 0-day iOS vulnerabilities

#367

If your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data leaking vulnerabilities within 90 days, or pay out everyone who bought your product. I just updated to iOS 15 and it now tells you which sites you have been compromised on, or had your passwords/info compromised on. To be clear, I use a password manager with a…

Aren't Ombuds generally limited to investigations and recommendations (not enforcement)? What country colors your context? (e.g. I'm in the US where federal Ombuds aren't much of a thing, though similar roles may be filled by other persons).

Re: Disclosure of three 0-day iOS vulnerabilities

#368

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…

Depending on her data plan, downloading several tens of gigs over her 4G could have resulted in a rather exciting phone bill.

Re: Disclosure of three 0-day iOS vulnerabilities

#369
post #148

Earlier quoted context omitted.

> This is a complete myth. No, it isn't. Snow Leopard was awesome. Mavericks was also pretty solid. In fact, I'm still running that on my machines today.

Yes, it is. Snow Leopard and Mavericks are not devices. The quote I am responding to is: > Apple used to be the company that made devices that were secure and "just worked". Unless your first generation iPod still works wonders.

Sorry, I'm old-school. A computer is a device.

Re: Disclosure of three 0-day iOS vulnerabilities

#370
post #265

Earlier quoted context omitted.

Hang on, you have a coffee machine that is capable of being compromised? How exactly? Further to this, you claim that you have been compromised on HUNDREDS of sites even though you use a unique password everywhere? How is this happening to you? Isn't this a huge concern?

When I was looking for an espresso making a lot of them have touch screens and connected features. They will wake up before you get out of bed and have hot water ready. I specifically bought one without touch screens and all that crap. It takes maybe 30 seconds for the water to heat up. Lots of people will get their regular coffee maker ready the night before with water and ground beans. At a specific time in the AM…

>My Bosch fridge is a smart fridge and I plan on putting it on a VLAN.

As another new owner of a Bosch fridge, why put it on anything at all? I just peeled the sticker that told me how to connect off, threw it in the trash, and treat it just like my old non-connected fridge. Is there actually some beneficial feature that makes it worth connecting at all?

Post reply on HN