Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

381–390 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#381
post #365
post #352

Earlier quoted context omitted.

In the simplest way, not unlike Windows Update: snapshot filesystem, start filesystem transaction, unzip changed binary files, check new files integrity, end transaction. Indeed, Apple used to distribute patches this way in the past. You also could ship a list of updated system files hashes, compare to the installed files and just download the changed ones, like rsync. Better than shipping a whole new disk image ever…

Yeah, I'm sure it's theoretically doable, but it's one of those things which would almost certainly require substantial work given the massively complex edifice of iOS. (And the iOS IPSW format, or even iOS DMGs/ADIs, are very different from the OS X patches you mentioned.)

It's cheaper to make things that aren't maintainable. We optimize for the dev, not the platform or the user.

It's the same lazy dev culture that gives us Electron apps, or the lazy sysadmin culture that gives us docker.

It's cheaper to create massive incomprehensible and unmaintainable edifice that requires massive storage / processor / network inefficiency to maintain versus well thought-out and "clever" systems that work efficiently.

Personally, I wish the days of optimizing for low-resource machines, slow network connections, and expensive storage weren't gone. As an end-user I think the results of moving away from a culture of optimization haven't been good. I think the ship has sailed, though.

Re: Disclosure of three 0-day iOS vulnerabilities

#382

Earlier quoted context omitted.

I’m convinced that the modern role of US political parties is to simply keep the masses squabbling. I wish we could get rid of gerrymandering and the two party dominance.

Totally agree here. It has to be intentional at this point.

Yes. Hyperpartisanship is the way to maintain minority control of an ostensibly majority-controlled system. Both parties feign gridlock over popular policy but cooperate on what their owners want. Populist support for policies doesn't matter when people are kept divided along party lines. "Radical" nonconformists who aim to do what voters want can always be defeated from within their party if not by the other side.

Re: Disclosure of three 0-day iOS vulnerabilities

#383

Earlier quoted context omitted.

So, is this the lack of grandmas working at Apple in software development? This is nothing you can fix by following some diversity ideology. This is a question of respecting different requirements from different user groups. You cannot mirror every user group in the development teams. How do you represent people of old age, with illnesses, or certain disabilities in a development team? How do you represent people liv…

Sometimes you need to accept you just aren’t the target audience of a product. You may love cars. You might think Tesla’s are amazing. But if you live on a small island without an electrical grid, it might not be the car for you just because it doesn’t come with its own solar panels.

Owning an iPhone with no other means of Internet connection makes one not the target market for an iPhone?

Re: Disclosure of three 0-day iOS vulnerabilities

#384

Earlier quoted context omitted.

I believe the poster was referring to the practice of testing if an app was installed by calling [UIApplication canOpenURL:] —- as I recall Twitter was found to check for hundreds of different apps, to feed into their ads and analytics business, and Apple later changed it to only be callable 50 times.

Nit: for 50 different schemes, not 50 times.

And you have to provide those schemes in your App's plist as well if I recall correctly. Gated pretty hard.

Re: Disclosure of three 0-day iOS vulnerabilities

#385
post #380

Earlier quoted context omitted.

> A computer is a device. Correct. A computer is a device. Snow Leopard and Mavericks--your two examples-- are, however, not computers.

Oh, good grief, do you really need to get that pedantic? Apple made computers (devices) that ran those operating systems, and that combination mostly Just Worked (at least it did for me).

Pedantism is trotting out the fact that yeah, you can find plenty of people still running Windows-whatever on their Gateways, or lovingly cared-for TRS that still "just works". The point is that by and large, Apple devices are built in with planned obsolescence in mind (see the lawsuit they settled a few months ago about literally this).

Re: Disclosure of three 0-day iOS vulnerabilities

#387
post #268

Earlier quoted context omitted.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3…

> I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly) Print Nightmare was part of a risky call in the printing subsystem design which was recognized as such when they made it in the 90s. That specific vulnerability was disclosed to Microsoft in 2020, accidentally disclosed in public in June, flailed at with incomplete patches and bad documentatio…

It would not certainly make everything more expensive. The cost of breaches is significant, though difficult to quantify, so the cost of effective prevention could be lower.

Re: Disclosure of three 0-day iOS vulnerabilities

#388
post #265

Earlier quoted context omitted.

When I was looking for an espresso making a lot of them have touch screens and connected features. They will wake up before you get out of bed and have hot water ready. I specifically bought one without touch screens and all that crap. It takes maybe 30 seconds for the water to heat up. Lots of people will get their regular coffee maker ready the night before with water and ground beans. At a specific time in the AM…

>My Bosch fridge is a smart fridge and I plan on putting it on a VLAN. As another new owner of a Bosch fridge, why put it on anything at all? I just peeled the sticker that told me how to connect off, threw it in the trash, and treat it just like my old non-connected fridge. Is there actually some beneficial feature that makes it worth connecting at all?

The right french door is hard to close compared to our last side by side fridge. For now it helps me remember to close it when I’m in a different room and can’t hear the alarm.

Re: Disclosure of three 0-day iOS vulnerabilities

#389

With these Apple-related vulnerability annoucements on HN, usually we see response from a satisified Apple owner along the lines of "This is fixed in [some new version number]". The thing is, the problem isnt whether something is fixed, its that it was broken to begin with. It passed "QA" at a trillion dollar company and its a pre-installed fixture^1 on some relatively expensive hardware item. If there is such an "it…

The only bug-less software is software that was never written.

Please point me to a consumer OS that doesn't have security vulnerabilities.

Re: Disclosure of three 0-day iOS vulnerabilities

#390
post #268

Earlier quoted context omitted.

> I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly) Print Nightmare was part of a risky call in the printing subsystem design which was recognized as such when they made it in the 90s. That specific vulnerability was disclosed to Microsoft in 2020, accidentally disclosed in public in June, flailed at with incomplete patches and bad documentatio…

It would not certainly make everything more expensive. The cost of breaches is significant, though difficult to quantify, so the cost of effective prevention could be lower.

That's _possible_ but fundamentally I'm looking at this from the perspective of requiring new work to be done by expensive people (infosec, dev, ops are all in-demand skills) — maybe some of that comes from changing team priorities, in which case the cost is less feature work, but in most cases I'd expect that to be hiring. There aren't many breaches which have direct costs greater than that because companies have been able to avoid penalties or compensation in most cases. If the cost of a breach was greater than, say, a year of free credit monitoring that calculation could change dramatically.

Ransomware has already changed this somewhat: now the cost is halting operations for a potentially lengthy period of time, and that has spurred a lot more awareness that the current model is insufficient but not from what I've seen significant efforts to change it.

Post reply on HN