Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

401–410 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#401

Earlier quoted context omitted.

Just tried it again. I have 70GB available. Got on the hotspot, started the download, unplugged the laptop, waited for it to go to sleep, woke it up - same result. I had to accept the EULAs again and it started to download from about 50mb. Having attempted (unsuccessfully) to write a resumable HTTP/HTTPS downloader, which is what I suspect nsurlsessiond is using behind the scenes - it's really hard to get it right. M…

But Apple has the luxury of controlling both the server and the client. Why isn’t it just a matter of using HTTP range requests? https://developer.mozilla.org/en-US/docs/Web/HTTP/Range_requ... And if they need to get more clever than that, why not have a BitTorrent-like map of chunk hashes. So you download the update, check the hash of the whole thing and if it fails the hash check, download the chunk hashes which wi…

We can only speculate, but my guess is some combination of “didn’t feel the need to” and “the code responsible for this is nested 6 layers deep between 3 different frameworks”.

Re: Disclosure of three 0-day iOS vulnerabilities

#402

Earlier quoted context omitted.

Apple makes ridiculous amount of money, and many Apple fanboys I know believe their devices are hack-proof.

I don’t think of my devices as being hack-proof, but as being the best set of trade-offs for me personally between security, privacy, usability, etc.

Agreed. I use Windows/Android for the same reason- I know what I'm giving up but the upsides are important enough to me. I am talking about people who don't have much clues about either.

Re: Disclosure of three 0-day iOS vulnerabilities

#403
post #236

Earlier quoted context omitted.

The only interactions made cumbersome by GDPR are those with organizations that abuse their users/customers’ data. Otherwise you don’t even need a cookie banner.

So, all of them.

Given that, is the law bad, or is the default behavior of companies?

Re: Disclosure of three 0-day iOS vulnerabilities

#404

Earlier quoted context omitted.

It's just marked as unavailable. Apple does that to try keeping people from using XPC on iOS. Use the full code from GitHub, it has a bypass for that Xcode check

Unless they have evidence of it getting past Apple and into the App Store, just doing it dynamically doesn’t change anything

If you have a developer account that you are willing to sacrifice and don't mind the possibility of legal action, you can try that. I've managed to upload the binary built from the source code from gamed exploit repository on GitHub to App Store Connect and installed it onto my own device via TestFlight. I didn't submit it for review, but if the functionality would have been concealed, it would easily pass.

As far as I know, how the review happens is that reviewers just install apps onto their iPads, tap through all the screens they can find and make their decisions based purely on that. So if an app connects to server and asks what it should do, it's possible to make an app behave differently for reviewers and all other users.

Re: Disclosure of three 0-day iOS vulnerabilities

#405

With these Apple-related vulnerability annoucements on HN, usually we see response from a satisified Apple owner along the lines of "This is fixed in [some new version number]". The thing is, the problem isnt whether something is fixed, its that it was broken to begin with. It passed "QA" at a trillion dollar company and its a pre-installed fixture^1 on some relatively expensive hardware item. If there is such an "it…

The only bug-less software is software that was never written. Please point me to a consumer OS that doesn't have security vulnerabilities.

The joke here is that they advertise security.

This is their main claim atm.

Re: Disclosure of three 0-day iOS vulnerabilities

#406
post #397
post #362

Earlier quoted context omitted.

Which you can call directly from Swift.

You are right. https://steipete.com/posts/calling-super-at-runtime/

Look at the code of gamed exploit that I've uploaded to GitHub, the app is written in Swift and it calls Objective-C runtime functions from it

Re: Disclosure of three 0-day iOS vulnerabilities

#407
post #357

Earlier quoted context omitted.

Best explanation I've heard was in Darknet Diaries about Zero Day Brokers, which was a fantastic listen! ( https://open.spotify.com/episode/4vXyFtBk1IarDRAoXIWQFf?si=3... ) The short version is that if the bounties become too large they'll lose internal talent who can just quit to do the same thing outside the org. Another reason was that they can't offer competitive bounties for zero days because they'll be competin…

this is the real reason. not anything internal/culture related A good iOS 0-day is worth hundreds of millions of dollars in contracts with shady governments. Apple can't compete with that multiple times a year

According to Zerodium, iOS exploits are cheaper than Android exploits because they are so plentiful in comparison.

Re: Disclosure of three 0-day iOS vulnerabilities

#409
post #49
post #22

Earlier quoted context omitted.

Bug bounty programs are the antithesis of Apple's internal methodology, culture, and way of doing business. They keep everything close to the chest, they shun "outsiders", etc.. The idea that someone outside of Apple, from the unwashed masses, could find a flaw in Apple's own software is a pretty big pill for them to swallow. Thus it doesn't surprise me there are problems with their bug bounty program. I think if the…

that's just dumb, like third parties do all the work and contact you about critical bugs the only effort on Apple's part of verification and some coordination which shouldn't be a huge issue for a company the size of apple.. just hire a team to do it and be done with it the whole 'secrecy culture' is a bunch of hogwash

Apple is all about silos.

So a security threat gets reported to this bug bounty team. They are able to reproduce and confirm. The bug is in some deep, crusty part of the kernel; the code for which isn't available to this team, because Silos.

The team who does have access to this Silo is tracked down. It gets processed into a ticket. Maybe it gets done, maybe it doesn't. Their backlog is already maxed out, as is everyone's.

The security team says "we've done all we can".

This is not a matter of "lol just hire a team". You need leadership aligned, so the manager's manager can see their task list, or open security issues, and say "what the fuck, why are you not prioritizing this".

That's not Apple. Apple is product-driven. They actually, legitimately don't care about Privacy and Security. Their manager-managers get mad when products aren't delivered on time. They may also push-back on purposeful anti-privacy decisions. Its not in their culture to push back on Security issues, or latent Privacy issues resulting from those Security issues.

"Just tear down the silos" > Working for Apple is a cult. The silos are a part of the cult; left-over from one of the worst corporate leaders of all time, Jobs. Try telling a cult member their beliefs are false.

"Grant the security team access to everything" > And, I guess, also hire the smartest humans to ever exist on the planet to be able to implement security improvements across thousands of repositories in dozens of programming languages, billions of lines of code? And, even if they could, push those changes through a drive-by review and deployment with a team on the other side of the planet you've never met? You, coming into their house, and effectively saying "y'all are incompetent, this is insecure, merge this" (jeeze ok, we'll get to it, maybe in... iOS 18)

Re: Disclosure of three 0-day iOS vulnerabilities

#410
post #400

Earlier quoted context omitted.

That is hilarious. Problem: Right french door is hard to close and user often leaves it open. User does not hear alarm. Solution 1: Make french door easier to close / close automatically. Solution 2: Make alarm louder. Adjustable even. Solution 3: Add networked computer, software, mobile phone application, and wire them all up.

It’s caused issues with my wife thinking the kids milk has gone bad because the door was ajar. Trust me when I say peace of mind and possibly getting hacked is much better than an angry wife plus hungry kids. French door fridges have this flat piece that slides behind one of the doors to make it airtight. Our previous place had a Samsung that did the same thing, except it was the left door and easier to shut. It’s ma…

I apologize, I did not mean to disparage your solution for a purchase you already made. I was cynically imagining the thinking of the manufacturer! Also, yes, we have a fridge with french doors, so I understand the problem. Ours just has a really effective alarm. Have you tried sticking two small wedges under the front feet so that the doors get a little more momentum when swung closed? That was actually in our manual. (Yes I read my fridge's manual).
Post reply on HN