Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

411–420 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#411

Earlier quoted context omitted.

So, is this the lack of grandmas working at Apple in software development? This is nothing you can fix by following some diversity ideology. This is a question of respecting different requirements from different user groups. You cannot mirror every user group in the development teams. How do you represent people of old age, with illnesses, or certain disabilities in a development team? How do you represent people liv…

All these different groups your speaking of are called personas . Apple should have each of their personas identified based off their technical prowess, their life experiences, health, how they connect for user updates and whatever else may differentiate a group of users from one another and needs to be considered and accounted for. Once you have that you create a user journey map for each of those personas - in this…

Of course, these groups are called personas in software engineering circles. I was answering to people who believe diversity will somehow fix all problems of this world. And they do not talk about personas. They talk about minorities, victims and races.

Before Apple or any other customer company describes personas, there is an explicit or implicit decision of which personas to consider and which not. But most consumer targeted companies hide which personas they consider and which not.

Re: Disclosure of three 0-day iOS vulnerabilities

#412

Earlier quoted context omitted.

Now that you mention it, I think there's a real lack of grandmas in tech... maybe I shouldn't be saying this publicly, but we don't have any at our company.

One of our product managers is a grandmother (she is actually taking an early retirement soon because her 4th grandchild is on the way). We are in the B2B/B2EDU space so the "As a grandmother, I think..." line of thought does not apply. However, she has frequently had insights and observations that none of us would have come up with. Once implemented, they have been very successful/profitable. So yes, absolutely, unl…

> One of our product managers is a grandmother

> However, she has frequently had insights and observations that none of us would have come up with

> So yes, absolutely, unless your company wants to be in a very specific niche, the lack of true diversity in your company is a drag on your success.

The conclusion you are drawing here, does not follow from your two observations above. The fact that your product manager has had insights, that nobody else had in team, does not mean a "lack of true diversity in your company is a drag on your success." Some diversity may help in certain situations and in others not. The above mentioned insights and observations might just be the result of competence and more experience of the product manager or incompetence of the rest of the team. There may be many other reasons. We don't know. We have one observation and should refrain from generalizing. That this is because of more diversity is just a speculation. A speculation that fits an often repeated narrative, but that doesn't make it a logical conclusion.

Re: Disclosure of three 0-day iOS vulnerabilities

#413
post #376

Unfortunate that this researcher, shame on apple for not handling these vulnerabilities quickly. I used to believe that iphones were more secure than android and was considering making the switch. After reading this article and with some other recent news (CSAM[1], spam on the app store[2]) I don't think I'll be hopping on the iOS train anytime soon. [1]: https://www.apple.com/child-safety/ [2]:

While Apple's recent behavior does seem bad, I'm personally wondering if there is some quantitate measure comparing iOS/Android before I make the opposite switch. I wonder if iOS still may be more privacy friendly compared to alternatives regardless of the recent issue (I genuinely have no clue)

IMO, that seems like apple but the lines are getting closer than ever

Re: Disclosure of three 0-day iOS vulnerabilities

#414

Earlier quoted context omitted.

> Siphoning off potential and sabotaging developing countries through human resource poaching called "immigration" You think immigration should be illegal? > Government theft and fractional enslavement through taxation You really had me in agreement with the first few items. You are not a serious person.

I'm going to guess that they're referring to only allowing "cream of the crop" immigration. (eg H1B or other visas often are only open to top candidates, not everyone)

The problem with the argument that this is crippling developing countries is that it's often the case that the top talent can't really shine in their country. They can't realize their potential, either due to the lack of means or corruption or envy or whatever. I am from a third world country and a large part of our scientists did great things because they immigrated, at the same time, there are many great minds here that to do anything at all have to partake in an endless uphill battle.

Like, I'd totally love to have our top engineers and scientists come from the West and do some amazing things here (they 100% can make a great change), but I feel that they actually just can't.

Re: Disclosure of three 0-day iOS vulnerabilities

#415

Earlier quoted context omitted.

All these different groups your speaking of are called personas . Apple should have each of their personas identified based off their technical prowess, their life experiences, health, how they connect for user updates and whatever else may differentiate a group of users from one another and needs to be considered and accounted for. Once you have that you create a user journey map for each of those personas - in this…

Of course, these groups are called personas in software engineering circles. I was answering to people who believe diversity will somehow fix all problems of this world. And they do not talk about personas. They talk about minorities, victims and races. Before Apple or any other customer company describes personas, there is an explicit or implicit decision of which personas to consider and which not. But most consume…

> They talk about minorities, victims and races.

When I mentioned diversity, what I actually had in mind was that all tech workers in California have wifi, and probably find this so normal to connect your phone to wifi that they expect any normal user will do this on a daily basis.

I'm not a grandma but I'm a tech worker with a very different life style. Like the person I was replying to's grandma, I have no wifi. Like her, I have to fake it from time to time so that my Android phone will backup photos, accept to download Google drive documents, etc.

So the diversity I had in mind is rather a diversity in location and lifestyle.

Re: Disclosure of three 0-day iOS vulnerabilities

#416
post #415

Earlier quoted context omitted.

Of course, these groups are called personas in software engineering circles. I was answering to people who believe diversity will somehow fix all problems of this world. And they do not talk about personas. They talk about minorities, victims and races. Before Apple or any other customer company describes personas, there is an explicit or implicit decision of which personas to consider and which not. But most consume…

> They talk about minorities, victims and races. When I mentioned diversity, what I actually had in mind was that all tech workers in California have wifi, and probably find this so normal to connect your phone to wifi that they expect any normal user will do this on a daily basis. I'm not a grandma but I'm a tech worker with a very different life style. Like the person I was replying to's grandma, I have no wifi. Li…

That's what I understood you to mean too. I just added in differently-abled people. I've never seen a persona based off minorities, "victims" (not sure what that means in this context?), or races. It's always been capabilities and life experiences.

Re: Disclosure of three 0-day iOS vulnerabilities

#417

I am not able to compile the first two of these (after the first two I stopped trying) with the newest Xcode on iOS 15.0. I haven't tried the other two or older tools. The source code as given also had syntax errors in it.

Follow the links to GitHub, the code there compiles perfectly, the PoC inside the article is just a shortened version

Thank you for the explanation! Will give it a shot.

P.S. Yes it works! Perhaps add a comments in the short version where it says

//This shortened version does not compile, use the GitHub version of the code

It said "proof-of-concept" and I generally expect PoC to work as presented. My bad for not reading everything carefully.

Re: Disclosure of three 0-day iOS vulnerabilities

#418
post #414

Earlier quoted context omitted.

I'm going to guess that they're referring to only allowing "cream of the crop" immigration. (eg H1B or other visas often are only open to top candidates, not everyone)

The problem with the argument that this is crippling developing countries is that it's often the case that the top talent can't really shine in their country. They can't realize their potential, either due to the lack of means or corruption or envy or whatever. I am from a third world country and a large part of our scientists did great things because they immigrated, at the same time, there are many great minds here…

Also it ignores, as i've observed with Filipinos in Canada, that they often send like half of their paycheck back "home" . Some of them live in developed world "squalor" (like many people to a house, or taking the bus) so their families can live like royalty in a low CoL area.

Re: Disclosure of three 0-day iOS vulnerabilities

#419

Earlier quoted context omitted.

I imagine they are just overwhelmed. Let’s say they have a team of 6 engineers tasked with this. They probably receive hundreds of reports a day, many bogus, some real, but all long winded descriptions like this framed to make the vuln seem as bad as possible. In addition many vuln reports are generated by automated tools and sprayed to thousands of sites/vendors daily in the hope of one of them paying out, they seem…

I feel like Apple could afford to staff a security program like this. Much, much smaller and less wealthy companies manage it.

much smaller, less wealthy companies attract far fewer reports

Re: Disclosure of three 0-day iOS vulnerabilities

#420
post #377

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

Having worked in at a large tech company with a big bug bounty program and seeing tonnes of bugs come through, my experience is that usually there is a wide disconnect between the bug bounty program (situated in one org of the company) and the engineering group responsible for fixing the bug (which is in a different part of the company.) This is exacerbated by misaligned incentives, bug bounty team wants fixes ASAP w…

it feels like we're conflating two issues here: fixing the bug on time and paying out the researcher. at the point where the bug is too complicated to fix within SLA and the exception has been escalated to senior leadership, surely the bug bounty team can pay the researcher?
Post reply on HN