After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I though…
Disclosure of three 0-day iOS vulnerabilities
441–450 of 464 posts
Re: Disclosure of three 0-day iOS vulnerabilities
#442Earlier quoted context omitted.
While Apple's recent behavior does seem bad, I'm personally wondering if there is some quantitate measure comparing iOS/Android before I make the opposite switch. I wonder if iOS still may be more privacy friendly compared to alternatives regardless of the recent issue (I genuinely have no clue)
I think they're at least trying! All the vulnerabilities mentioned can be found with static analysis, which Apple is doing before accepting an app into the store. I'm pretty sure if you pack one of these 0-days in your app, it will get rejected. So as for now, this is a theoretical exercise, unless proven that this code has actually been shipped to the store.
Re: Disclosure of three 0-day iOS vulnerabilities
#443Earlier quoted context omitted.
The second sentence of the article gives a sufficient timeline. > I've reported four 0-day vulnerabilities this year between March 10 and May 4 So the vulnerabilities were reported at least 140 days ago. He also mentions 3 upgrades of iOS were published after his reports.
Yeah, I quoted it myself. My point is that the article is formatted in a confusing way. It's formatted into 4 vulnerabilities, but only 1 of them has a timeline, which immediately made me wonder why there weren't 3 more timelines. Even though I read the sentence at the beginning saying the author reported all 4 to Apple, when I saw there was a reporting timeline on 1 vuln but not the other 3 I started doubting my own…
Re: Disclosure of three 0-day iOS vulnerabilities
#444Earlier quoted context omitted.
That makes apple (the org, not the fanboys) sound a bit cultish... Can't say I'm surprised though...
It is in SV after all..
Re: Disclosure of three 0-day iOS vulnerabilities
#445Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…
It doesn’t matter how big of a company they are, the only thing that matters financially is whether they’re growing or not.
Re: Disclosure of three 0-day iOS vulnerabilities
#446After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I though…
You can download the IPSW from ipsw.me (you actually grab the file straight from Apple and it's digitally signed, so the malware risk is zero) and perform the update yourself by option-clicking the Update button in the iPhone window in Finder.
Re: Disclosure of three 0-day iOS vulnerabilities
#447Earlier quoted context omitted.
It is in SV after all..
There are plenty of companies in SV that are the opposite of cultish, eg. Google is known to try to be more like a university. (or it was at least, I think they are pulling back on that as their political problems mount.)
Re: Disclosure of three 0-day iOS vulnerabilities
#448This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…
The only mitigating factor is that they’re not remote vulnerabilities. That being said, this is more or less the industry standard. And even if the other person mentioning this was downvoted, they are right: this has been the case since forever and can only be remedied through laws making companies responsible for their failures. But neither the US government nor said companies want this. It will have to get so bad t…
Re: Disclosure of three 0-day iOS vulnerabilities
#449Earlier quoted context omitted.
Yeah, I quoted it myself. My point is that the article is formatted in a confusing way. It's formatted into 4 vulnerabilities, but only 1 of them has a timeline, which immediately made me wonder why there weren't 3 more timelines. Even though I read the sentence at the beginning saying the author reported all 4 to Apple, when I saw there was a reporting timeline on 1 vuln but not the other 3 I started doubting my own…
I've updated the article to include a timeline for each vulnerability
Re: Disclosure of three 0-day iOS vulnerabilities
#450Earlier quoted context omitted.
I'm curious. Would you accept it if Apple came out and said that the reason this is happening is because of the COVID pandemic affecting their operations? Surely even if it were true, that is no excuse for a company like Apple?
Did I say I "accept" it? No. Did I say it was an "excuse"? No. Please don't put words in my mouth. The -4 downvotes made your point well enough. I get it: people want to trash Apple by any means necessary and that's way more important than a free and open discussion of the issue. Thanks.
After claiming that I am putting words in your mouth, you go ahead and accuse me of only wanting to trash Apple and not caring about having a discussion.
I would have preferred it if you had simply told me to fuck off.