Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

451–460 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#451

Earlier quoted context omitted.

So let's say you have a printed list where kids and their parents signup with name and phone numbers, you should probably have a data integrity policy and someone akin to a DPO. In your small non-profit soccer club! Yes! You should! This is the same as if your small, non-profit club deals with dangerous chemicals - it needs to make sure that the appropriate risk assessments are done, and safety information is availab…

Your view is of course fully valid, and probably the view reflected in the GDPR legislation. To use your metaphor of chemicals: I see the current situation as if the soccer club is handling a 1L container of consumer-grade vinegar weedkiller, and is required to do pretty cumbersome things to document their use and keep it "safe". Many of them have consulted some firm or expert to get boiler-plate documentation, becau…

> I see the current situation as if the soccer club is handling a 1L container of consumer-grade vinegar weedkiller

What if one of the kids' parents is on a protection program? What if two years later you find to have the contacts details of a famous star/politician/CEO? What if one of the people on your lists gets in a controversy and you happen to have certain proof of events? And so on.

I'm trying to argue how apparently innocent data might very well be highly sensitive instead, but that without a proper framework to assess that, you never know.

Re: Disclosure of three 0-day iOS vulnerabilities

#452
post #7

This is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of…

Is that really the case? Or were they just not such a big target before when everyone was spending most of their time in a windows desktop. Maybe they just got away with it more easily in the past.

100% - they got away with it because they were small. Hacking Mac OS was unattractive - whereas, hacking iOS is the most attractive target. High gain, low security.

Apple does not have security in its DNA, as is obvious from all these exploits. Apple lives in the past where it was OK to kinda fudge it, to kinda give home apps special passes, to bypass stuff to make the game center work, and so on and so forth. These are all red flags.

Apple's threat model is script kiddies and Russian hacker groups. It's very naive vs real world exploits conducted by state level actors, companies serving state level actors, and a $1M market rate for iPhone zero day p0wn exploits.

In this cat and mouse game, the hackers are leagues ahead at this point - motivated by money and a whole different mindset.

Relying on the app store review process to catch these things is naive. A company that takes security seriously would never even think this way, obviously there's many ways around app store reviews, and hackers who went through all the trouble of finding exploits will find a way around the app store reviews, too.

Re: Disclosure of three 0-day iOS vulnerabilities

#453
post #409
post #49

Earlier quoted context omitted.

that's just dumb, like third parties do all the work and contact you about critical bugs the only effort on Apple's part of verification and some coordination which shouldn't be a huge issue for a company the size of apple.. just hire a team to do it and be done with it the whole 'secrecy culture' is a bunch of hogwash

Apple is all about silos. So a security threat gets reported to this bug bounty team. They are able to reproduce and confirm. The bug is in some deep, crusty part of the kernel; the code for which isn't available to this team, because Silos. The team who does have access to this Silo is tracked down. It gets processed into a ticket. Maybe it gets done, maybe it doesn't. Their backlog is already maxed out, as is every…

Accurate - Engineering at Apple has no tradition of security; nor does it have a tradition of being very efficient. It's mostly based on heroics of some very few very talented developers. Processes that are in place are actively hindering development.

Scaling development is hard, and Apple has never really gotten it right. I am wondering if a zero day is $1M on the open market - wouldn't it be easier and cheaper to get an engineer inside Apple to leave some plausible deniability bugs in the code? Or compromise an engineer already there?

Software engineering never had security as its main goal - but today, if you had to do it all over, security would be built into all processes from the get go, and that's likely the only way software could be made secure.

It always amazes me Apple (and others) can't even make a browser that doesn't have a drive by zero day that can take over my computer. Why is that? There must be something fundamentally wrong in the system here. And I think what's wrong is that security was not even in the minds of engineers when most of these software modules were created.

BSD had it built in, but they watered it down instead of - what they should have done - doubling down on it.

Re: Disclosure of three 0-day iOS vulnerabilities

#454
post #251

Earlier quoted context omitted.

could you try litle bit harder to provide any example why it is "harder than it looks". you repeated multiple times that its hard, but what exactly(aproximately) makes it hard?

It's mostly just 'human factors'. What I'm describing below applies across the spectrum of bug reports from fake to huge to everything in between. Nothing of what I'm listing below is an attempt to directly explain or rationalize events in the article, it's just some context from my (anecdotal) experience. - The security researcher community is composed of a broad spectrum of people. Most of them are amazing. However…

Reading the OA, I also believe that there's a wide variety of technical detail that could be the cause of, say, not responding.

Maybe the reports get to the tech teams, the tech team figures out that this bug will definitely be caught by the static analyzer, and they have other more pressing issues.

The main problem today IMO is that the incentives for finding and actively using exploits are much higher than the incentives for fixing them, and certainly much higher than building secure code that doesn't have the issues in the first place.

After all, nobody will give you a medal for delivering secure code. They will give you a medal for delivering a feature fast.

Re: Disclosure of three 0-day iOS vulnerabilities

#455

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

Here's my totally outsider informed guesswork. We've seen similar problems recently with Microsoft, where legitimate sounding issues are denied bounties, so this kind of issue is not unique to Apple. My guess would be, that MSRC and Apple's equivalent have an OKR about keeping bounties under a certain level. Security is seen as a cost centre by most companies, and what do "well run" companies do with cost centres...…

My hypothesis is a lot simpler:

Hacking is much more profitable than preventing hacking.

Incentives are heavily biased towards security exploits on all levels.

End of story.

There's no reward for "your code never got hacked". There's a reward for delivering a feature in time and a penalty for not doing so.

You'll get a bonus or promotion for delivering features. If you take twice as long because you made your code really secure - no one will know.

I think that's really all there is to it. Security is obscure and complicated.

Re: Disclosure of three 0-day iOS vulnerabilities

#456
post #336

Earlier quoted context omitted.

What’s the incentive for a user to opt-in to tracking?

Some people claim that they want personalized ads (at least on HN and similar communities) I've never met anyone in real life who wasn't creeped out by a targeted ad. Everyone nowadays has a story about how they were having a conversation with someone about something, and then one of their devices served them an advertisement for the thing they were talking about. Everyone finds that creepy as hell, but it's hard to…

Alexa... well you paid for this device to spy on you so that definitely should not surprise anyone.

I think it's bizarre that people are not only OK with having their house bugged with a device that listens to their every conversation - but they're happy to pay for the privilege.

Do you know that when you have an argument with your partner, Alexa is listening to the whole thing? Sensitive business meetings... etc... very strange!

Re: Disclosure of three 0-day iOS vulnerabilities

#457

Earlier quoted context omitted.

> crap like GDPR (which makes basically all normal interaction cumbersome) Only if you count "tracking users on first visit before they do anything else" as normal. Otherwise, there isn't a banner needed; sites could simply have a link to opt-in to tracking in the header or footer, and not track unless the user opts in. This is like passing a law making it illegal to just hit people in the street, requiring you have…

You cannot claim that GDPR is a good law, not with the galaxy-sized loophole where you can track the vast majority of people just like before, as long as your annoy them first. Better than nothing, sure, but not good.

The only reason for the GDPR is to get more government control on your daily interactions.

People are out of their mind to think that governments are working to "protect" them - hello? Govern ment means to rule the mind, mind control, that's the word, and the main mind control governments are interested in perpetuating is to make you believe you need them.

If people didn't think they need their government, there would be no more governments - and they couldn't control us.

Logically, if I was the government, I would mainly work on making sure that people think they need me. I would have every incentive to create catastrophes, pandemics, wars, in fact I would have every incentive to create any problem that has, as its solution, more governmental control.

Re: Disclosure of three 0-day iOS vulnerabilities

#458
post #251

Earlier quoted context omitted.

It's mostly just 'human factors'. What I'm describing below applies across the spectrum of bug reports from fake to huge to everything in between. Nothing of what I'm listing below is an attempt to directly explain or rationalize events in the article, it's just some context from my (anecdotal) experience. - The security researcher community is composed of a broad spectrum of people. Most of them are amazing. However…

Reading the OA, I also believe that there's a wide variety of technical detail that could be the cause of, say, not responding. Maybe the reports get to the tech teams, the tech team figures out that this bug will definitely be caught by the static analyzer, and they have other more pressing issues. The main problem today IMO is that the incentives for finding and actively using exploits are much higher than the ince…

I’ve been in infosec since the 90’s, moving slowly has killed way more companies than any security issues.

I’ve worked at some of the largest financial institutions and they spend billions on security every year to achieve something slightly better than average. Building products with a step function increase in security would incur costs in time and energy and flexibility that very few would be willing to pay.

Re: Disclosure of three 0-day iOS vulnerabilities

#459

Earlier quoted context omitted.

The only bug-less software is software that was never written. Please point me to a consumer OS that doesn't have security vulnerabilities.

The joke here is that they advertise security. This is their main claim atm.

I can advertise that I sell a lock that hasn’t been picked or bypassed. That doesn’t mean it’ll never be picked.

Re: Disclosure of three 0-day iOS vulnerabilities

#460
post #61

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

It's interesting to me that in this entire thread, nobody is even mentioning or considering the possibility that COVID has impacted Apple's operations. It obviously has. It has affected every tech company. Certainly it has affected mine. Whether this is an example of that, I don't know, of course, but I think it's plausible.

Hackers aren't going to stop because of COVID. Apple has a duty to their customers to keep their products secure.
Post reply on HN