Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

21–30 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#21

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

No, he's not. Those are low-priority bugs and the only thing that made them stand out was the fact that he dropped them online without a patch. RCEs get priority in patching, and his priv esc issues were not as important.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#22
post #12

The need for Linux phones, in a market dominated by two companies and one government, is more than ever! Hope we soon get a usable Linux phone.

PinePhone is our only hope! Still a ways off from being consumer ready but it's heading in the right direction.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#23
post #11
post #7

Here's a fun conspiracy theory proposed entirely in jest: Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices. So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ulti…

> alleviate pressure on its encryption practices. Apple is not that different from the status quo on end to end encryption as to necessitate a conspiracy (probably even in jest ). They have no icloud encryption, no photos encryption, no device backup encryption etc etc.

One small correction. They do have backup encryption. As a matter of fact, your various account passwords are only backed up if you keep the encrypt option turned on.

https://support.apple.com/en-us/HT205220

As far as the original article, I agree completely that not paying and crediting these folks in a timely manner is just stupid and will reduce Apple security long term.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#24

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.

>And thereby accomplishing what, exactly?

...$$$$?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#25

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.

Trillion dollar companies don't care about merit for doing the right thing. Why should this guy in the future?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#26
post #15
post #7

Here's a fun conspiracy theory proposed entirely in jest: Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices. So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ulti…

Next level conspiracy theory: Apple employs, knowingly or unknowingly, CIA/NSA agents who intentionally introduce these bugs.

[deleted]

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#27

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#28

Earlier quoted context omitted.

> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.

Trillion dollar companies don't care about merit for doing the right thing. Why should this guy in the future?

Maybe he doesn't want dissident journalists and activists to get spied on and chopped to pieces?

That sounds like a good enough reason to report these bugs for someone with morals.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#29
post #10

This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.

I'm so happy Linux is an option on the computer. When it comes to phones I feel stuck behind a rock and a hard place - choose iPhone, with poor Linux integration and threats to passively scan files on my phone and forward them to LEO? Sure, they have a decent record with security but these bug bounty reports haven't been great. Or choose Android, with its poor privacy record, a result of being built by an ad company…

Likewise. I'm in the market for a new phone. I want to get something top of the line and then keep it for at least 5 years, so good updates etc. But I have serious issues with both Google and Apple at this point.

For me it isn't really the tech companies that need to buy in to make an alternative phone OS viable, but things like banks. Online mobile banking is one of the main things I use my phone for after web browsing and messaging. The probability that it won't work on some third OS is what puts me off trying some of the alternatives.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#30
post #7

Here's a fun conspiracy theory proposed entirely in jest: Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices. So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ulti…

This is indeed silly, because the zero-day vulnerabilities that the IC exploits provide full kernel-level access to devices, and this just lets you read contacts from an app you install from the app store (which does local API-level surveillance already) on the device.
Post reply on HN