But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite request not a demand.
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
31–40 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#32Earlier quoted context omitted.
> alleviate pressure on its encryption practices. Apple is not that different from the status quo on end to end encryption as to necessitate a conspiracy (probably even in jest ). They have no icloud encryption, no photos encryption, no device backup encryption etc etc.
One small correction. They do have backup encryption. As a matter of fact, your various account passwords are only backed up if you keep the encrypt option turned on. https://support.apple.com/en-us/HT205220 As far as the original article, I agree completely that not paying and crediting these folks in a timely manner is just stupid and will reduce Apple security long term.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#33Earlier quoted context omitted.
> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.
>And thereby accomplishing what, exactly? ...$$$$?
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#34What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.
> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.
But in the grand scheme of things, does it even punish the tech giants? They have so many claws in a users life, and in the case of apple, your only other choice is google or a bunch of shady oems.
At the end of the day the only people who pay for it are users themselves, their data is comprised and irreversibly out there
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#35This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.
I'm so happy Linux is an option on the computer. When it comes to phones I feel stuck behind a rock and a hard place - choose iPhone, with poor Linux integration and threats to passively scan files on my phone and forward them to LEO? Sure, they have a decent record with security but these bug bounty reports haven't been great. Or choose Android, with its poor privacy record, a result of being built by an ad company…
You can download the source, modify it, and build them all freely. Hopefully more people can get involved and move the needle instead of only lamenting how they don't succeed while not actively trying to help them succeed. I mean this in a respectful way.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#36Apple definitely needs to improve its processes in order to ensure he and others gets credit. But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite…
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#37What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.
> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#38Earlier quoted context omitted.
>And thereby accomplishing what, exactly? ...$$$$?
I could accomplish the same thing by robbing a bank - doesn’t make it the right thing to do.
By that logic, a grocery store giving away everything for free is the right thing to do. Doesn't lead to anything sustainable though.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#39What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.
No, he's not. Those are low-priority bugs and the only thing that made them stand out was the fact that he dropped them online without a patch. RCEs get priority in patching, and his priv esc issues were not as important.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#40Apple definitely needs to improve its processes in order to ensure he and others gets credit. But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite…
It's the first line of the email after the greeting, manually written in.