Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

31–40 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#31
Apple definitely needs to improve its processes in order to ensure he and others gets credit.

But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite request not a demand.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#32
post #11

Earlier quoted context omitted.

> alleviate pressure on its encryption practices. Apple is not that different from the status quo on end to end encryption as to necessitate a conspiracy (probably even in jest ). They have no icloud encryption, no photos encryption, no device backup encryption etc etc.

One small correction. They do have backup encryption. As a matter of fact, your various account passwords are only backed up if you keep the encrypt option turned on. https://support.apple.com/en-us/HT205220 As far as the original article, I agree completely that not paying and crediting these folks in a timely manner is just stupid and will reduce Apple security long term.

Apple holds the keys to encrypted iCloud backups.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#33
post #24

Earlier quoted context omitted.

> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.

>And thereby accomplishing what, exactly? ...$$$$?

I could accomplish the same thing by robbing a bank - doesn’t make it the right thing to do.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#34

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.

I agree somewhat, the users which include me get caught in the crossfire if someone releases a zero day out in the wild, but I also think there needs to be a negative feedback to these tech giants that expect work for free.

But in the grand scheme of things, does it even punish the tech giants? They have so many claws in a users life, and in the case of apple, your only other choice is google or a bunch of shady oems.

At the end of the day the only people who pay for it are users themselves, their data is comprised and irreversibly out there

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#35
post #10

This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.

I'm so happy Linux is an option on the computer. When it comes to phones I feel stuck behind a rock and a hard place - choose iPhone, with poor Linux integration and threats to passively scan files on my phone and forward them to LEO? Sure, they have a decent record with security but these bug bounty reports haven't been great. Or choose Android, with its poor privacy record, a result of being built by an ad company…

I get that a lot of the Android-based projects don't pan out, but LineageOS has been going for quite a while now, CalyxOS is relatively new, and GrapheneOS (previously CopperheadOS) have successfully established themselves as the defacto hardened Android platform.

You can download the source, modify it, and build them all freely. Hopefully more people can get involved and move the needle instead of only lamenting how they don't succeed while not actively trying to help them succeed. I mean this in a respectful way.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#36

Apple definitely needs to improve its processes in order to ensure he and others gets credit. But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite…

That’s not clear at all. I’d be twitchy too if I had $100k on the line and the other party had repeatedly messed up over months of interactions.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#37

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.

Forcing Apple to do the right thing the next time.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#38
post #24

Earlier quoted context omitted.

>And thereby accomplishing what, exactly? ...$$$$?

I could accomplish the same thing by robbing a bank - doesn’t make it the right thing to do.

Doesn't make free work for a for trillion dollar corporation something noble to do.

By that logic, a grocery store giving away everything for free is the right thing to do. Doesn't lead to anything sustainable though.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#39
post #21

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

No, he's not. Those are low-priority bugs and the only thing that made them stand out was the fact that he dropped them online without a patch. RCEs get priority in patching, and his priv esc issues were not as important.

He dropped them online after a significant period of delay. Already discussed here on HN. [1]

[1] https://news.ycombinator.com/item?id=28637276

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#40

Apple definitely needs to improve its processes in order to ensure he and others gets credit. But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite…

It is of note that this is not the standard footer attached to outgoing e-mails.

It's the first line of the email after the greeting, manually written in.

Post reply on HN