Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

51–60 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#51
post #48

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

Can't we hope they go for full-disclosure instead of selling to the highest bidder? Selling to the highest bidder just hurts apple users not apple.

> just hurts apple users not apple.

As a first-order effect, sure.. but Apple is not immune to the damage that this causes either. More importantly, their failure to pay or honor their commitments would be the root cause of this in the future.

They opened this "bug bounty" door on their own, they are solely responsible for it's success or failure.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#53
post #40

Apple definitely needs to improve its processes in order to ensure he and others gets credit. But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite…

It is of note that this is not the standard footer attached to outgoing e-mails. It's the first line of the email after the greeting, manually written in.

Not all emails will trigger the automated footer if they use it at all. They never did when I was there.

And being a very serious security vulnerability (enough to warrant its own release) they are probably just being cautious.

It really is a polite request not some legal demand.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#54
post #10

This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.

I'm so happy Linux is an option on the computer. When it comes to phones I feel stuck behind a rock and a hard place - choose iPhone, with poor Linux integration and threats to passively scan files on my phone and forward them to LEO? Sure, they have a decent record with security but these bug bounty reports haven't been great. Or choose Android, with its poor privacy record, a result of being built by an ad company…

Android doesn't scan your phone and mine it for data. Apps on Android scan your phone and mine it for data. Apps on iOS also scan your phone and mine it for data. The major difference between the two is that Android lets you choose which apps to put on your phone.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#55
Zerodium (https://zerodium.com/program.html) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal.

Next time someone finds one of these, I wonder where they will report it to….

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#56
post #7

Here's a fun conspiracy theory proposed entirely in jest: Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices. So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ulti…

So then explain this page:

https://support.apple.com/en-au/HT201222

Why would they bother fixing any of the bugs ?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#57

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

>Why are people out to crucify Apple for a story that's still being resolved?

>The company hasn't denied the bounty, they're just incompetent / slow on this process.

People probably expect more from... checks notes The world's most valuable and successful modern corporation.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#58
post #40

Earlier quoted context omitted.

It is of note that this is not the standard footer attached to outgoing e-mails. It's the first line of the email after the greeting, manually written in.

Not all emails will trigger the automated footer if they use it at all. They never did when I was there. And being a very serious security vulnerability (enough to warrant its own release) they are probably just being cautious. It really is a polite request not some legal demand.

I didn't mean for my comment to come across as disagreeing with your overall point - just highlight that there is (in my mind) a fairly big difference between auto-generated footers attached to outgoing emails that you referenced (re banks, teclos) and explicitly written instructions at the beginning of an email.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#59

Earlier quoted context omitted.

One small correction. They do have backup encryption. As a matter of fact, your various account passwords are only backed up if you keep the encrypt option turned on. https://support.apple.com/en-us/HT205220 As far as the original article, I agree completely that not paying and crediting these folks in a timely manner is just stupid and will reduce Apple security long term.

Apple holds the keys to encrypted iCloud backups.

Yes, they do have some way of using your iCloud account credentials to get to the backup key. Given the level of customer support needed for forgotten backup keys, they have probably chosen this as the lesser of two evils.

If you don't like that "feature," don't do iCloud backups. I do direct backups as described in the support link. Apple doesn't have those keys.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#60
post #7

Here's a fun conspiracy theory proposed entirely in jest: Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices. So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ulti…

You've got the wrong ideas. The government isn't using the same exploits as you and me, their backdoors are hidden much better and offer far more comprehensive control than just a silly Gamecenter vuln.
Post reply on HN