Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

61–70 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#61

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

Devil's advocate here: I've worked the other side of managing bug bounties.

It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it.

When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't share details of a larger vulnerability with them. All we can really do is ask for more time. In the end it all works out and they get paid out/credited for the original+follow on bug.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#62

Zerodium ( https://zerodium.com/program.html ) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal. Next time someone finds one of these, I wonder where they will report it to….

Is it moral though? What do they do with these exploits? If it is to help advance the agendas of countries like Israel and Saudi Arabia how would you feel submitting exploits to them?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#63

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

Because those emails are probably lies, they're just delaying and delaying and hoping it will just go away, and writing fake "We're sorry"'s when they're forced to.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#64

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

>Why are people out to crucify Apple for a story that's still being resolved? >The company hasn't denied the bounty, they're just incompetent / slow on this process. People probably expect more from... checks notes The world's most valuable and successful modern corporation.

Ya, if I interpreted this right, also really convenient that they seem to be dragging their feet on a $100,000 bounty.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#65

Zerodium ( https://zerodium.com/program.html ) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal. Next time someone finds one of these, I wonder where they will report it to….

Zerodium doesn't list "information disclosure" for smartphones. "Information disclosure" from an email server means exfiltrating the emails. Zerodium will almost certainly not outbid Apple for the `gamed` vulnerability here (maybe for publicity).

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#66

Zerodium ( https://zerodium.com/program.html ) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal. Next time someone finds one of these, I wonder where they will report it to….

Is it moral though? What do they do with these exploits? If it is to help advance the agendas of countries like Israel and Saudi Arabia how would you feel submitting exploits to them?

They sell them to the IC.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#67

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

I understand what you're saying and in most cases, most companies, most products, you are correct and I would absolutely agree. In this case it is an IOS zero-day. I'm not sure of the number of people on the planet using IOS but the chances of that zero-day being applicable to the phone in your pocket at one point aren't too bad. I do think Apple should be held responsible, their massive amount of sales has given them a massive amount of responsibility that they are not stepping up to.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#68
post #24

Earlier quoted context omitted.

>And thereby accomplishing what, exactly? ...$$$$?

I could accomplish the same thing by robbing a bank - doesn’t make it the right thing to do.

Robbing a bank is immoral, selling information about how a piece of software works, in my humble opinion, is not. Or if it is, then it's not even close to the level of "wrong" that is robbing a bank.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#69

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

> they're just incompetent / slow on this process

> I feel for company leaders in this kind of shitty journalism

You're not making sense. Plus Apple has a history of being incompetent and slow on this.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#70

Zerodium ( https://zerodium.com/program.html ) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal. Next time someone finds one of these, I wonder where they will report it to….

Is it moral though? What do they do with these exploits? If it is to help advance the agendas of countries like Israel and Saudi Arabia how would you feel submitting exploits to them?

You can choose between a rich murderous dictator and an arrogant IT company that does not give you a proper credit. Either way you are screwed as a security researcher :(
Post reply on HN