Earlier quoted context omitted.
>And thereby accomplishing what, exactly? ...$$$$?
Except that as this thread demonstrates, there is no realistic possibility of this researcher actually making more $$$ in real life by trying to find another bidder.
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
91–100 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#92What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.
Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.
Anyone who actually pays money or golden bars within a reasonable timeframe?
> It's a significant vulnerability, but there's e.g. no price list entry on Zerodium
On this scale I think it's "Contact us and we negotiate" sort of price.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#93Earlier quoted context omitted.
Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.
> Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? Anyone who actually pays money or golden bars within a reasonable timeframe? > It's a significant vulnerability, but there's e.g. no price list entry on Zerodium On this scale I think it's "Contact us and we negotiate" sort of price.
Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exfiltrates contact lists from apps that have to be installed from the app store.
The non-bounty market clearing price for a lot of scary sounding vulnerabilities is $0.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#94Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…
"Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories."
They didn't give him credit in the last 5 advisories. Really no excuse for that imho. If Apple keeps this up then why would anyone report bugs to them when you can just post it online and get credit for it right away? Or sell it on some 0-day site.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#95Earlier quoted context omitted.
I could accomplish the same thing by robbing a bank - doesn’t make it the right thing to do.
Robbing a bank is immoral, selling information about how a piece of software works, in my humble opinion, is not. Or if it is, then it's not even close to the level of "wrong" that is robbing a bank.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#96Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#97Earlier quoted context omitted.
> Plus Apple has a history of being incompetent and slow on this Have they, really? Just because you find this instance here and there of such a story where they were, doesn't mean they have a history of being incompetent and slow on this (the same way someone who hit 99% of their three-pointers doesn't have a history of being an awful shooter). That's how they fare long term: https://www.pandasecurity.com/en/mediace…
Apple's bug bounty is notoriously slow to respond, to the point that it has posed legitimate security concerns in the past: particularly their rhetoric around Thunderspy amused me. https://habr.com/en/post/579714/ https://thunderspy.io
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#98Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…
"Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they failed to credit his analyticsd bug report." "Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories." They didn't give him credit in the last 5 advisories. Reall…
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#99Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…
"Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they failed to credit his analyticsd bug report." "Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories." They didn't give him credit in the last 5 advisories. Reall…
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#100This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.
If you can't see the value apple offers, that's fine, but to be blind to what they offer others seems odd.
I've yet to be scammed by apple's app store. Ie, I can cancel my subscriptions easily, bad apps you can even get a refund on if prompt etc.
I have been repeatedly screwed by websites run by developers outside of apple. These websites have been LOADED with trackers, they have impossible to cancel subscriptions, they do all sorts of dirty tricks (I'm tired of the intercom type follow-up emails - sorry I missed you, give me one last chance etc).
I get it, the dog eat dog crapfest is appealing to some, but Apple offers an alternative, and for some people that has value. And yes, I get it, the folks making these eye blinding slow websites have lots to say about apple, but my weather app opens promptly on apple, whereas the ad littered weather pages online bog my machine (with 100x the memory) down.