Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

91–100 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#91
post #85
post #24

Earlier quoted context omitted.

>And thereby accomplishing what, exactly? ...$$$$?

Except that as this thread demonstrates, there is no realistic possibility of this researcher actually making more $$$ in real life by trying to find another bidder.

Zerodium pays more for the exploits, and unlike Apple, is willing to compensate you in non-traceable currency.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#92
post #27

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.

> Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts?

Anyone who actually pays money or golden bars within a reasonable timeframe?

> It's a significant vulnerability, but there's e.g. no price list entry on Zerodium

On this scale I think it's "Contact us and we negotiate" sort of price.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#93
post #27

Earlier quoted context omitted.

Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.

> Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? Anyone who actually pays money or golden bars within a reasonable timeframe? > It's a significant vulnerability, but there's e.g. no price list entry on Zerodium On this scale I think it's "Contact us and we negotiate" sort of price.

Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them.

Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exfiltrates contact lists from apps that have to be installed from the app store.

The non-bounty market clearing price for a lot of scary sounding vulnerabilities is $0.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#94

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

"Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they failed to credit his analyticsd bug report."

"Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories."

They didn't give him credit in the last 5 advisories. Really no excuse for that imho. If Apple keeps this up then why would anyone report bugs to them when you can just post it online and get credit for it right away? Or sell it on some 0-day site.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#95

Earlier quoted context omitted.

I could accomplish the same thing by robbing a bank - doesn’t make it the right thing to do.

Robbing a bank is immoral, selling information about how a piece of software works, in my humble opinion, is not. Or if it is, then it's not even close to the level of "wrong" that is robbing a bank.

And what if that information gets weaponized against journalists in an authoritarian regime?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#96
The advisory credit and bug bounty fiasco aside, when I reported a security vulnerability to Apple in 2010, they wrote, "Because of the potentially sensitive nature of security vulnerabilities, we ask that this information remain between you and Apple while we investigate it further." It seems to just be a standard inclusion in their correspondence, and not unique to this exchange.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#97
post #79

Earlier quoted context omitted.

> Plus Apple has a history of being incompetent and slow on this Have they, really? Just because you find this instance here and there of such a story where they were, doesn't mean they have a history of being incompetent and slow on this (the same way someone who hit 99% of their three-pointers doesn't have a history of being an awful shooter). That's how they fare long term: https://www.pandasecurity.com/en/mediace…

Apple's bug bounty is notoriously slow to respond, to the point that it has posed legitimate security concerns in the past: particularly their rhetoric around Thunderspy amused me. https://habr.com/en/post/579714/ https://thunderspy.io

How can we reasonably say Apple is moving slowly to fix bugs when we don’t know how much work is going on behind the scenes? A slow response can just be a slow response.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#98
post #94

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

"Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they failed to credit his analyticsd bug report." "Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories." They didn't give him credit in the last 5 advisories. Reall…

Exactly, that's the issue. This is a RT*A scenario.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#99
post #94

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

"Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they failed to credit his analyticsd bug report." "Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories." They didn't give him credit in the last 5 advisories. Reall…

If credit is what you care about, it's straightforward to ensure you get credit without working with Apple's bounty program. You can do what P0 does and provide a fixed timeline after which you're publishing, and nobody credible is going to hold that against you (in part because P0 has established this norm).

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#100

This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.

Are these comments real? They are surprisingly close minded for a hacker news site.

If you can't see the value apple offers, that's fine, but to be blind to what they offer others seems odd.

I've yet to be scammed by apple's app store. Ie, I can cancel my subscriptions easily, bad apps you can even get a refund on if prompt etc.

I have been repeatedly screwed by websites run by developers outside of apple. These websites have been LOADED with trackers, they have impossible to cancel subscriptions, they do all sorts of dirty tricks (I'm tired of the intercom type follow-up emails - sorry I missed you, give me one last chance etc).

I get it, the dog eat dog crapfest is appealing to some, but Apple offers an alternative, and for some people that has value. And yes, I get it, the folks making these eye blinding slow websites have lots to say about apple, but my weather app opens promptly on apple, whereas the ad littered weather pages online bog my machine (with 100x the memory) down.

Post reply on HN