Earlier quoted context omitted.
Apple's bug bounty is notoriously slow to respond, to the point that it has posed legitimate security concerns in the past: particularly their rhetoric around Thunderspy amused me. https://habr.com/en/post/579714/ https://thunderspy.io
How can we reasonably say Apple is moving slowly to fix bugs when we don’t know how much work is going on behind the scenes? A slow response can just be a slow response.
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
101–110 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#102Seems that no credit, no bount, nothing, has become the way that Apple deals with the iBugs Hunters. And all it takes is one of those unsong heros giving up on reporting to Apple and, instead, reporting to some 0-day company, and some ransonware go brrrr
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#103Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#104Earlier quoted context omitted.
Yes, they do have some way of using your iCloud account credentials to get to the backup key. Given the level of customer support needed for forgotten backup keys, they have probably chosen this as the lesser of two evils. If you don't like that "feature," don't do iCloud backups. I do direct backups as described in the support link. Apple doesn't have those keys.
I do wonder how much longer local, machine-based backups will continue to be supported. Could easily see a future model dropping the cable entirely, dropping local backup and modestly upping the free iCloud storage.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#105Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#106Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…
Tokarev discovered 4 iOS 0-days, then reported them all to Apple back in May. After months of Apple's continued refusal to fix or even publicly acknowledge all four of the issues, Tokarev made all of them public on GitHub.
Weeks passed, and now it's today. Apple has yet to fix or publicly acknowledge two of the four security vulnerabilities. That should make Apple look bad because it's some fundamentally irresponsible security practices.
Yes, I'm biased. I'm human, not a computer, and it's stuff like this that makes me biased towards Apple. They should receive negative publicity for this, then they should change how they do things. At the very least, app developers and users should be warned about the two issues that have yet to be fixed.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#107Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#108Earlier quoted context omitted.
Is it moral though? What do they do with these exploits? If it is to help advance the agendas of countries like Israel and Saudi Arabia how would you feel submitting exploits to them?
You can choose between a rich murderous dictator and an arrogant IT company that does not give you a proper credit. Either way you are screwed as a security researcher :(
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#109Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…
You're framing this as if it's all about the bounty and Apple just hasn't gotten around to it yet. That's only a small fraction of the story and could easily be forgiven. If I wanted to make Apple look good, I'd focus on that part, but that would be rather biased to ignore the whole picture... Tokarev discovered 4 iOS 0-days, then reported them all to Apple back in May. After months of Apple's continued refusal to fi…
* There are valid reasons that bugs can take longer to fix than you'd expect; the most notable of them is when the bug you found is actually systemic, or has a deep root cause, and the real fix for the vulnerability is more complicated than the surface bug. Without a hard timeline, some shops will work to get the root cause fixed on some bugs even at the cost of an increased timeline, because the patch for the surface bug reveals the pattern and amplifies risk to customers.
* As a reporter, you can take some measure of control over the process back by providing a fixed timeline (like the P0 90 days). There's no negotiation needed; you give the vendor time to fix and they either do or don't, but either way you're going public. That is a valid way to go about things, but may cost you the bounty.
* These things are bug-dependent, and the process that runs for a zero-interaction RCE won't be the same as the process that runs for a bug that requires a malicious app store app and only gives access to the contact database.
* Message boards tend to expect that big vendors can just shell out for the bounty as a show of good faith. It's easy to see why they believe that. It makes sense. But it also creates broken incentives. The limiting reagent on bugs isn't bounty dollars (these are indeed barely even rounding errors to major vendors), but rather programmer time. If you pay out for weak, stuck-in-process bugs, you create incentives that redirect programmer time to those weak bugs and away from more significant bugs; as angry as you can reasonably be about a malicious app being able to snarf your contacts, if you're rational, you're a lot more concerned about memory corruption flaws, which is what you really want people spending their time on.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#110What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.
> Next time I hope he sells his next vuln to the highest bidder And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.
There seems to be the strange wordview where ordinary joe must be morally impeccable but its corporate leadership can be as immoral as they come.
Like the richer you are, the less rules you have to follow. Surelly it should be the other way round?