Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

111–120 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#111

Earlier quoted context omitted.

Robbing a bank is immoral, selling information about how a piece of software works, in my humble opinion, is not. Or if it is, then it's not even close to the level of "wrong" that is robbing a bank.

And what if that information gets weaponized against journalists in an authoritarian regime?

You know what gets weaponised?

Actual weapons our government sold to Saudi and other's.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#112

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

Some security people love to hand-wave and issue prophecies of doom for attribution and attention. It’s great chum for writers — easier to run with some guys grievance than research a more substantive story.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#113

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

Some security people love to hand-wave and issue prophecies of doom for attribution and attention. It’s great chum for writers — easier to run with some guys grievance than research a more substantive story.

There's a spectrum of quality to these stories, and one sign that you're tending towards an end of that spectrum is the use of the term "zero-day" without qualification. These are bug bounties; all of these bugs are zero days, no matter how severe (or not) they are. It's literally the least important detail in the story about how a bounty is being handled.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#114
post #61

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

Devil's advocate here: I've worked the other side of managing bug bounties. It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it. When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't sha…

> In the end it all works out and they get paid out/credited for the original+follow on bug.

I've worked on the company end of bug bounties too, and it does happen that a report just falls through the cracks. Seemingly-inactive reports do need a certain amount of maintenance; you don't want to just trust that everything will work out in the end. (That said, as long as you get responses when you ping the company, things are working in the background.)

(edit to followup: in about 18 months of this, I encountered one report that had fallen through the cracks. Obviously, there might have been others that never came to my attention at all, but the companies are tracking things much more carefully than researchers often assume.)

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#115

Earlier quoted context omitted.

You can choose between a rich murderous dictator and an arrogant IT company that does not give you a proper credit. Either way you are screwed as a security researcher :(

Uh, if your consideration is purely what happens to you , sure. If you have any thought in your mind about what will happen to other people due to your work, then it's nowhere near the same.

Trillion dollar companies are people under the US constitution and they don't seem to care about that so why should everyday citizens?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#116
post #94

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

"Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they failed to credit his analyticsd bug report." "Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories." They didn't give him credit in the last 5 advisories. Reall…

Obviously credit is important for them as a proof of competence. If the company does not give them credits how can they build their business, portfolio. You can jus say I was the one who discovered this.

Every field works in a certain way and when it comes to bounty you want to make a name for yourself. You can't just pull up and say you are the one

But yeah may be they should just sell it to third-parties

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#117

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

>Why are people out to crucify Apple for a story that's still being resolved? >The company hasn't denied the bounty, they're just incompetent / slow on this process. People probably expect more from... checks notes The world's most valuable and successful modern corporation.

And iOS users should be grateful that they report those bugs to Apple to get paid. They could also sell it to some spying companies and may be those pay well and very fast

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#118

Earlier quoted context omitted.

>Why are people out to crucify Apple for a story that's still being resolved? >The company hasn't denied the bounty, they're just incompetent / slow on this process. People probably expect more from... checks notes The world's most valuable and successful modern corporation.

And iOS users should be grateful that they report those bugs to Apple to get paid. They could also sell it to some spying companies and may be those pay well and very fast

Or maybe they don't pay for these bugs at all.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#119
post #12

The need for Linux phones, in a market dominated by two companies and one government, is more than ever! Hope we soon get a usable Linux phone.

PinePhone is our only hope! Still a ways off from being consumer ready but it's heading in the right direction.

"Only option"? What about Purism phones?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#120

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

there is no next highest bidder, you live in a cyberpunk fantasy land
Post reply on HN