Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…
Devil's advocate here: I've worked the other side of managing bug bounties. It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it. When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't sha…
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
121–130 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#122Earlier quoted context omitted.
I do wonder how much longer local, machine-based backups will continue to be supported. Could easily see a future model dropping the cable entirely, dropping local backup and modestly upping the free iCloud storage.
iPhones have supported Wifi backup to local computer for a decade now.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#123What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.
Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#124Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…
Devil's advocate here: I've worked the other side of managing bug bounties. It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it. When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't sha…
I have heard of many researchers having extremely long delays, poor communication and simple things like not acknowledging the bug submissions.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#125Earlier quoted context omitted.
You're framing this as if it's all about the bounty and Apple just hasn't gotten around to it yet. That's only a small fraction of the story and could easily be forgiven. If I wanted to make Apple look good, I'd focus on that part, but that would be rather biased to ignore the whole picture... Tokarev discovered 4 iOS 0-days, then reported them all to Apple back in May. After months of Apple's continued refusal to fi…
I don't know anything about Apple's bug bounty program except that there's a prevailing attitude that it is not the well-oiled machine that Google's bug bounty program is perceived to be, and I'm not super interested in making a case for Apple here. But because this is a recurring theme in every discussion about every bug bounty run by anyone: * There are valid reasons that bugs can take longer to fix than you'd expe…
It would be interesting to understand at what point this becomes a GDPR issue, and if the GDPR legislation can be used to pressure companies in expediting this process.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#126This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.
There is no better alternative (at least for some people)? Just some examples: - Integration between their devices cannot be matched by others - Apple Watch has the largest app collection, great integration between iOS and Watch apps, smooth animations/UX, the most accurate GPS of smart watches - Handover of AirPods between Apple devices is a lot better than with other Bluetooth headphones - (subjective) iOS has a lo…
Nothing matches it. I had some minor issues setting up my newly purchased M1 from an Intel backup, but it was quickly fixed when I updated the OS.
Always, always, always use a directly connected external hard dive. The networked version is terrible.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#127What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.
Can't we hope they go for full-disclosure instead of selling to the highest bidder? Selling to the highest bidder just hurts apple users not apple.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#128Earlier quoted context omitted.
Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.
Ideally it would be a privacy regulator who would issue a 7 figure fine and give the reporter a cut.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#129Earlier quoted context omitted.
I don't know anything about Apple's bug bounty program except that there's a prevailing attitude that it is not the well-oiled machine that Google's bug bounty program is perceived to be, and I'm not super interested in making a case for Apple here. But because this is a recurring theme in every discussion about every bug bounty run by anyone: * There are valid reasons that bugs can take longer to fix than you'd expe…
> * These things are bug-dependent, and the process that runs for a zero-interaction RCE won't be the same as the process that runs for a bug that requires a malicious app store app and only gives access to the contact database. It would be interesting to understand at what point this becomes a GDPR issue, and if the GDPR legislation can be used to pressure companies in expediting this process.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#130Earlier quoted context omitted.
> Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? Anyone who actually pays money or golden bars within a reasonable timeframe? > It's a significant vulnerability, but there's e.g. no price list entry on Zerodium On this scale I think it's "Contact us and we negotiate" sort of price.
Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them. Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exf…