Earlier quoted context omitted.
Is it moral though? What do they do with these exploits? If it is to help advance the agendas of countries like Israel and Saudi Arabia how would you feel submitting exploits to them?
People worried about the morality aspect could sell the exploit, donate the money and report the issue to the manufacturer anyways.
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
131–140 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#132Earlier quoted context omitted.
Uh, if your consideration is purely what happens to you , sure. If you have any thought in your mind about what will happen to other people due to your work, then it's nowhere near the same.
Trillion dollar companies are people under the US constitution and they don't seem to care about that so why should everyday citizens?
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#133Earlier quoted context omitted.
And what if that information gets weaponized against journalists in an authoritarian regime?
You know what gets weaponised? Actual weapons our government sold to Saudi and other's.
Selling a zero day would probably fall under a weapons clause.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#134Earlier quoted context omitted.
Next level conspiracy theory: Apple employs, knowingly or unknowingly, CIA/NSA agents who intentionally introduce these bugs.
It would indeed be a next-level conspiracy theory to suggest the NSA planted an employee at Apple to introduce a GameCenter bug that lets you read a cache of contacts, rather than, you know, just taking the whole device over, which is what "zero day" usually implies.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#135Earlier quoted context omitted.
Ideally it would be a privacy regulator who would issue a 7 figure fine and give the reporter a cut.
If you want to lobby for the law that enables that to happen, I'm happy to sign your petition, but I wouldn't get your hopes up.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#136Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#137Earlier quoted context omitted.
And what if that information gets weaponized against journalists in an authoritarian regime?
You know what gets weaponised? Actual weapons our government sold to Saudi and other's.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#138Earlier quoted context omitted.
Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them. Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exf…
Your comments are the only ones here which aren’t divorced from reality. It’s weird. Who are these supposed guys paying six figures for this sort of thing? It’s just not a valuable thing.
It's not that bugs of all stripes don't have plausible value. It's that there isn't a market for most of them. Bugs are small parts of the enterprises that exploit them. To purchase a bug for significant amounts of money, it has to slot into some kind of business process that will profitably† take advantage of it.
What people are subtextually observing with these $250k vulnerabilities is that there are a bunch of well-scripted playbooks for profiting from RCE vulnerabilities on widely distributed, unevenly patched devices. There may be no meaningful cap to how much a phone RCE is worth, since the IC's alternative to RCEs is human intelligence work that will dwarf any RCE cost just in health and benefits overhead for personnel.
But there just aren't a lot of business processes that profitably exploit stolen contact lists from malicious application installs. You can come up with lots of stories about those processes, but the key thing is that for a bug to be worth a bunch of money, that process already has to exist and be working; the cost of building all the business process stuff around the bug will rival the cost of the bug itself. Bugs have finite lifespans, and "snarf contacts from malicious app" bugs are idiosyncratic, and tend not to be pin compatible with a steady stream of similar bugs that would justify keeping that exploitative process up and running.
This is for what it's worth all my own personal weird theory of the situation, and I don't sell or buy bugs. But I have repeated the theory to many people who do either or both, and nobody has told me I'm totally wrong about it.
† For some possibly non-economic definition of "profitably"
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#139Earlier quoted context omitted.
> Hopefully more people can get involved and move the needle instead of only lamenting how they don't succeed while not actively trying to help them succeed. That's totally fair. I don't really have the time or Java/Kotlin/mobile familiarity to jump in here, and these aren't skills I can easily apply elsewhere in my career, personally. > LineageOS has been going for quite a while now, CalyxOS is relatively new, and G…
You can run one of those os's without any Google services. Paid apps are almost certain to not run, and a bunch of other apps that rely on the services. But almost all the apps I use work great. I have used CalyxOS and it's a great os. I did use microG and 98% of the apps I use worked flawlessly. If you have a supported phone, I'd definitely give it a shot.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#140Earlier quoted context omitted.
Devil's advocate here: I've worked the other side of managing bug bounties. It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it. When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't sha…
Why wouldn't the company communicate to the researcher "we found a larger issue related to this. your bounty will be upgraded to X. Please restart the clock for public disclosure" or something along those lines. Seems like better communication would create a win-win situation.
Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with.
I would also understand the researcher's point of view that this fell through the cracks or Apple is not willing to fix; and is likely what happened.