Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

141–150 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#141
post #87

Earlier quoted context omitted.

Android doesn't scan your phone and mine it for data. Apps on Android scan your phone and mine it for data. Apps on iOS also scan your phone and mine it for data. The major difference between the two is that Android lets you choose which apps to put on your phone.

"Android" doesn't but Google Play services & bundled apps do

Google Play Services and bundled apps don't have to be enabled and sends less data to Google than the equivalent services on iOS, which must be enabled.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#142

Earlier quoted context omitted.

Why wouldn't the company communicate to the researcher "we found a larger issue related to this. your bounty will be upgraded to X. Please restart the clock for public disclosure" or something along those lines. Seems like better communication would create a win-win situation.

My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…

Apple should be paying enough money that that issue is not a consideration. If I’m Apple (or anyone else for that matter) I’m paying absolute top dollar times two to resolve these issues. And I’m not even thinking twice about it.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#143
post #134
post #42

Earlier quoted context omitted.

It would indeed be a next-level conspiracy theory to suggest the NSA planted an employee at Apple to introduce a GameCenter bug that lets you read a cache of contacts, rather than, you know, just taking the whole device over, which is what "zero day" usually implies.

zero day only implies that it is novel, day 0 of something being in the wild.

The first day that anything is available is technically “day 0”, but if I told you I had a PS5 zero day you’d assume I’d discovered a major compromise of the PS5, not that I’d managed to purchase a console the day they went on sale.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#145

Earlier quoted context omitted.

You know what gets weaponised? Actual weapons our government sold to Saudi and other's.

One of these things doesn't negate or excuse the other; both can happen at the same time. You're engaging in "whataboutism".

If you sell a knife, and it's used for a stabbing, are you culpable? Thousands of people buy knives every day, and most of them don't stab anyone. So unless there was good reason to suspect something, we would say no.

Most zerodays are probably not bought by china to spy on dissidents, they are more like knives. On the contrary, when we sell bombs to Saudis we can be 95% sure they will be used in Yemen.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#147

Earlier quoted context omitted.

My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…

Apple should be paying enough money that that issue is not a consideration. If I’m Apple (or anyone else for that matter) I’m paying absolute top dollar times two to resolve these issues. And I’m not even thinking twice about it.

that is, unfortunately, not at all how the bug-bounty market works. Apple (or any other tech company) can't outbid three-letter-agencies, certainly not on a regular basis. Open market value is at least 10x higher than companies will pay directly.

Apple will pay a million bucks? Fine, NSA TAO will pay $10m. Apple can't pay $10m or $100m a bug on a regular basis, for the customers whom this matters the check is basically blank, as much as it takes.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#149
post #7

Here's a fun conspiracy theory proposed entirely in jest: Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices. So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ulti…

Believe me when I say that all major tech companies have spooks in their ranks. They don't really need to insert backdoors or ignore bugs. They have human assets in the teams.

Ask anyone who works in one of these organisations and they will attest to how many former IC people fill the ranks in certain areas.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#150
post #48

Earlier quoted context omitted.

Can't we hope they go for full-disclosure instead of selling to the highest bidder? Selling to the highest bidder just hurts apple users not apple.

> just hurts apple users not apple. As a first-order effect, sure.. but Apple is not immune to the damage that this causes either. More importantly, their failure to pay or honor their commitments would be the root cause of this in the future. They opened this "bug bounty" door on their own, they are solely responsible for it's success or failure.

Sure there are secondary affects. However they are mild comparatively

The two options:

- someone full discloses a 0-day. Apple is embarrased, users can take mitigating action until its patched. Apple is probably forced to patch. End result: really embarasing for apple. Small risk to users that's pretty ephemeral.

- sell to highest bidder. Black market or at best grey hat. Exploit is used against users. Nobody really knows its happening. Maybe that eventually comes back to give apple a bad reputation, but not likely to happen in the short term.

One of these courses of action disproportionately hurts users a lot and apple not very much. The other hurts basically only apple and users very little. Even if you argue that the black market might eventually hurt apple a little bit, its still a very small hurt.

If your goal is to piss off apple, it seems clear that full-disclosure is the thing to do here. If your goal is just to clear your concious on the morality of selling exploits to bad people who intend to use them to do bad things - while i'm sure you'd find a way to justify that no matter what apple did. The human mind is good at self-justification.

> More importantly, their failure to pay or honor their commitments

What commitment? A bug bounty program isn't a commitment to do anything. Its not a contract or a work agreement. At best its sort of like a contest.

But even disregarding that, i'm not sure this bug even is in any of the categories they list. What they say is: iOS user installed app can access sensitive data including Contacts, Mail, Messages, Notes, Photos, or real-time or historical precise location data. i'm not sure this fits.

Is apple being a dick? Yes. Are they breaking commitments they made? Not super clear.

Post reply on HN