Earlier quoted context omitted.
Android doesn't scan your phone and mine it for data. Apps on Android scan your phone and mine it for data. Apps on iOS also scan your phone and mine it for data. The major difference between the two is that Android lets you choose which apps to put on your phone.
"Android" doesn't but Google Play services & bundled apps do
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
141–150 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#142Earlier quoted context omitted.
Why wouldn't the company communicate to the researcher "we found a larger issue related to this. your bounty will be upgraded to X. Please restart the clock for public disclosure" or something along those lines. Seems like better communication would create a win-win situation.
My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#143Earlier quoted context omitted.
It would indeed be a next-level conspiracy theory to suggest the NSA planted an employee at Apple to introduce a GameCenter bug that lets you read a cache of contacts, rather than, you know, just taking the whole device over, which is what "zero day" usually implies.
zero day only implies that it is novel, day 0 of something being in the wild.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#144Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#145Earlier quoted context omitted.
You know what gets weaponised? Actual weapons our government sold to Saudi and other's.
One of these things doesn't negate or excuse the other; both can happen at the same time. You're engaging in "whataboutism".
Most zerodays are probably not bought by china to spy on dissidents, they are more like knives. On the contrary, when we sell bombs to Saudis we can be 95% sure they will be used in Yemen.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#146Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#147Earlier quoted context omitted.
My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…
Apple should be paying enough money that that issue is not a consideration. If I’m Apple (or anyone else for that matter) I’m paying absolute top dollar times two to resolve these issues. And I’m not even thinking twice about it.
Apple will pay a million bucks? Fine, NSA TAO will pay $10m. Apple can't pay $10m or $100m a bug on a regular basis, for the customers whom this matters the check is basically blank, as much as it takes.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#148What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#149Here's a fun conspiracy theory proposed entirely in jest: Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices. So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ulti…
Ask anyone who works in one of these organisations and they will attest to how many former IC people fill the ranks in certain areas.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#150Earlier quoted context omitted.
Can't we hope they go for full-disclosure instead of selling to the highest bidder? Selling to the highest bidder just hurts apple users not apple.
> just hurts apple users not apple. As a first-order effect, sure.. but Apple is not immune to the damage that this causes either. More importantly, their failure to pay or honor their commitments would be the root cause of this in the future. They opened this "bug bounty" door on their own, they are solely responsible for it's success or failure.
The two options:
- someone full discloses a 0-day. Apple is embarrased, users can take mitigating action until its patched. Apple is probably forced to patch. End result: really embarasing for apple. Small risk to users that's pretty ephemeral.
- sell to highest bidder. Black market or at best grey hat. Exploit is used against users. Nobody really knows its happening. Maybe that eventually comes back to give apple a bad reputation, but not likely to happen in the short term.
One of these courses of action disproportionately hurts users a lot and apple not very much. The other hurts basically only apple and users very little. Even if you argue that the black market might eventually hurt apple a little bit, its still a very small hurt.
If your goal is to piss off apple, it seems clear that full-disclosure is the thing to do here. If your goal is just to clear your concious on the morality of selling exploits to bad people who intend to use them to do bad things - while i'm sure you'd find a way to justify that no matter what apple did. The human mind is good at self-justification.
> More importantly, their failure to pay or honor their commitments
What commitment? A bug bounty program isn't a commitment to do anything. Its not a contract or a work agreement. At best its sort of like a contest.
But even disregarding that, i'm not sure this bug even is in any of the categories they list. What they say is: iOS user installed app can access sensitive data including Contacts, Mail, Messages, Notes, Photos, or real-time or historical precise location data. i'm not sure this fits.
Is apple being a dick? Yes. Are they breaking commitments they made? Not super clear.