Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

151–160 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#151
post #127
post #48

Earlier quoted context omitted.

Can't we hope they go for full-disclosure instead of selling to the highest bidder? Selling to the highest bidder just hurts apple users not apple.

Apple hurts Apple users all the time.

So? Someone else doing something bad doesn't mean you should to.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#152

Earlier quoted context omitted.

Some security people love to hand-wave and issue prophecies of doom for attribution and attention. It’s great chum for writers — easier to run with some guys grievance than research a more substantive story.

There's a spectrum of quality to these stories, and one sign that you're tending towards an end of that spectrum is the use of the term "zero-day" without qualification. These are bug bounties; all of these bugs are zero days , no matter how severe (or not) they are. It's literally the least important detail in the story about how a bounty is being handled.

Are there lots of articles that describe zero-days but don't include the actual term "zero-day"? I may have been underestimating the state of journalism...

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#153

Earlier quoted context omitted.

You know what gets weaponised? Actual weapons our government sold to Saudi and other's.

One of these things doesn't negate or excuse the other; both can happen at the same time. You're engaging in "whataboutism".

Important information about "whataboutism":

https://theoutline.com/post/8610/united-states-russia-whatab...

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#154

Earlier quoted context omitted.

Trillion dollar companies are people under the US constitution and they don't seem to care about that so why should everyday citizens?

Because if everyday citizens care the policies will change.

If that was the solution to surveillance capitalism, Apple wouldn't be the biggest company in the world.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#155
post #124
post #61

Earlier quoted context omitted.

Devil's advocate here: I've worked the other side of managing bug bounties. It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it. When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't sha…

I have also worked on managing bug bounties and that is why you keep lines of communication open with the researchers. Not to throw stones in glass houses, but there are a number of ways Apple could improve on their approach to how they do their bug bounty program. I have heard of many researchers having extremely long delays, poor communication and simple things like not acknowledging the bug submissions.

Aftering filing multiple bug reports with Apple now against WkWebView, I can say that extremely long delays and poor communication is not isolated to the bug bounty team :)

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#156

Earlier quoted context omitted.

Why wouldn't the company communicate to the researcher "we found a larger issue related to this. your bounty will be upgraded to X. Please restart the clock for public disclosure" or something along those lines. Seems like better communication would create a win-win situation.

My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…

I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere. No maybe the shadiness inherent in the field means no one trusts that agreement anyway, but I suspect there's generally some amount of trust for researchers submitting vulnerabilities, particularly if they have some kind of history of good faith.

Also, I'm not sure that saying "we have discovered a deeper problem that here beyond what you reported" really delivers much information beyond perhaps telling the researcher to keep investigating (although if they're already getting the bounty, the additional investigation wouldn't really be useful).

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#157

Earlier quoted context omitted.

My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…

I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere. No maybe the shadiness inherent in the field means no one trusts that agreement anyway, but I suspect there's generally some amount of trust for researchers submitting vulnerabilities, particularly if they have some kind of history of good faith. Also, I'm not sure that saying "we have discovered a deeper p…

> would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere

Having an e-mail from the company confirming the bug is serious and systemic massively raises its market value. Security is necessarily trust less. These game dynamics are unavoidable.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#158
post #61

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

Devil's advocate here: I've worked the other side of managing bug bounties. It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it. When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't sha…

Why withhold payment though?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#159

Earlier quoted context omitted.

My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…

I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere. No maybe the shadiness inherent in the field means no one trusts that agreement anyway, but I suspect there's generally some amount of trust for researchers submitting vulnerabilities, particularly if they have some kind of history of good faith. Also, I'm not sure that saying "we have discovered a deeper p…

> I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere.

That is a very mistaken assumption. Even NDAs backed by threats from nation state intelligence agencies aren’t sufficient to keep exploits from being resold multiple times.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#160

Earlier quoted context omitted.

>Why are people out to crucify Apple for a story that's still being resolved? >The company hasn't denied the bounty, they're just incompetent / slow on this process. People probably expect more from... checks notes The world's most valuable and successful modern corporation.

And iOS users should be grateful that they report those bugs to Apple to get paid. They could also sell it to some spying companies and may be those pay well and very fast

> and may be those pay well and very fast

Pay very well? Often, assuming they actually pay, sometimes you can get stiffed there too. Very fast? Nope. Easy to work with? Nope. Communicate with you any better than Apple through the process? Not usually.

Post reply on HN