Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

161–170 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#161

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

Let me selectively quote you:

> Why are people out to crucify Apple (...), they're just incompetent / slow on this process.

That's exactly the problem when they're endangering the security of approximately one billion users.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#162

Earlier quoted context omitted.

PinePhone is our only hope! Still a ways off from being consumer ready but it's heading in the right direction.

"Only option"? What about Purism phones?

While they do seem to be shipping every so slowly they're still stuck on orders from the initial crowd funding campaign from 2018.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#163
post #147

Earlier quoted context omitted.

Apple should be paying enough money that that issue is not a consideration. If I’m Apple (or anyone else for that matter) I’m paying absolute top dollar times two to resolve these issues. And I’m not even thinking twice about it.

that is, unfortunately, not at all how the bug-bounty market works. Apple (or any other tech company) can't outbid three-letter-agencies, certainly not on a regular basis. Open market value is at least 10x higher than companies will pay directly. Apple will pay a million bucks? Fine, NSA TAO will pay $10m. Apple can't pay $10m or $100m a bug on a regular basis, for the customers whom this matters the check is basical…

How does one contact the NSA TAO and offer to sell a zero-day?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#164
post #64

Earlier quoted context omitted.

>Why are people out to crucify Apple for a story that's still being resolved? >The company hasn't denied the bounty, they're just incompetent / slow on this process. People probably expect more from... checks notes The world's most valuable and successful modern corporation.

Ya, if I interpreted this right, also really convenient that they seem to be dragging their feet on a $100,000 bounty.

Nobody's going to pay $100,000 for a bug that lets you download someone's contact list.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#165
post #93

Earlier quoted context omitted.

Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them. Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exf…

Your comments are the only ones here which aren’t divorced from reality. It’s weird. Who are these supposed guys paying six figures for this sort of thing? It’s just not a valuable thing.

I'm with you. I think these cheap, Apple-bashing blogs want to make this into a bigger deal but there are a few things that don't add up to make this the huge issue they think it is:

1. The bug lets you download contacts. Nothing else. As you've said, no one's going to pay six figures for a bug that lets you get someone's contacts from GameCenter. If this was even slightly more abstract and didn't specifically deal with just GameCenter, I could see it being valuable for companies that do phone-to-phone transfers, for example, because you could download someone's contacts from a locked device. This isn't that, though.

2. Nowhere in the article, or even the original tweet, does Apple acknowledge or state that he was the person that initially found the bug. They just confirmed that the bug exists and asked him to keep it confidential. It's entirely possible that the reason for the delay is because someone discovered a lower-level bug that rolled up to this and it's a bit less clear-cut who is owed the credit for the fix that they released. They're not just going to go around and pay everyone who claims to have found a bug. They have to verify it and make sure that it's not something they've already discovered through another report or on their own.

3. Sometimes this stuff just takes time. When you're dealing with codebases that as large as this, changing a small thing to fix a bug can unintentionally break a bunch of other things. It's not always a simple matter of "this small piece is broken and is completely independent of everything else". We have no idea if this is or isn't one of those cases because we don't really know much about it (and for good reason).

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#166

Earlier quoted context omitted.

I could accomplish the same thing by robbing a bank - doesn’t make it the right thing to do.

Doesn't make free work for a for trillion dollar corporation something noble to do. By that logic, a grocery store giving away everything for free is the right thing to do. Doesn't lead to anything sustainable though.

What suggests that any of this is "free work for a trillion dollar corporation"? Apple hasn't acknowledged that this person discovered this bug yet. They've only acknowledged that it existed and that they were going to patch it in the future. Crediting someone for a bug bounty isn't as easy as you all are making it out to be.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#167
post #85

Earlier quoted context omitted.

Except that as this thread demonstrates, there is no realistic possibility of this researcher actually making more $$$ in real life by trying to find another bidder.

Zerodium pays more for the exploits, and unlike Apple, is willing to compensate you in non-traceable currency.

Not for this exploit. They pay more for code-execution exploits. No one is going to pay the sums you guys are thinking they will over a bug that gives you someone's GameCenter contacts. It's not a trivial bug but it's also not a very valuable one.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#168

Zerodium ( https://zerodium.com/program.html ) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal. Next time someone finds one of these, I wonder where they will report it to….

>iOS “information disclosure” exploit (likely what this would have fallen under)

Based on what? There's nothing to suggest that this falls into the category for an "information disclosure" according to Zerodium's eligibility guidelines.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#169
post #65

Zerodium ( https://zerodium.com/program.html ) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal. Next time someone finds one of these, I wonder where they will report it to….

Zerodium doesn't list "information disclosure" for smartphones. "Information disclosure" from an email server means exfiltrating the emails. Zerodium will almost certainly not outbid Apple for the `gamed` vulnerability here (maybe for publicity).

You seem to be the only person here who actually read the article and understands what the stakes are here. Some of these comments are delusional.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#170

Seems that no credit, no bount, nothing, has become the way that Apple deals with the iBugs Hunters. And all it takes is one of those unsong heros giving up on reporting to Apple and, instead, reporting to some 0-day company, and some ransonware go brrrr

>Seems that no credit, no bount, nothing, has become the way that Apple deals with the iBugs Hunters.

Based on what? You can't possibly know anything about this bug or what stage of the reporting process it's in and Apple regularly pays and credits people for reporting vulnerabilities and other exploits. This specific bug just isn't a high enough priority to elevate it to the level you're describing.

Post reply on HN