Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

171–180 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#171

Earlier quoted context omitted.

Is it moral though? What do they do with these exploits? If it is to help advance the agendas of countries like Israel and Saudi Arabia how would you feel submitting exploits to them?

You can choose between a rich murderous dictator and an arrogant IT company that does not give you a proper credit. Either way you are screwed as a security researcher :(

There is a really simple solution to this. Just not put your time in analyzing software from Apple. There is other software you could analyze. Just go to a walk or count your toes. Everything makes more sense then searching security bugs in Apple software when you care about moral.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#172
post #134
post #42

Earlier quoted context omitted.

It would indeed be a next-level conspiracy theory to suggest the NSA planted an employee at Apple to introduce a GameCenter bug that lets you read a cache of contacts, rather than, you know, just taking the whole device over, which is what "zero day" usually implies.

zero day only implies that it is novel, day 0 of something being in the wild.

That's true, but the implication of "zero day" in a new story is code execution, because those are the only zero days that make the news. You can just read this thread and see that several people commenting here clearly believe these bugs were comparable to code execution. The article, uh, does not go out of its way to clear up the ambiguity.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#173
post #79

Earlier quoted context omitted.

> Plus Apple has a history of being incompetent and slow on this Have they, really? Just because you find this instance here and there of such a story where they were, doesn't mean they have a history of being incompetent and slow on this (the same way someone who hit 99% of their three-pointers doesn't have a history of being an awful shooter). That's how they fare long term: https://www.pandasecurity.com/en/mediace…

Apple's bug bounty is notoriously slow to respond, to the point that it has posed legitimate security concerns in the past: particularly their rhetoric around Thunderspy amused me. https://habr.com/en/post/579714/ https://thunderspy.io

Is this not a potential Sharpshooter fallacy? Are you sure that we aren't mainly hearing about bounties when Apple doesn't handle them smoothly and not so much when they are handled smoothly?

Or to put it another way, when you poll people who complain Apple is notoriously slow to respond, don't be surprised if your conclusion is that Apple is notoriously slow to respond.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#174

This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.

Are these comments real? They are surprisingly close minded for a hacker news site. If you can't see the value apple offers, that's fine, but to be blind to what they offer others seems odd. I've yet to be scammed by apple's app store. Ie, I can cancel my subscriptions easily, bad apps you can even get a refund on if prompt etc. I have been repeatedly screwed by websites run by developers outside of apple. These webs…

I have a feeling that HN recently had an influx of users from other sites. It seems like the exodus from Reddit, for example, has resulted in a significantly larger signal to noise ratio of comments. There's a lot more impassioned nonsense that's based on article headlines rather than detailed discussion of technology and either it's just more pronounced because of the pandemic or it's actually new users that are diluting the comments.

It's especially pronounced in Apple-related threads (one of the few topics that I browse HN for as there are a lot of topics I have no experience or expertise in) where all the nuance seems to have been zapped away as of late. It's either you're a complete Apple hater or a complete Apple fanboi and there's no in-between anymore. I have lots of criticisms of Apple but it seems like there's nowhere to discuss them anymore because they're immediately taken over by "Apple wants to scan your phone" and "Apple is suing mom and pop repair shops" or other hot takes that completely misunderstand their situations.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#175
post #93

Earlier quoted context omitted.

> Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? Anyone who actually pays money or golden bars within a reasonable timeframe? > It's a significant vulnerability, but there's e.g. no price list entry on Zerodium On this scale I think it's "Contact us and we negotiate" sort of price.

Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them. Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exf…

>Who?

Cellebrite and all the surveillance-as-a-service shops might be interested in information disclosure bugs. You maybe will not get the $100K Apple promised, but maybe you can sell it four times for $30K or something like that if the bug is still "good enough" for certain uses.

RCEs in Windows or iOS go for a lot more than a measly $100K if you can manage to get in contact with the right people. Think 10-20 times that.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#176
post #36

Apple definitely needs to improve its processes in order to ensure he and others gets credit. But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite…

That’s not clear at all. I’d be twitchy too if I had $100k on the line and the other party had repeatedly messed up over months of interactions.

He doesn't have $100k on the line. That's ridiculous.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#177

Earlier quoted context omitted.

If you want to lobby for the law that enables that to happen, I'm happy to sign your petition, but I wouldn't get your hopes up.

It's called the GDPR. Places other than the US exist, and the bug reporter seems to be an EU resident.

The GDPR indeed has provisions to fine companies for "avoidable" data leaks due to lacking security practices. The regulators will not pay you a bounty for reporting companies, and there is a big difference between a normal "bug" and "bad practices".

E.g. one of the first GDPR fines here in Germany was issued against a company that had their customer DB dumped[0], specifically for still storing some user passwords in plaintext.

[0] https://gdprhub.eu/index.php?title=LfDI_-_O_1018/115

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#178
post #93

Earlier quoted context omitted.

Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them. Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exf…

>Who? Cellebrite and all the surveillance-as-a-service shops might be interested in information disclosure bugs. You maybe will not get the $100K Apple promised, but maybe you can sell it four times for $30K or something like that if the bug is still "good enough" for certain uses. RCEs in Windows or iOS go for a lot more than a measly $100K if you can manage to get in contact with the right people. Think 10-20 times…

Full chain RCEs in iOS go for 1MM from the Apple bounty program, so you'd imagine they'd have to go for more than that from a tranched grey market contract.

This is a bug that allows you to read contacts from a malicious app installed from the app store. It's not drive-by contract exfiltration; it's intensively interactive. I'm surprised the Apple bounty terms are so generous-sounding about bugs like these, but I read them, and I'm not contesting the $100k the article claims this is worth.

Apple can't really outbid the grey market on RCEs, but they have clearly outbid it on this bug.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#179

Earlier quoted context omitted.

People worried about the morality aspect could sell the exploit, donate the money and report the issue to the manufacturer anyways.

What makes you think the seller’s donation is going to counterbalance the harm of his now-weaponized exploit?

The report to the manufacturer with the remark that there is a existing weaponized exploit will lead to a much faster fix. And why you are so sure that there was no weaponized exploit out there before?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#180
post #163
post #147

Earlier quoted context omitted.

that is, unfortunately, not at all how the bug-bounty market works. Apple (or any other tech company) can't outbid three-letter-agencies, certainly not on a regular basis. Open market value is at least 10x higher than companies will pay directly. Apple will pay a million bucks? Fine, NSA TAO will pay $10m. Apple can't pay $10m or $100m a bug on a regular basis, for the customers whom this matters the check is basical…

How does one contact the NSA TAO and offer to sell a zero-day?

One doesn't, I don't think; I think one sells to one of several grey-market brokers who in turn sell to DOD. But I think it's more productive to substitute "the IC" for "NSA TAO", because there are several countries (on the "sort of legitimate" side of this market) buying. All of them can pull any plausible amount of cash for a vulnerability out of their couch cushions (then again, so can small countries).
Post reply on HN