Earlier quoted context omitted.
Is it moral though? What do they do with these exploits? If it is to help advance the agendas of countries like Israel and Saudi Arabia how would you feel submitting exploits to them?
You can choose between a rich murderous dictator and an arrogant IT company that does not give you a proper credit. Either way you are screwed as a security researcher :(
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
171–180 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#172Earlier quoted context omitted.
It would indeed be a next-level conspiracy theory to suggest the NSA planted an employee at Apple to introduce a GameCenter bug that lets you read a cache of contacts, rather than, you know, just taking the whole device over, which is what "zero day" usually implies.
zero day only implies that it is novel, day 0 of something being in the wild.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#173Earlier quoted context omitted.
> Plus Apple has a history of being incompetent and slow on this Have they, really? Just because you find this instance here and there of such a story where they were, doesn't mean they have a history of being incompetent and slow on this (the same way someone who hit 99% of their three-pointers doesn't have a history of being an awful shooter). That's how they fare long term: https://www.pandasecurity.com/en/mediace…
Apple's bug bounty is notoriously slow to respond, to the point that it has posed legitimate security concerns in the past: particularly their rhetoric around Thunderspy amused me. https://habr.com/en/post/579714/ https://thunderspy.io
Or to put it another way, when you poll people who complain Apple is notoriously slow to respond, don't be surprised if your conclusion is that Apple is notoriously slow to respond.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#174This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.
Are these comments real? They are surprisingly close minded for a hacker news site. If you can't see the value apple offers, that's fine, but to be blind to what they offer others seems odd. I've yet to be scammed by apple's app store. Ie, I can cancel my subscriptions easily, bad apps you can even get a refund on if prompt etc. I have been repeatedly screwed by websites run by developers outside of apple. These webs…
It's especially pronounced in Apple-related threads (one of the few topics that I browse HN for as there are a lot of topics I have no experience or expertise in) where all the nuance seems to have been zapped away as of late. It's either you're a complete Apple hater or a complete Apple fanboi and there's no in-between anymore. I have lots of criticisms of Apple but it seems like there's nowhere to discuss them anymore because they're immediately taken over by "Apple wants to scan your phone" and "Apple is suing mom and pop repair shops" or other hot takes that completely misunderstand their situations.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#175Earlier quoted context omitted.
> Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? Anyone who actually pays money or golden bars within a reasonable timeframe? > It's a significant vulnerability, but there's e.g. no price list entry on Zerodium On this scale I think it's "Contact us and we negotiate" sort of price.
Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them. Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exf…
Cellebrite and all the surveillance-as-a-service shops might be interested in information disclosure bugs. You maybe will not get the $100K Apple promised, but maybe you can sell it four times for $30K or something like that if the bug is still "good enough" for certain uses.
RCEs in Windows or iOS go for a lot more than a measly $100K if you can manage to get in contact with the right people. Think 10-20 times that.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#176Apple definitely needs to improve its processes in order to ensure he and others gets credit. But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite…
That’s not clear at all. I’d be twitchy too if I had $100k on the line and the other party had repeatedly messed up over months of interactions.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#177Earlier quoted context omitted.
If you want to lobby for the law that enables that to happen, I'm happy to sign your petition, but I wouldn't get your hopes up.
It's called the GDPR. Places other than the US exist, and the bug reporter seems to be an EU resident.
E.g. one of the first GDPR fines here in Germany was issued against a company that had their customer DB dumped[0], specifically for still storing some user passwords in plaintext.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#178Earlier quoted context omitted.
Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them. Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exf…
>Who? Cellebrite and all the surveillance-as-a-service shops might be interested in information disclosure bugs. You maybe will not get the $100K Apple promised, but maybe you can sell it four times for $30K or something like that if the bug is still "good enough" for certain uses. RCEs in Windows or iOS go for a lot more than a measly $100K if you can manage to get in contact with the right people. Think 10-20 times…
This is a bug that allows you to read contacts from a malicious app installed from the app store. It's not drive-by contract exfiltration; it's intensively interactive. I'm surprised the Apple bounty terms are so generous-sounding about bugs like these, but I read them, and I'm not contesting the $100k the article claims this is worth.
Apple can't really outbid the grey market on RCEs, but they have clearly outbid it on this bug.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#179Earlier quoted context omitted.
People worried about the morality aspect could sell the exploit, donate the money and report the issue to the manufacturer anyways.
What makes you think the seller’s donation is going to counterbalance the harm of his now-weaponized exploit?
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#180Earlier quoted context omitted.
that is, unfortunately, not at all how the bug-bounty market works. Apple (or any other tech company) can't outbid three-letter-agencies, certainly not on a regular basis. Open market value is at least 10x higher than companies will pay directly. Apple will pay a million bucks? Fine, NSA TAO will pay $10m. Apple can't pay $10m or $100m a bug on a regular basis, for the customers whom this matters the check is basical…
How does one contact the NSA TAO and offer to sell a zero-day?