Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

181–190 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#181

Earlier quoted context omitted.

My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…

I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere. No maybe the shadiness inherent in the field means no one trusts that agreement anyway, but I suspect there's generally some amount of trust for researchers submitting vulnerabilities, particularly if they have some kind of history of good faith. Also, I'm not sure that saying "we have discovered a deeper p…

None of us are thinking of any of this before the brokers already have; this work has been going on for many, many years. You can resell vulnerabilities, but the contract terms you get from brokers are tranched, and they stop paying when the vulnerability is burned. Your incentive not to spread your bug around is that you you're cutting your nose off to spite your face, not to mention that you're probably making the terms you'll get for future bugs worse.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#182
post #82

I wish Apple would do a feature freeze for iOS and macOS for a couple of years, then focus on fixing bugs, improving security and optimizing performance instead.

All of those things are actually more likely to cause new bugs than feature development, not less.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#183

Earlier quoted context omitted.

I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere. No maybe the shadiness inherent in the field means no one trusts that agreement anyway, but I suspect there's generally some amount of trust for researchers submitting vulnerabilities, particularly if they have some kind of history of good faith. Also, I'm not sure that saying "we have discovered a deeper p…

> would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere Having an e-mail from the company confirming the bug is serious and systemic massively raises its market value. Security is necessarily trust less. These game dynamics are unavoidable.

Having an email from the company confirming that they know about the bug probably erases its market value.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#184

Earlier quoted context omitted.

>Who? Cellebrite and all the surveillance-as-a-service shops might be interested in information disclosure bugs. You maybe will not get the $100K Apple promised, but maybe you can sell it four times for $30K or something like that if the bug is still "good enough" for certain uses. RCEs in Windows or iOS go for a lot more than a measly $100K if you can manage to get in contact with the right people. Think 10-20 times…

Full chain RCEs in iOS go for 1MM from the Apple bounty program , so you'd imagine they'd have to go for more than that from a tranched grey market contract. This is a bug that allows you to read contacts from a malicious app installed from the app store. It's not drive-by contract exfiltration; it's intensively interactive. I'm surprised the Apple bounty terms are so generous-sounding about bugs like these, but I re…

Yes, I agree with this assessment of this particular bug. As far as this bug goes, from the description, this particular one probably not very valuable to anybody. You have to get an app into the app store and then trick people to install it for not that much information you can exfiltrate. If it was a bug that allowed attackers to exfiltrate contacts and email addresses and such just by having the victim visit a website or open an email, that would be another matter, and still quite valuable even tho it wouldn't be RCE.

But who knows, it still might worth a few bucks to you because you already figure out the delivery. And your relationship to somebody with the skills to find interesting bugs and willingness to sell to you might be even worth more, so you might pay money not just for the bug but for the relationship.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#185

Zerodium ( https://zerodium.com/program.html ) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal. Next time someone finds one of these, I wonder where they will report it to….

See my comment history for a firsthand account of Zerodium.

Hah! That was a fun read :)

If you're ever in Amsterdam and feel up for drinking a beer [0] with someone interested in netsec [1], feel free to email me.

[0] Or coffee, tea, your beverage of choice.

[1] I did a couple of fairly good security courses and about 300 hours of hackthebox.eu. So while I'm not a professional, at least I've scripted with IDA Python and defeated fun boxes like PlayerTwo.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#186

Earlier quoted context omitted.

What makes you think the seller’s donation is going to counterbalance the harm of his now-weaponized exploit?

The report to the manufacturer with the remark that there is a existing weaponized exploit will lead to a much faster fix. And why you are so sure that there was no weaponized exploit out there before?

So you are okay with submitting the exploit on a silver platter to people who murder dissidents because “you can’t be so sure that there wasn’t an existing weaponized exploit”?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#187
post #163
post #147

Earlier quoted context omitted.

that is, unfortunately, not at all how the bug-bounty market works. Apple (or any other tech company) can't outbid three-letter-agencies, certainly not on a regular basis. Open market value is at least 10x higher than companies will pay directly. Apple will pay a million bucks? Fine, NSA TAO will pay $10m. Apple can't pay $10m or $100m a bug on a regular basis, for the customers whom this matters the check is basical…

How does one contact the NSA TAO and offer to sell a zero-day?

> We pay big bounties

https://zerodium.com/

>One person who will share those sales numbers is a South African hacker who goes by the name “the Grugq” and lives in Bangkok. For just over a year the Grugq has been supplementing his salary as a security researcher by acting as a broker for high-end exploits, connecting his hacker friends with buyers among his government contacts. He says he takes a 15% commission on sales and is on track to earn more than $1 million from the deals this year. “I refuse to deal with anything below mid-five-figures these days,” he says. In December of last year alone he earned $250,000 from his government buyers. “The end-of-year budget burnout was awesome.”

https://www.forbes.com/sites/andygreenberg/2012/03/21/meet-t...

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#188
post #155
post #124

Earlier quoted context omitted.

I have also worked on managing bug bounties and that is why you keep lines of communication open with the researchers. Not to throw stones in glass houses, but there are a number of ways Apple could improve on their approach to how they do their bug bounty program. I have heard of many researchers having extremely long delays, poor communication and simple things like not acknowledging the bug submissions.

Aftering filing multiple bug reports with Apple now against WkWebView, I can say that extremely long delays and poor communication is not isolated to the bug bounty team :)

Security bugs are much more important than other bugs. A security bug that's affecting no one currently could turn into a disaster tomorrow. A functionality bug that's affecting few people today will almost certainly affect few people tomorrow.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#189
post #64

Earlier quoted context omitted.

Ya, if I interpreted this right, also really convenient that they seem to be dragging their feet on a $100,000 bounty.

Nobody's going to pay $100,000 for a bug that lets you download someone's contact list.

How much would a bug like that be worth? I can imagine getting anyone's contact list being valuable.
Post reply on HN