Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

191–200 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#191
My friend has just looked on Find My Mac and he can remotely format and track the whereabouts of the Macbook Pro of a guy called “Jason”. He’s never sold or had this MacBook model on his account.

The people in the Apple store provided no fixes but suggested formatting the machine which I guess would be illegal in most places.

It makes me worry that I could be Jason and someone could remotely format my computer… it’s scary that something like this is possible.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#192

Earlier quoted context omitted.

Nobody's going to pay $100,000 for a bug that lets you download someone's contact list.

How much would a bug like that be worth? I can imagine getting anyone's contact list being valuable.

Why? What would be valuable about that? Specifically, what would be valuable about getting someone's GameCenter contacts? These aren't business or family contacts. These are people the person games with. It's a privacy violating bug but not a show-stopping bug. Important but not valuable.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#193

Earlier quoted context omitted.

Apple holds the keys to encrypted iCloud backups.

Yes, they do have some way of using your iCloud account credentials to get to the backup key. Given the level of customer support needed for forgotten backup keys, they have probably chosen this as the lesser of two evils. If you don't like that "feature," don't do iCloud backups. I do direct backups as described in the support link. Apple doesn't have those keys.

It doesn't matter if you don't do iCloud backups. All of your iMessages will be backed up to Apple in ways that Apple/FBI can read because iCloud Backup (not e2e) is on on every device held by the people you are iMessaging with.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#194

This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.

Ignore the software for a moment: nobody makes smartphones or tablets anywhere near the hardware quality of the iPhone or iPad Pro.

Nobody.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#195

Earlier quoted context omitted.

> * These things are bug-dependent, and the process that runs for a zero-interaction RCE won't be the same as the process that runs for a bug that requires a malicious app store app and only gives access to the contact database. It would be interesting to understand at what point this becomes a GDPR issue, and if the GDPR legislation can be used to pressure companies in expediting this process.

There's a "be careful what you wish for" argument here, because my understanding is that the FAANG vendors are snapping up security people just as fast as they possibly can, and, again, ceteris paribus you'd rather have those people working on the actual most serious vulnerabilities rather than the ones causing the noisiest bounty drama. But you could reasonably go either way on this I guess.

The degree of damage done by particular vulnerabilities is different from person to person. For one individual losing their contact database to some un-identified third party might be a 'meh' event, for another it could be a disaster.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#196

iOS 15 from release date has had the most bugs I've ever experienced with any former versions of iOS. Siri would revert back to Dragon style text to speech randomly is one thing I noticed frequently.

A former Apple person reminded me that the new major version iOS must ship on the same day as the new hardware, as the new hardware (this year, the new iPad Mini, and iPhones 13) will not run iOS14. They are developed in lockstep with the next OS and will ship with it, and cannot ship without it.

The software is going out the door alongside the latest version of their biggest money-making product.

Note well how quickly 15.0.1 was released.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#197

Earlier quoted context omitted.

Why wouldn't the company communicate to the researcher "we found a larger issue related to this. your bounty will be upgraded to X. Please restart the clock for public disclosure" or something along those lines. Seems like better communication would create a win-win situation.

My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…

They can’t be that worried - the bug that allows you to input behind the lockscreen on OS X has now been a thing for… six years, over three or four versions of macOS? I’ve reported it, but they each time said it was a feature, not a bug.

Damn strange feature that allows me to compromise any screen-locked mac.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#198

Earlier quoted context omitted.

You're framing this as if it's all about the bounty and Apple just hasn't gotten around to it yet. That's only a small fraction of the story and could easily be forgiven. If I wanted to make Apple look good, I'd focus on that part, but that would be rather biased to ignore the whole picture... Tokarev discovered 4 iOS 0-days, then reported them all to Apple back in May. After months of Apple's continued refusal to fi…

I don't know anything about Apple's bug bounty program except that there's a prevailing attitude that it is not the well-oiled machine that Google's bug bounty program is perceived to be, and I'm not super interested in making a case for Apple here. But because this is a recurring theme in every discussion about every bug bounty run by anyone: * There are valid reasons that bugs can take longer to fix than you'd expe…

> If you pay out for weak, stuck-in-process bugs, you create incentives that redirect programmer time to those weak bugs and away from more significant bugs; as angry as you can reasonably be about a malicious app being able to snarf your contacts, if you're rational, you're a lot more concerned about memory corruption flaws, which is what you really want people spending their time on.

I don't understand how this isn't already reflected in bug bounty pricing tiers? Like, if I access your contacts, I get $x, but if I can access all your photos, I get $xx. As a user, I couldn't care less for how my data got accessed, whether it's a logic bug or memory corruption…

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#199

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

Sell it to the highest bidder then release it on the darknet for free anyways :^)

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#200

Earlier quoted context omitted.

How much would a bug like that be worth? I can imagine getting anyone's contact list being valuable.

Why? What would be valuable about that? Specifically, what would be valuable about getting someone's GameCenter contacts? These aren't business or family contacts. These are people the person games with. It's a privacy violating bug but not a show-stopping bug. Important but not valuable.

You're misunderstanding the vulnerability. The bug is in gamed, the Game Center daemon, but it allows access to the entire CoreDuet database, which does on-device intelligence stuff. Duet essentially logs everything you do on your phone, which means that if you look at the database it'll contain logs for all your interactions, not just those with Game Center contacts.
Post reply on HN