Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

201–210 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#201
post #27

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.

Shady advertising SDK? (Also, don't people use code execution to exfiltrate contacts and messages? This is basically what this bug does, albeit with "several clicks" involved.)

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#202
post #93

Earlier quoted context omitted.

Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them. Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exf…

>Who? Cellebrite and all the surveillance-as-a-service shops might be interested in information disclosure bugs. You maybe will not get the $100K Apple promised, but maybe you can sell it four times for $30K or something like that if the bug is still "good enough" for certain uses. RCEs in Windows or iOS go for a lot more than a measly $100K if you can manage to get in contact with the right people. Think 10-20 times…

Cellebrite is more in the business of data extraction.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#203

Earlier quoted context omitted.

One of these things doesn't negate or excuse the other; both can happen at the same time. You're engaging in "whataboutism".

If you sell a knife, and it's used for a stabbing, are you culpable? Thousands of people buy knives every day, and most of them don't stab anyone. So unless there was good reason to suspect something, we would say no. Most zerodays are probably not bought by china to spy on dissidents, they are more like knives. On the contrary, when we sell bombs to Saudis we can be 95% sure they will be used in Yemen.

What exactly do you do with a zero day that isn't "use it against someone"?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#204
post #18

Seems that no credit, no bount, nothing, has become the way that Apple deals with the iBugs Hunters. And all it takes is one of those unsong heros giving up on reporting to Apple and, instead, reporting to some 0-day company, and some ransonware go brrrr

I'm sure people are selling them, although I think it would only become public by accident. At least some are going the back to the Full Disclosure days... https://twitter.com/jonathandata1/status/1448037463419674625

FYI: that person is at best very confused, and at worst willfully fraudulent.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#205
post #75

>Apple silently fixes iOS zero-day, asks bug reporter to keep quiet Isn't that standard procedure for any company faced with a 0-day, prudent, and the right thing to do?

Why would asking the reporter to keep quiet be prudent, especially after the bug has been fixed?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#206

Earlier quoted context omitted.

Are these comments real? They are surprisingly close minded for a hacker news site. If you can't see the value apple offers, that's fine, but to be blind to what they offer others seems odd. I've yet to be scammed by apple's app store. Ie, I can cancel my subscriptions easily, bad apps you can even get a refund on if prompt etc. I have been repeatedly screwed by websites run by developers outside of apple. These webs…

I have a feeling that HN recently had an influx of users from other sites. It seems like the exodus from Reddit, for example, has resulted in a significantly larger signal to noise ratio of comments. There's a lot more impassioned nonsense that's based on article headlines rather than detailed discussion of technology and either it's just more pronounced because of the pandemic or it's actually new users that are dil…

> "Apple wants to scan your phone" and "Apple is suing mom and pop repair shops" or other hot takes that completely misunderstand their situations

But, IIUC, both of those are completely true.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#207
post #163

Earlier quoted context omitted.

How does one contact the NSA TAO and offer to sell a zero-day?

> We pay big bounties https://zerodium.com/ >One person who will share those sales numbers is a South African hacker who goes by the name “the Grugq” and lives in Bangkok. For just over a year the Grugq has been supplementing his salary as a security researcher by acting as a broker for high-end exploits, connecting his hacker friends with buyers among his government contacts. He says he takes a 15% commission on sal…

For those who figure this is a great way to monetize their security skills and actually have the chops to do it:

It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#208

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

> The company hasn't denied the bounty, they're just incompetent / slow on this process.

With 0-day security vulnerabilities, slowness equals incompetence. Companies with unbounded resources like Apple have absolutely no excuse for not being able to move as quickly as a small startup on issues like this, unless their message to shareholders is "yes invest in us so you can see our performance literally decrease with every dollar invested".

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#209

Earlier quoted context omitted.

"Only option"? What about Purism phones?

While they do seem to be shipping every so slowly they're still stuck on orders from the initial crowd funding campaign from 2018.

Ah. Good point. Still a name worth mentioning though; we need to each of the few companies in this space.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#210
post #207

Earlier quoted context omitted.

> We pay big bounties https://zerodium.com/ >One person who will share those sales numbers is a South African hacker who goes by the name “the Grugq” and lives in Bangkok. For just over a year the Grugq has been supplementing his salary as a security researcher by acting as a broker for high-end exploits, connecting his hacker friends with buyers among his government contacts. He says he takes a 15% commission on sal…

For those who figure this is a great way to monetize their security skills and actually have the chops to do it: It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it.

Getting rid of people who want democracy
Post reply on HN