Earlier quoted context omitted.
> would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere Having an e-mail from the company confirming the bug is serious and systemic massively raises its market value. Security is necessarily trust less. These game dynamics are unavoidable.
Having an email from the company confirming that they know about the bug probably erases its market value.
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
211–220 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#212>Apple silently fixes iOS zero-day, asks bug reporter to keep quiet Isn't that standard procedure for any company faced with a 0-day, prudent, and the right thing to do?
Why would asking the reporter to keep quiet be prudent, especially after the bug has been fixed?
You can, of course, disclose vulnerabilities whenever you like. But don't expect to get a bounty if you piss off the vendor in the process.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#213Earlier quoted context omitted.
> We pay big bounties https://zerodium.com/ >One person who will share those sales numbers is a South African hacker who goes by the name “the Grugq” and lives in Bangkok. For just over a year the Grugq has been supplementing his salary as a security researcher by acting as a broker for high-end exploits, connecting his hacker friends with buyers among his government contacts. He says he takes a 15% commission on sal…
For those who figure this is a great way to monetize their security skills and actually have the chops to do it: It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it.
By this logic, americans should stop using cars at all, cause all that oil is coming from middle east, saudi arabia.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#214Earlier quoted context omitted.
For those who figure this is a great way to monetize their security skills and actually have the chops to do it: It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it.
> It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it. By this logic, americans should stop using cars at all, cause all that oil is coming from middle east, saudi arabia.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#215Earlier quoted context omitted.
I'm sure people are selling them, although I think it would only become public by accident. At least some are going the back to the Full Disclosure days... https://twitter.com/jonathandata1/status/1448037463419674625
FYI: that person is at best very confused, and at worst willfully fraudulent.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#216Earlier quoted context omitted.
"Android" doesn't but Google Play services & bundled apps do
Google Play Services and bundled apps don't have to be enabled and sends less data to Google than the equivalent services on iOS, which must be enabled.
Have a source for them sending less data? Even if it were true, the use of that data differs.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#217Earlier quoted context omitted.
And iOS users should be grateful that they report those bugs to Apple to get paid. They could also sell it to some spying companies and may be those pay well and very fast
> and may be those pay well and very fast Pay very well? Often, assuming they actually pay, sometimes you can get stiffed there too. Very fast? Nope. Easy to work with? Nope. Communicate with you any better than Apple through the process? Not usually.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#218Earlier quoted context omitted.
My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…
They can’t be that worried - the bug that allows you to input behind the lockscreen on OS X has now been a thing for… six years, over three or four versions of macOS? I’ve reported it, but they each time said it was a feature, not a bug. Damn strange feature that allows me to compromise any screen-locked mac.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#219Earlier quoted context omitted.
I have a feeling that HN recently had an influx of users from other sites. It seems like the exodus from Reddit, for example, has resulted in a significantly larger signal to noise ratio of comments. There's a lot more impassioned nonsense that's based on article headlines rather than detailed discussion of technology and either it's just more pronounced because of the pandemic or it's actually new users that are dil…
> "Apple wants to scan your phone" and "Apple is suing mom and pop repair shops" or other hot takes that completely misunderstand their situations But, IIUC, both of those are completely true.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#220Earlier quoted context omitted.
Why? What would be valuable about that? Specifically, what would be valuable about getting someone's GameCenter contacts? These aren't business or family contacts. These are people the person games with. It's a privacy violating bug but not a show-stopping bug. Important but not valuable.
You're misunderstanding the vulnerability. The bug is in gamed, the Game Center daemon, but it allows access to the entire CoreDuet database, which does on-device intelligence stuff. Duet essentially logs everything you do on your phone, which means that if you look at the database it'll contain logs for all your interactions, not just those with Game Center contacts.
There's nothing here that suggests Zerodium, or someone similar, would pay the same amount Apple is offering and there's nothing that suggests that Apple doesn't intend to pay this or credit him. That's all completely conjecture.