Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

221–230 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#221

Earlier quoted context omitted.

They can’t be that worried - the bug that allows you to input behind the lockscreen on OS X has now been a thing for… six years, over three or four versions of macOS? I’ve reported it, but they each time said it was a feature, not a bug. Damn strange feature that allows me to compromise any screen-locked mac.

How do you do that?

Surprisingly straightforwardly - when you open the lid, focus is initially still on the desktop, not on the Lock Screen. You may have noticed if you’re too quick with your password the first few characters don’t appear. They don’t go nowhere - they go to the desktop.

If you get a certain key combination in before focus switches, it stays on the desktop, and you can continue to input - fire up a terminal, do whatever you fancy. It’s all blind, but still perfectly dangerous.

Certain full screen apps, if they have focus when you lock, retain focus indefinitely. Paradox interactive games, for instance - stellaris exhibits the behaviour nicely. This even includes mouse focus, and if you Apple-tab, then focus goes to whatever you Apple-tab to. You can only restore focus to the Lock Screen by clicking in the password field.

Both times I reported this I got a pedantic “locking the screen does not terminate applications, which may continue to run in the background” response.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#222

Earlier quoted context omitted.

I don't know anything about Apple's bug bounty program except that there's a prevailing attitude that it is not the well-oiled machine that Google's bug bounty program is perceived to be, and I'm not super interested in making a case for Apple here. But because this is a recurring theme in every discussion about every bug bounty run by anyone: * There are valid reasons that bugs can take longer to fix than you'd expe…

> If you pay out for weak, stuck-in-process bugs, you create incentives that redirect programmer time to those weak bugs and away from more significant bugs; as angry as you can reasonably be about a malicious app being able to snarf your contacts, if you're rational, you're a lot more concerned about memory corruption flaws, which is what you really want people spending their time on. I don't understand how this isn…

The point is that memory corruption vulnerabilities are complete device takeovers, not that they have extra aesthetic value.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#223

Earlier quoted context omitted.

Your comments are the only ones here which aren’t divorced from reality. It’s weird. Who are these supposed guys paying six figures for this sort of thing? It’s just not a valuable thing.

I'm with you. I think these cheap, Apple-bashing blogs want to make this into a bigger deal but there are a few things that don't add up to make this the huge issue they think it is: 1. The bug lets you download contacts. Nothing else. As you've said, no one's going to pay six figures for a bug that lets you get someone's contacts from GameCenter. If this was even slightly more abstract and didn't specifically deal w…

> 1. The bug lets you download contacts. Nothing else. As you've said, no one's going to pay six figures for a bug that lets you get someone's contacts from GameCenter. If this was even slightly more abstract and didn't specifically deal with just GameCenter, I could see it being valuable for companies that do phone-to-phone transfers, for example, because you could download someone's contacts from a locked device. This isn't that, though.

I, the evil overlord, would very much like to know who is ratting out my secret initiatives to those nosy journalists. Maybe some of them don't keep a good information hygiene and will download my simple but quite addictive game? At least I get to know some names and addresses.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#224

Earlier quoted context omitted.

One of these things doesn't negate or excuse the other; both can happen at the same time. You're engaging in "whataboutism".

If you sell a knife, and it's used for a stabbing, are you culpable? Thousands of people buy knives every day, and most of them don't stab anyone. So unless there was good reason to suspect something, we would say no. Most zerodays are probably not bought by china to spy on dissidents, they are more like knives. On the contrary, when we sell bombs to Saudis we can be 95% sure they will be used in Yemen.

Zero-days, unlike knives, are not dual-use instruments. The only people buying those zero-days are incorporating them into surveillance and monitoring systems. Literally, how else could an exploit be monetized? Stealing crypto-wallets?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#225

Earlier quoted context omitted.

I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere. No maybe the shadiness inherent in the field means no one trusts that agreement anyway, but I suspect there's generally some amount of trust for researchers submitting vulnerabilities, particularly if they have some kind of history of good faith. Also, I'm not sure that saying "we have discovered a deeper p…

> I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere. That is a very mistaken assumption. Even NDAs backed by threats from nation state intelligence agencies aren’t sufficient to keep exploits from being resold multiple times.

Also, the ones who sell two or more times, can just claim that the other buyer actually discovered the exploit themselves?

Or maybe that someone in the first buyer's organization resold it?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#226

Earlier quoted context omitted.

Are these comments real? They are surprisingly close minded for a hacker news site. If you can't see the value apple offers, that's fine, but to be blind to what they offer others seems odd. I've yet to be scammed by apple's app store. Ie, I can cancel my subscriptions easily, bad apps you can even get a refund on if prompt etc. I have been repeatedly screwed by websites run by developers outside of apple. These webs…

I have a feeling that HN recently had an influx of users from other sites. It seems like the exodus from Reddit, for example, has resulted in a significantly larger signal to noise ratio of comments. There's a lot more impassioned nonsense that's based on article headlines rather than detailed discussion of technology and either it's just more pronounced because of the pandemic or it's actually new users that are dil…

This might be it, it's pretty noticeable.

The scan your phone, repairs shops should be able to fake battery replacements or change faceID sensors without controls type stuff is also in this, or no reason for apple to make certain decisions (despite obvious reasons) etc.

It's gotten to just BLIND reaction - ie, apple is done when reality is apple remains far more trusted than almost any other company (or govt) brand wise.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#227

Earlier quoted context omitted.

How do you do that?

Surprisingly straightforwardly - when you open the lid, focus is initially still on the desktop, not on the Lock Screen. You may have noticed if you’re too quick with your password the first few characters don’t appear. They don’t go nowhere - they go to the desktop. If you get a certain key combination in before focus switches, it stays on the desktop, and you can continue to input - fire up a terminal, do whatever…

Open-terminal shortcut, then "killall xlock" or whatever it's called in macOS?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#228
post #216

Earlier quoted context omitted.

Google Play Services and bundled apps don't have to be enabled and sends less data to Google than the equivalent services on iOS, which must be enabled.

Google Play Services does need to be enabled to use many (most?) mainstream apps. Have a source for them sending less data? Even if it were true, the use of that data differs.

To install any apps on an iPhone at all, you must give Apple your billing information. Even if you install apps from the Google Play store, you do not need to give up that much privacy.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#229
post #193

Earlier quoted context omitted.

Yes, they do have some way of using your iCloud account credentials to get to the backup key. Given the level of customer support needed for forgotten backup keys, they have probably chosen this as the lesser of two evils. If you don't like that "feature," don't do iCloud backups. I do direct backups as described in the support link. Apple doesn't have those keys.

It doesn't matter if you don't do iCloud backups. All of your iMessages will be backed up to Apple in ways that Apple/FBI can read because iCloud Backup (not e2e) is on on every device held by the people you are iMessaging with.

Depending on how cheap your friends are, they might not have effective backups because they wont spend money for the iCloud space to have enough space for their backups in the first place.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#230
post #215

Earlier quoted context omitted.

FYI: that person is at best very confused, and at worst willfully fraudulent.

Why is that?

They demonstrate a clear lack of knowledge of actual security–like unzipping a firmware update and calling it "decompiling" or connecting a device to a computer and using the file transfer functionality as proof of "RCE".
Post reply on HN