Earlier quoted context omitted.
> If you pay out for weak, stuck-in-process bugs, you create incentives that redirect programmer time to those weak bugs and away from more significant bugs; as angry as you can reasonably be about a malicious app being able to snarf your contacts, if you're rational, you're a lot more concerned about memory corruption flaws, which is what you really want people spending their time on. I don't understand how this isn…
The point is that memory corruption vulnerabilities are complete device takeovers, not that they have extra aesthetic value.
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
231–240 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#232Earlier quoted context omitted.
You're misunderstanding the vulnerability. The bug is in gamed, the Game Center daemon, but it allows access to the entire CoreDuet database, which does on-device intelligence stuff. Duet essentially logs everything you do on your phone, which means that if you look at the database it'll contain logs for all your interactions, not just those with Game Center contacts.
You are correct. I did misunderstand that portion of it but that doesn't change the fact that Apple is willing to pay $100k for a bounty like that but no one else does and Apple's actions don't suggest at all that they won't pay out the bounty. If you've ever been part of a program like this, on the developer side, it's possible that they discovered a larger bug that this was a part of or that someone else had alread…
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#233Earlier quoted context omitted.
The point is that memory corruption vulnerabilities are complete device takeovers, not that they have extra aesthetic value.
Well, that circles back around to my point: if Apple wants people to submit more complete device takeovers, they should pay more for them (and they do, or at least they claim they do).
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#234Earlier quoted context omitted.
I'm with you. I think these cheap, Apple-bashing blogs want to make this into a bigger deal but there are a few things that don't add up to make this the huge issue they think it is: 1. The bug lets you download contacts. Nothing else. As you've said, no one's going to pay six figures for a bug that lets you get someone's contacts from GameCenter. If this was even slightly more abstract and didn't specifically deal w…
> 1. The bug lets you download contacts. Nothing else. As you've said, no one's going to pay six figures for a bug that lets you get someone's contacts from GameCenter. If this was even slightly more abstract and didn't specifically deal with just GameCenter, I could see it being valuable for companies that do phone-to-phone transfers, for example, because you could download someone's contacts from a locked device. T…
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#235Earlier quoted context omitted.
> 1. The bug lets you download contacts. Nothing else. As you've said, no one's going to pay six figures for a bug that lets you get someone's contacts from GameCenter. If this was even slightly more abstract and didn't specifically deal with just GameCenter, I could see it being valuable for companies that do phone-to-phone transfers, for example, because you could download someone's contacts from a locked device. T…
It's not just that it's contact data; I agree, exposing contact databases is a big deal, and that this (as depicted) is a significant bug. It's that to accomplish that with this bug, you have to install a malicious app from the app store. That is a very high hurdle towards operationalizing the bug, especially since, as I said elsewhere, Apple does API-level surveillance of apps in the app store.
Or make useless copycats, as Kosta Eleftheriou proved already is a way of choice in the iOS App Store.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#236Earlier quoted context omitted.
Well, that circles back around to my point: if Apple wants people to submit more complete device takeovers, they should pay more for them (and they do, or at least they claim they do).
This bug was not a complete takeover, or anything even close to one.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#237Earlier quoted context omitted.
This bug was not a complete takeover, or anything even close to one.
Well, yes, that's why Apple won't pay a million dollars for it. But there are tiers lower than that ("Unauthorized access to sensitive data from a user-installed app") which do cover the kind of bug described here.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#238Earlier quoted context omitted.
> I don't see how it's possible without the support of the large tech players - Facebook, Instagram, Snapchat, WhatsApp, Twitter, and Spotify at minimum, to say nothing of the long tail. This wouldn't be much of a problem if it wasn't for Google's SafetyNet that prevents Android apps from running on hardware and software platforms that Google doesn't approve of. You wouldn't need support from large companies if you w…
What's SafetyNet have to do with anything? It's opt it device attestation the app creator has to implement It's not Android/Google forcing SafetyNet on you, it's app developers insisting you need some special end user setup
> What's SafetyNet have to do with anything?
I thought I made that pretty clear in my post. I was addressing a post about competitors to Android facing challenges because of lack of app support from major companies.
SafetyNet helps Google maintain their mobile OS duopoly with Apple by preventing other mobile operating systems from running Android apps, despite there not being any technical reason why the apps can't run on other operating systems.
Steam was able to bring Windows games over to Linux via Proton because of projects like WINE. SafetyNet precludes running Android apps on devices and operating systems Google doesn't approve of.
Microsoft was able to bring Linux apps over to Windows via WSL 1 & 2. SafetyNet precludes running Android apps on Windows unless Google gives Windows a pass in their DRM.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#239Earlier quoted context omitted.
It's not just that it's contact data; I agree, exposing contact databases is a big deal, and that this (as depicted) is a significant bug. It's that to accomplish that with this bug, you have to install a malicious app from the app store. That is a very high hurdle towards operationalizing the bug, especially since, as I said elsewhere, Apple does API-level surveillance of apps in the app store.
But isn't it the reason malicious actors buy legit apps made by small shops to insert what at best is adware/spyware into something that is useful and made a name for itself already? Or make useless copycats, as Kosta Eleftheriou proved already is a way of choice in the iOS App Store.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#240Earlier quoted context omitted.
Well, yes, that's why Apple won't pay a million dollars for it. But there are tiers lower than that ("Unauthorized access to sensitive data from a user-installed app") which do cover the kind of bug described here.
You've lost me. What does this have to do with the point I made about which bugs we want security developers at Apple spending their time on? You seem to be making my point for me.
If Apple wants to nudge people towards submitting more serious bugs, they can pay more so people are incentivized to work towards those rather than mucking around in gamed. But, they don't really get to say "we didn't really have time to get around to this Contacts bug, sorry": people expect them to have it fixed. That's the whole reason Apple offers a bounty at all: so that researchers tell them about it early so they can fix it.