Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

231–240 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#231

Earlier quoted context omitted.

> If you pay out for weak, stuck-in-process bugs, you create incentives that redirect programmer time to those weak bugs and away from more significant bugs; as angry as you can reasonably be about a malicious app being able to snarf your contacts, if you're rational, you're a lot more concerned about memory corruption flaws, which is what you really want people spending their time on. I don't understand how this isn…

The point is that memory corruption vulnerabilities are complete device takeovers, not that they have extra aesthetic value.

Well, that circles back around to my point: if Apple wants people to submit more complete device takeovers, they should pay more for them (and they do, or at least they claim they do).

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#232

Earlier quoted context omitted.

You're misunderstanding the vulnerability. The bug is in gamed, the Game Center daemon, but it allows access to the entire CoreDuet database, which does on-device intelligence stuff. Duet essentially logs everything you do on your phone, which means that if you look at the database it'll contain logs for all your interactions, not just those with Game Center contacts.

You are correct. I did misunderstand that portion of it but that doesn't change the fact that Apple is willing to pay $100k for a bounty like that but no one else does and Apple's actions don't suggest at all that they won't pay out the bounty. If you've ever been part of a program like this, on the developer side, it's possible that they discovered a larger bug that this was a part of or that someone else had alread…

I have no idea if Zerodium would pay out that much for this bug (probably not) or anyone else (maybe?) but Apple in general has a poor track record of paying out bug bounties. They do sometimes, but it seems like it is far rarer than their website says they should.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#233

Earlier quoted context omitted.

The point is that memory corruption vulnerabilities are complete device takeovers, not that they have extra aesthetic value.

Well, that circles back around to my point: if Apple wants people to submit more complete device takeovers, they should pay more for them (and they do, or at least they claim they do).

This bug was not a complete takeover, or anything even close to one.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#234

Earlier quoted context omitted.

I'm with you. I think these cheap, Apple-bashing blogs want to make this into a bigger deal but there are a few things that don't add up to make this the huge issue they think it is: 1. The bug lets you download contacts. Nothing else. As you've said, no one's going to pay six figures for a bug that lets you get someone's contacts from GameCenter. If this was even slightly more abstract and didn't specifically deal w…

> 1. The bug lets you download contacts. Nothing else. As you've said, no one's going to pay six figures for a bug that lets you get someone's contacts from GameCenter. If this was even slightly more abstract and didn't specifically deal with just GameCenter, I could see it being valuable for companies that do phone-to-phone transfers, for example, because you could download someone's contacts from a locked device. T…

It's not just that it's contact data; I agree, exposing contact databases is a big deal, and that this (as depicted) is a significant bug. It's that to accomplish that with this bug, you have to install a malicious app from the app store. That is a very high hurdle towards operationalizing the bug, especially since, as I said elsewhere, Apple does API-level surveillance of apps in the app store.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#235

Earlier quoted context omitted.

> 1. The bug lets you download contacts. Nothing else. As you've said, no one's going to pay six figures for a bug that lets you get someone's contacts from GameCenter. If this was even slightly more abstract and didn't specifically deal with just GameCenter, I could see it being valuable for companies that do phone-to-phone transfers, for example, because you could download someone's contacts from a locked device. T…

It's not just that it's contact data; I agree, exposing contact databases is a big deal, and that this (as depicted) is a significant bug. It's that to accomplish that with this bug, you have to install a malicious app from the app store. That is a very high hurdle towards operationalizing the bug, especially since, as I said elsewhere, Apple does API-level surveillance of apps in the app store.

But isn't it the reason malicious actors buy legit apps made by small shops to insert what at best is adware/spyware into something that is useful and made a name for itself already?

Or make useless copycats, as Kosta Eleftheriou proved already is a way of choice in the iOS App Store.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#236

Earlier quoted context omitted.

Well, that circles back around to my point: if Apple wants people to submit more complete device takeovers, they should pay more for them (and they do, or at least they claim they do).

This bug was not a complete takeover, or anything even close to one.

Well, yes, that's why Apple won't pay a million dollars for it. But there are tiers lower than that ("Unauthorized access to sensitive data from a user-installed app") which do cover the kind of bug described here.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#237

Earlier quoted context omitted.

This bug was not a complete takeover, or anything even close to one.

Well, yes, that's why Apple won't pay a million dollars for it. But there are tiers lower than that ("Unauthorized access to sensitive data from a user-installed app") which do cover the kind of bug described here.

You've lost me. What does this have to do with the point I made about which bugs we want security developers at Apple spending their time on? You seem to be making my point for me.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#238
post #78

Earlier quoted context omitted.

> I don't see how it's possible without the support of the large tech players - Facebook, Instagram, Snapchat, WhatsApp, Twitter, and Spotify at minimum, to say nothing of the long tail. This wouldn't be much of a problem if it wasn't for Google's SafetyNet that prevents Android apps from running on hardware and software platforms that Google doesn't approve of. You wouldn't need support from large companies if you w…

What's SafetyNet have to do with anything? It's opt it device attestation the app creator has to implement It's not Android/Google forcing SafetyNet on you, it's app developers insisting you need some special end user setup

I have the same problems with SafetyNet as I do with Widevine.

> What's SafetyNet have to do with anything?

I thought I made that pretty clear in my post. I was addressing a post about competitors to Android facing challenges because of lack of app support from major companies.

SafetyNet helps Google maintain their mobile OS duopoly with Apple by preventing other mobile operating systems from running Android apps, despite there not being any technical reason why the apps can't run on other operating systems.

Steam was able to bring Windows games over to Linux via Proton because of projects like WINE. SafetyNet precludes running Android apps on devices and operating systems Google doesn't approve of.

Microsoft was able to bring Linux apps over to Windows via WSL 1 & 2. SafetyNet precludes running Android apps on Windows unless Google gives Windows a pass in their DRM.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#239

Earlier quoted context omitted.

It's not just that it's contact data; I agree, exposing contact databases is a big deal, and that this (as depicted) is a significant bug. It's that to accomplish that with this bug, you have to install a malicious app from the app store. That is a very high hurdle towards operationalizing the bug, especially since, as I said elsewhere, Apple does API-level surveillance of apps in the app store.

But isn't it the reason malicious actors buy legit apps made by small shops to insert what at best is adware/spyware into something that is useful and made a name for itself already? Or make useless copycats, as Kosta Eleftheriou proved already is a way of choice in the iOS App Store.

The reason attackers buy or compromise existing apps is exactly because they want to sidestep the hurdle of tricking people into downloading their malicious app. Using an existing app gives you access to the existing users.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#240

Earlier quoted context omitted.

Well, yes, that's why Apple won't pay a million dollars for it. But there are tiers lower than that ("Unauthorized access to sensitive data from a user-installed app") which do cover the kind of bug described here.

You've lost me. What does this have to do with the point I made about which bugs we want security developers at Apple spending their time on? You seem to be making my point for me.

The whole point of the bug bounty program is that anything that qualifies for it is something that Apple considers to be important enough to pay out money for, because they (ostensibly) want people to report these to them. I understand if they are overloaded with "this function leaks the country of the device" bug reports but the ones that they actually include in the bug bounty program are those that have the potential to significantly damage their stated goals around security, so it's kind of the point that they review all of them.

If Apple wants to nudge people towards submitting more serious bugs, they can pay more so people are incentivized to work towards those rather than mucking around in gamed. But, they don't really get to say "we didn't really have time to get around to this Contacts bug, sorry": people expect them to have it fixed. That's the whole reason Apple offers a bounty at all: so that researchers tell them about it early so they can fix it.

Post reply on HN