Earlier quoted context omitted.
You've lost me. What does this have to do with the point I made about which bugs we want security developers at Apple spending their time on? You seem to be making my point for me.
The whole point of the bug bounty program is that anything that qualifies for it is something that Apple considers to be important enough to pay out money for, because they (ostensibly) want people to report these to them. I understand if they are overloaded with "this function leaks the country of the device" bug reports but the ones that they actually include in the bug bounty program are those that have the potent…
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
241–250 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#242Earlier quoted context omitted.
It's not just that it's contact data; I agree, exposing contact databases is a big deal, and that this (as depicted) is a significant bug. It's that to accomplish that with this bug, you have to install a malicious app from the app store. That is a very high hurdle towards operationalizing the bug, especially since, as I said elsewhere, Apple does API-level surveillance of apps in the app store.
But isn't it the reason malicious actors buy legit apps made by small shops to insert what at best is adware/spyware into something that is useful and made a name for itself already? Or make useless copycats, as Kosta Eleftheriou proved already is a way of choice in the iOS App Store.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#243Earlier quoted context omitted.
I could accomplish the same thing by robbing a bank - doesn’t make it the right thing to do.
Unless it's a mafia's bank.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#244Earlier quoted context omitted.
For those who figure this is a great way to monetize their security skills and actually have the chops to do it: It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it.
> It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it. By this logic, americans should stop using cars at all, cause all that oil is coming from middle east, saudi arabia.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#245Earlier quoted context omitted.
You are correct. I did misunderstand that portion of it but that doesn't change the fact that Apple is willing to pay $100k for a bounty like that but no one else does and Apple's actions don't suggest at all that they won't pay out the bounty. If you've ever been part of a program like this, on the developer side, it's possible that they discovered a larger bug that this was a part of or that someone else had alread…
I have no idea if Zerodium would pay out that much for this bug (probably not) or anyone else (maybe?) but Apple in general has a poor track record of paying out bug bounties. They do sometimes, but it seems like it is far rarer than their website says they should.
What is this based on? My understanding is that Apple pays out 99% of the reported bug bounties and that's only because they include multiple submissions in the totals but not in the payouts (they only payout the first discovery or root discovery).
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#246Earlier quoted context omitted.
I have no idea if Zerodium would pay out that much for this bug (probably not) or anyone else (maybe?) but Apple in general has a poor track record of paying out bug bounties. They do sometimes, but it seems like it is far rarer than their website says they should.
>Apple in general has a poor track record of paying out bug bounties What is this based on? My understanding is that Apple pays out 99% of the reported bug bounties and that's only because they include multiple submissions in the totals but not in the payouts (they only payout the first discovery or root discovery).
thunderspy.io/
Those are my favorite recent examples, but specifically Apple has huge issues with turnaround time. They also don't communicate with or assist the researchers who found these exploits either, which makes things particularly frustrating for people who ultimately both want to secure Apple's systems. Their overt hostility, history of poor communication, and frankly pathetic bug bounties are all contributors to how people perceive Apple's relationship with security experts.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#247Earlier quoted context omitted.
PinePhone is our only hope! Still a ways off from being consumer ready but it's heading in the right direction.
"Only option"? What about Purism phones?
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#248Earlier quoted context omitted.
>Apple in general has a poor track record of paying out bug bounties What is this based on? My understanding is that Apple pays out 99% of the reported bug bounties and that's only because they include multiple submissions in the totals but not in the payouts (they only payout the first discovery or root discovery).
https://habr.com/en/post/579714/ thunderspy.io/ Those are my favorite recent examples, but specifically Apple has huge issues with turnaround time. They also don't communicate with or assist the researchers who found these exploits either, which makes things particularly frustrating for people who ultimately both want to secure Apple's systems. Their overt hostility, history of poor communication, and frankly patheti…
This makes it seem like this is a recurring problem yet there are only a handful of complaints.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#249Earlier quoted context omitted.
> If you pay out for weak, stuck-in-process bugs, you create incentives that redirect programmer time to those weak bugs and away from more significant bugs; as angry as you can reasonably be about a malicious app being able to snarf your contacts, if you're rational, you're a lot more concerned about memory corruption flaws, which is what you really want people spending their time on. I don't understand how this isn…
The point is that memory corruption vulnerabilities are complete device takeovers, not that they have extra aesthetic value.
Is your point that all bugs soak up time to fix? If so pay the bounty and add it to the backlog. Or is it too much time to verify? That seems to be something you can kick back to the reporter.
Apologetics for a bug bounty program dragging their feet on a payout because "it's not a mem corruption bug" alone is unconvincing.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#250Earlier quoted context omitted.
> and may be those pay well and very fast Pay very well? Often, assuming they actually pay, sometimes you can get stiffed there too. Very fast? Nope. Easy to work with? Nope. Communicate with you any better than Apple through the process? Not usually.
Have you dealt with terrorist orgs in the past, or is this all conjecture?
The above type of organization is what I was referring to. So if you consider the grey market buyers[⋁] of exploits “terrorist orgs”, then yes. If you use the normal definition of “terrorist orgs”, then hell no.
[⋀] three letter government agencies, defense contractors, and those who sell to them