Earlier quoted context omitted.
Putting the exploit in the App Store isn't particularly polite either and doesn't seem to serve any purpose other than generating some publicity for the researcher. It'd be different if he believed Apple wasn't going to fix it or that the exploit was being used or was about to be used in malicious apps - but he doesn't claim that was his motivation.
Except that how else is he supposed to prove that it works other than actually demonstrating it with a real app on the real App Store?
Security researcher Charlie Miller booted from Apple Developer Program
41–50 of 116 posts
Re: Security researcher Charlie Miller booted from Apple Developer Program
#42Earlier quoted context omitted.
when you submit a security related bug report to apple - granted my experience dates from 99-2005 - you get: A/ ignored (mail auto reply "we might fix it, don't tell anyone or we'll go after you" B/ bug don't get fixed for 2 or 3 years C/ bug get fixed, you get no credits
I don't know why this is being downvoted. Apple is notoriously horrible at fixing vulnerabilities reported by the general public, unless they're downright critical.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#43Earlier quoted context omitted.
I think the risk is primarily bad press. It's not really a "security hole" for apps to add additional runnable code from an external website, when apps can currently contain pretty much anything at all (as long as they don't link to forbidden symbols). Remember that Apple does not see source code, and relies completely on app developers to behave, beyond a few perfunctory checks. And Apple has made it abundantly clea…
The downside is poorer security, which could blow up in their face spectacularly at some point in the future.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#44Re: Security researcher Charlie Miller booted from Apple Developer Program
#45I come into your party as a guest and what I do is steal all your stuff. If you would be a white hat, you would knock at the door and kindly hint me to the loophole instead of just doing it ...
Re: Security researcher Charlie Miller booted from Apple Developer Program
#46Earlier quoted context omitted.
I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.
This hardly qualifies as an exploit. While it allows the app to do something it's not supposed to do, the ability to download and execute additional executable code doesn't actually violate security. The new code is still restricted to the app's sandbox and can't do anything that the original app couldn't potentially have done directly.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#47Earlier quoted context omitted.
Hold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.
He did not put users at risk. This vulnerability allows apps to download and execute new code, but that new code is still subject to the app's sandbox. This vulnerability is interesting from a research standpoint, but has zero actual consequences to the security of iOS.
http://www.forbes.com/sites/andygreenberg/2011/11/07/iphone-...
Re: Security researcher Charlie Miller booted from Apple Developer Program
#48Earlier quoted context omitted.
Developer agreements are not a security mechanism.
And security research does not trump the developer agreement. The guy submitted a real live exploit to the Joe-User facing App Store. What on earth did he expect would happen?
It's the equivalent of making a word document pop up calc.exe. This proves that you've broken the security, but doesn't cause harm.
You have to actually do it to be taken seriously, especially with unreceptive vendors like Apple.
There is really no reason to behave in a hostile way towards a researcher that does this. He's telling you about the problem.
In the security industry, there are many people who seek and find vulnerabilities. Some of them report them, and some of them keep them private and exploit them secretly to attack people's property, or privately sell to others who do the same. Selling these to the underground is big business now.
Let's subtract the people who report things from the above equation (because we ban and vilify them). Now what does your ecosystem look like?
Dumb move, Apple. Dumb move.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#49Earlier quoted context omitted.
Hold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.
He did not put users at risk. This vulnerability allows apps to download and execute new code, but that new code is still subject to the app's sandbox. This vulnerability is interesting from a research standpoint, but has zero actual consequences to the security of iOS.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#50Earlier quoted context omitted.
The downside is poorer security, which could blow up in their face spectacularly at some point in the future.
I really doubt it. To be blunt, Apple is an existence proof that security on consumer products doesn't provide business value in proportion to its cost. Keeping users safe is seldom worth investing in.