Live data from Hacker News

I hacked macOS

asahilina.net

101–110 of 140 posts

Re: I hacked macOS

#102
post #52
post #48

Earlier quoted context omitted.

" Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting. " https://news.ycombinator.com/newsguidelines.html

Respectfully: do you genuinely believe that guideline had this kind of presentation in mind, or the very common tedium of poorly built websites that occurs frequently on amateur tech posts. Even the examples provided by the rule you quoted lend to the latter. The format is indeed relevant.

The guideline is to prevent threads turning discussions of interesting things into discussions of boring things, like most of the other guidelines. Plus you can ask the person who came up with it, I'm sure they'll tell you something similar.

Re: I hacked macOS

#103
post #76
post #68

Earlier quoted context omitted.

You’re pretty much correct. GPUs are a very interesting attack vector. Especially as more computation is being pushed to GPUs, and they’re not always well isolated.

I'm genuinely concerned about the WebGPU attack vector. The possibilities are exciting, but we (everyone) has virtually no experience with securing them (compared to decades of securing x86 - which we still can't pull off). My biggest concern is fingerprinting.

Is this substantially different than say, containers with GPU access, right?

Lots of computation is moving to GPUs.

Re: I hacked macOS

#105
post #74

Earlier quoted context omitted.

I mean, this is the company where the only security certification advertised on their website for macOS [1][2] only achieved the lowest possible level of security, EAL1. A level only fit for products where [3]: "some confidence in correct operation is required, but the threats to security are not viewed as serious" which is one level lower than "demonstrating resistance to penetration attackers with a basic attack po…

EAL is not a measure of security but a measure of the depth of analysis. Looking at the complexity of monolithic-kernel-based operating systems, I don't much can be derived from certifications with an EAL < 5.

Evaluated assurance levels (EAL) are a bundle of security assurance requirements (SAR) that reasonably trace to varying levels of assurance that the target of evaluation (TOE) enforces the Security Functional Requirements (SFR) of the product. One of the core SARs being AVA (vulnerability assessment) which evaluates resistance to penetration attackers and the presence of vulnerabilities. It is only at EAL5 that you are required to demonstrate AVA_VAN.4 which is resistance to penetration attackers with a moderate attack potential.

What we derive from companies only able to achieve EAL We further know from decades of experience that any system that attempts EAL5 certification and then fails has structural deficiencies that make it practically impossible for any configuration to ever be certified without a total redesign. As far as I know, nobody has ever achieved that despite decades of attempts and billions of dollars spent attempting to retrofit inherently insecure designs such as Windows, Linux, or macOS.

So, what we know is that macOS, iOS, Linux, Windows, BSDs, etc. are structurally insecure against moderate attacks such as those employed by commercial hackers and organized crime, let alone state-level actors, and that it is hopeless for them to ever be improved to reach such a level. Anything less than EAL5 is inadequate for the modern threat landscape of established commercial hackers and state actors as experienced by consumers, businesses, and governments. Therefore, the systems currently deployed are universally unfit for their usage in these connected systems and we have the certifications and continuous examples to prove it.

Re: I hacked macOS

#107

Earlier quoted context omitted.

How would you value this exploit, or any exploit?

I understand this is arbitrary code execution with root access. I'm imagining the potential of infecting a high status individual and I think a bad actor would pay millions for such an exploit.

Apple pays up to $2M for such zero click exploits.

Re: I hacked macOS

#108
post #90

Earlier quoted context omitted.

Sounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.

What? That's an insane amount of money

Less than the salary of their software engineers.

Re: I hacked macOS

#109

Earlier quoted context omitted.

On the other hand, that's a years salary for many people. Seems like a quite fair payment, and a payout to envy. Lower, easier to get payouts are arguably better than rare jackpot payouts you have to fight over...

> On the other hand, that's a years salary for many people. It's several years salary for many people.

But not for people with this level of applied skills.

How many people do you think could pull this off? I certainly couldn't. Could you?

Re: I hacked macOS

#110
Just a note this isn't new: fixed in macOS last year (october 2022), and the japanese stream with the same slides is half a year old. (The english content is new, so I guess this is still worth the front page as long as people are interested)
Post reply on HN