Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…
There have been many documented cases where tech giants have outright refused to pay out, employing practices like: changing the rules of engagement post-factum, silently banning security researchers from active bounties, escalating good-faith disclosures to law enforcement, extreme pettiness from managers, etc. > The sums involved are not meaningful to the company Which makes it the more bewildering to see how misha…
Zero-Click Calendar invite vulnerability chain in macOS
101–110 of 166 posts
Re: Zero-Click Calendar invite vulnerability chain in macOS
#102Earlier quoted context omitted.
I think there's a pretty big gap between "people at my company are allowed to add things to my calendar" and "random stranger anywhere in the world can add things to my calendar".
Neither of the above examples would come from people in my company.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#103Re: Zero-Click Calendar invite vulnerability chain in macOS
#104Earlier quoted context omitted.
If the recruiter doesn't ask me first (or I don't agree to a meeting), this is called "spam", and I would be happy for the system to just not allow it.
I have never encountered a situation where recruiter starts immediately with an invite without prior conversation (such invite also blocks the time slot of the sender - it would be stupidly ineffective to do that). It is hypothetical and improbable scenario that is not even worth mentioning here.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#105Earlier quoted context omitted.
The cost of an uncharitable blog post is massively more than the price of a bounty, like, it's not even close. The cost of an uncharitable blog post is potentially unbounded (as in: not many people in a large tech company would know how to put a ceiling on the cost), and the cost of a bounty, even a high one, is more or less chump change. Another in my long-running dramatic series "businesses pay spectacularly more f…
Companies are not set up to accurately and effectively gauge the impact of intangible costs to themselves.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#106Earlier quoted context omitted.
Honestly, Apple is a 3.5 trillion dollar company. If the bug bounty program is understaffed then it's an intentional choice and they should fix it. And I say that as someone who's generally sympathetic to Apple.
Sure. My comment isn't really about Apple specifically so much as bounty program misconceptions generally.
Every organization includes a mess of situations where the overall best interest of the organization no longer comes through. Groups and individuals don't want to admit mistakes both personal and in wider senses and have alliances, competitions, team and organizational loyalty that twists their behavior.
A lot of organizations know they would benefit from having a proper whistle blower program and then proceed to crucify the first person who uses it.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#107Earlier quoted context omitted.
How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?
Not unrealistic as a consultant. My boss sells me to a project. Then clients might be asked to send me the meeting invite to kick things of. I might not have directly communicated with client at any point at this time.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#108Earlier quoted context omitted.
Sure. My comment isn't really about Apple specifically so much as bounty program misconceptions generally.
I think suspicion of bug bounties even from organizations who would clearly benefit the nost from doing them right are well founded and you are over simplifying the situation. Every organization includes a mess of situations where the overall best interest of the organization no longer comes through. Groups and individuals don't want to admit mistakes both personal and in wider senses and have alliances, competitions…
Re: Zero-Click Calendar invite vulnerability chain in macOS
#109Re: Zero-Click Calendar invite vulnerability chain in macOS
#110Earlier quoted context omitted.
There have been many documented cases where tech giants have outright refused to pay out, employing practices like: changing the rules of engagement post-factum, silently banning security researchers from active bounties, escalating good-faith disclosures to law enforcement, extreme pettiness from managers, etc. > The sums involved are not meaningful to the company Which makes it the more bewildering to see how misha…
Give me an example of a good-faith disclosure escalated to law enforcement? Some examples come to mind, but the ones I'm thinking of won't support your argument.
I was really expecting you to say this doesn't happen, I'm now left wondering why security researcher's are willing to take such risks.