Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

101–110 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#101
post #77
post #39

Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…

There have been many documented cases where tech giants have outright refused to pay out, employing practices like: changing the rules of engagement post-factum, silently banning security researchers from active bounties, escalating good-faith disclosures to law enforcement, extreme pettiness from managers, etc. > The sums involved are not meaningful to the company Which makes it the more bewildering to see how misha…

Give me an example of a good-faith disclosure escalated to law enforcement? Some examples come to mind, but the ones I'm thinking of won't support your argument.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#102
post #45

Earlier quoted context omitted.

I think there's a pretty big gap between "people at my company are allowed to add things to my calendar" and "random stranger anywhere in the world can add things to my calendar".

Neither of the above examples would come from people in my company.

"others who I work with who were responsible for bringing me into it" sounded to me like people at your company, who I assumed would be able to add you to the meetings. I guess I might have been mistaken

Re: Zero-Click Calendar invite vulnerability chain in macOS

#104
post #44

Earlier quoted context omitted.

If the recruiter doesn't ask me first (or I don't agree to a meeting), this is called "spam", and I would be happy for the system to just not allow it.

I have never encountered a situation where recruiter starts immediately with an invite without prior conversation (such invite also blocks the time slot of the sender - it would be stupidly ineffective to do that). It is hypothetical and improbable scenario that is not even worth mentioning here.

Okay, so why wouldn't you be able to whitelist them ahead of time then?

Re: Zero-Click Calendar invite vulnerability chain in macOS

#105
post #71

Earlier quoted context omitted.

The cost of an uncharitable blog post is massively more than the price of a bounty, like, it's not even close. The cost of an uncharitable blog post is potentially unbounded (as in: not many people in a large tech company would know how to put a ceiling on the cost), and the cost of a bounty, even a high one, is more or less chump change. Another in my long-running dramatic series "businesses pay spectacularly more f…

Companies are not set up to accurately and effectively gauge the impact of intangible costs to themselves.

Exactly, which is why intangible costs will tend to be overpriced compared to risks with low cost ceilings, like "paying out an extra bounty".

Re: Zero-Click Calendar invite vulnerability chain in macOS

#106
post #87
post #84

Earlier quoted context omitted.

Honestly, Apple is a 3.5 trillion dollar company. If the bug bounty program is understaffed then it's an intentional choice and they should fix it. And I say that as someone who's generally sympathetic to Apple.

Sure. My comment isn't really about Apple specifically so much as bounty program misconceptions generally.

I think suspicion of bug bounties even from organizations who would clearly benefit the nost from doing them right are well founded and you are over simplifying the situation.

Every organization includes a mess of situations where the overall best interest of the organization no longer comes through. Groups and individuals don't want to admit mistakes both personal and in wider senses and have alliances, competitions, team and organizational loyalty that twists their behavior.

A lot of organizations know they would benefit from having a proper whistle blower program and then proceed to crucify the first person who uses it.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#107
post #57
post #21

Earlier quoted context omitted.

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

Not unrealistic as a consultant. My boss sells me to a project. Then clients might be asked to send me the meeting invite to kick things of. I might not have directly communicated with client at any point at this time.

In a certain way, the Nigerian Prince con artist is a “consultant”…

Re: Zero-Click Calendar invite vulnerability chain in macOS

#108
post #87

Earlier quoted context omitted.

Sure. My comment isn't really about Apple specifically so much as bounty program misconceptions generally.

I think suspicion of bug bounties even from organizations who would clearly benefit the nost from doing them right are well founded and you are over simplifying the situation. Every organization includes a mess of situations where the overall best interest of the organization no longer comes through. Groups and individuals don't want to admit mistakes both personal and in wider senses and have alliances, competitions…

Bug bounty programs aren't whistleblower programs.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#110
post #77

Earlier quoted context omitted.

There have been many documented cases where tech giants have outright refused to pay out, employing practices like: changing the rules of engagement post-factum, silently banning security researchers from active bounties, escalating good-faith disclosures to law enforcement, extreme pettiness from managers, etc. > The sums involved are not meaningful to the company Which makes it the more bewildering to see how misha…

Give me an example of a good-faith disclosure escalated to law enforcement? Some examples come to mind, but the ones I'm thinking of won't support your argument.

I'm sorry tptacet, some examples come to mind?

I was really expecting you to say this doesn't happen, I'm now left wondering why security researcher's are willing to take such risks.

Post reply on HN