Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

111–120 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#111
post #87
post #68

Earlier quoted context omitted.

MMS is whack though

I am guessing they already knew GPRS/UMTS and data plans were the future, hence they invested in iMessage. MMS already had an expiration date. Quite sure they only added it because of the PR disaster it had become.

I often use MMS. Whats the expiration date?

Re: Zero click vulnerability in Apple’s macOS Mail

#113

Earlier quoted context omitted.

Zerodium is interesting. Apparently this bug would fetch "Up to $50k": https://zerodium.com/images/zerodium_prices.png Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs? It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.

> There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor. Wouldn't the payout contract prohibit reporting to anyone else?

What're they going to do if you break it? Sue?

They might pay out over a long period of time for some guarantee that you'll play by their rules, though.

Re: Zero click vulnerability in Apple’s macOS Mail

#114
post #54

Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!

What's to stop someone from selling a vuln to Zerodium and then just reporting it to Apple shortly after? You get paid and Apple gets to fix it.

Probably a payout over a long period of time. Lots of people would prefer a free $50k over the course of one year.

(Just guessing though.)

Re: Zero click vulnerability in Apple’s macOS Mail

#115
post #76

Earlier quoted context omitted.

If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0] I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way. [0]: https://qz.com/1844937/hong-…

What part of iCloud is the problem?

The part where it backs up all your messages without using a device specific key.

The only things end to end encrypted are listed on this page: https://support.apple.com/en-us/HT202303

If you turn on iCloud syncing, basically you're falling back to simple "in transit" and "at rest" encryption.

A lot of iPhone cracks involve just attacking your iCloud account, and then reading all of your messages from backups. This is not possible on Pixel which encrypt your device backups with on-device hardware encryption.

Re: Zero click vulnerability in Apple’s macOS Mail

#116

Earlier quoted context omitted.

Zerodium is interesting. Apparently this bug would fetch "Up to $50k": https://zerodium.com/images/zerodium_prices.png Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs? It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.

> There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor. Wouldn't the payout contract prohibit reporting to anyone else?

I think so, but would Zerodium etc be able to prove it was the same person in each case? An independent researcher might have submitted the same issue to Apple coincidentally shortly after, presented in a slightly different way.

Re: Zero click vulnerability in Apple’s macOS Mail

#117

Earlier quoted context omitted.

What's to stop someone from selling a vuln to Zerodium and then just reporting it to Apple shortly after? You get paid and Apple gets to fix it.

Probably a payout over a long period of time. Lots of people would prefer a free $50k over the course of one year. (Just guessing though.)

I would guess it would have a Non Disclosure Agreement attached, along with the mercenary reputation damage one take on by breaking the contract. One would not be let back in the club. Do you think it wise to break a contract (eg: steal from) a weapons dealer?

Re: Zero click vulnerability in Apple’s macOS Mail

#118

Earlier quoted context omitted.

Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.

I wouldn't call it extreme when there was a known public website allowing one-click jailbreak for good few months (not sure if it was actually ever patched or just the iOS version got eol)

It's unsurprising that the main vector for iOS jailbreaks would be through the web engine. The FreeBSD-based PlayStation 4 was also jailbroken via it's browser.

If you have written a hardened, safe browser engine then you are free to share it to the world, otherwise I wouldn't downplay their efforts.

Re: Zero click vulnerability in Apple’s macOS Mail

#119
post #76

Earlier quoted context omitted.

If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0] I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way. [0]: https://qz.com/1844937/hong-…

What part of iCloud is the problem?

The agencies are believed to have the iCloud decryption keys.

Re: Zero click vulnerability in Apple’s macOS Mail

#120

Earlier quoted context omitted.

> There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor. Wouldn't the payout contract prohibit reporting to anyone else?

What're they going to do if you break it? Sue? They might pay out over a long period of time for some guarantee that you'll play by their rules, though.

There is a non-zero probability of not being alive any more. I don't think you understand the nature of that game.
Post reply on HN