Earlier quoted context omitted.
MMS is whack though
I am guessing they already knew GPRS/UMTS and data plans were the future, hence they invested in iMessage. MMS already had an expiration date. Quite sure they only added it because of the PR disaster it had become.
Zero click vulnerability in Apple’s macOS Mail
111–120 of 269 posts
Re: Zero click vulnerability in Apple’s macOS Mail
#112It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.
Re: Zero click vulnerability in Apple’s macOS Mail
#113Earlier quoted context omitted.
Zerodium is interesting. Apparently this bug would fetch "Up to $50k": https://zerodium.com/images/zerodium_prices.png Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs? It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.
> There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor. Wouldn't the payout contract prohibit reporting to anyone else?
They might pay out over a long period of time for some guarantee that you'll play by their rules, though.
Re: Zero click vulnerability in Apple’s macOS Mail
#114Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!
What's to stop someone from selling a vuln to Zerodium and then just reporting it to Apple shortly after? You get paid and Apple gets to fix it.
(Just guessing though.)
Re: Zero click vulnerability in Apple’s macOS Mail
#115Earlier quoted context omitted.
If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0] I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way. [0]: https://qz.com/1844937/hong-…
What part of iCloud is the problem?
The only things end to end encrypted are listed on this page: https://support.apple.com/en-us/HT202303
If you turn on iCloud syncing, basically you're falling back to simple "in transit" and "at rest" encryption.
A lot of iPhone cracks involve just attacking your iCloud account, and then reading all of your messages from backups. This is not possible on Pixel which encrypt your device backups with on-device hardware encryption.
Re: Zero click vulnerability in Apple’s macOS Mail
#116Earlier quoted context omitted.
Zerodium is interesting. Apparently this bug would fetch "Up to $50k": https://zerodium.com/images/zerodium_prices.png Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs? It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.
> There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor. Wouldn't the payout contract prohibit reporting to anyone else?
Re: Zero click vulnerability in Apple’s macOS Mail
#117Earlier quoted context omitted.
What's to stop someone from selling a vuln to Zerodium and then just reporting it to Apple shortly after? You get paid and Apple gets to fix it.
Probably a payout over a long period of time. Lots of people would prefer a free $50k over the course of one year. (Just guessing though.)
Re: Zero click vulnerability in Apple’s macOS Mail
#118Earlier quoted context omitted.
Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.
I wouldn't call it extreme when there was a known public website allowing one-click jailbreak for good few months (not sure if it was actually ever patched or just the iOS version got eol)
If you have written a hardened, safe browser engine then you are free to share it to the world, otherwise I wouldn't downplay their efforts.
Re: Zero click vulnerability in Apple’s macOS Mail
#119Earlier quoted context omitted.
If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0] I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way. [0]: https://qz.com/1844937/hong-…
What part of iCloud is the problem?
Re: Zero click vulnerability in Apple’s macOS Mail
#120Earlier quoted context omitted.
> There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor. Wouldn't the payout contract prohibit reporting to anyone else?
What're they going to do if you break it? Sue? They might pay out over a long period of time for some guarantee that you'll play by their rules, though.