Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

121–130 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#121
post #19

It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.

I like this idea.

1. Company verifies the bug

2. Assigns it a price according to impact

3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access.

Different bug markets can compete to correctly price bugs.

Re: Zero click vulnerability in Apple’s macOS Mail

#122

For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try t…

Um, how does that gel with thousands of engineers who work for FB?

Re: Zero click vulnerability in Apple’s macOS Mail

#123

For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try t…

is there any reason to not just sell to zerodium and then report to apple afterwards?

Re: Zero click vulnerability in Apple’s macOS Mail

#124

For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try t…

Nice morals. In reality, people often take their morals with a side of cash.

Let's turn it around. In Russia, the average salary is around $600 per year. Would you turn down a $50k payout? That's 83 years of an average salary.

Consider that you may be in a privileged position if you can say no to that kind of money.

The solution to this is for vendors to match what the market is paying. If an RCE is worth $50k on Zerodium, perhaps it's worth something similar to Apple not to have headlines about so-and-so exploit being used for cutting up bodies in an embassy.

EDIT: Oops. Divide 83 by 12. But you'll find it hard to locate someone willing to say no to 7 years of salary for ~zero additional work.

Re: Zero click vulnerability in Apple’s macOS Mail

#125
post #49
post #30

Earlier quoted context omitted.

I like Mailmate

If I switch, it will need to be to something that works on more than just macOS, and nonfree software will be excluded from consideration.

Thunderbird?

https://www.thunderbird.net/

Re: Zero click vulnerability in Apple’s macOS Mail

#126

For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try t…

is there any reason to not just sell to zerodium and then report to apple afterwards?

From Zerodium’s FAQ:

“By signing the agreement, you will accept an exclusive sale of your research to ZERODIUM and transfer all related intellectual property rights to us, meaning that the research becomes the exclusive property of ZERODIUM and you are not allowed to re-sell, share, publish, or report the research to any other person or entity.”

Re: Zero click vulnerability in Apple’s macOS Mail

#127

For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try t…

Nice morals. In reality, people often take their morals with a side of cash. Let's turn it around. In Russia, the average salary is around $600 per year. Would you turn down a $50k payout? That's 83 years of an average salary. Consider that you may be in a privileged position if you can say no to that kind of money. The solution to this is for vendors to match what the market is paying. If an RCE is worth $50k on Zer…

$600 / month is the average salary per month (according to probably the same Google search you did). Presumably someone reporting security vulnerabilities makes well more than the average.

Re: Zero click vulnerability in Apple’s macOS Mail

#128
post #19

It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.

Does it? It seems the priority should be fixing the issue.

Do you think the finance department is pushing the changes?

Re: Zero click vulnerability in Apple’s macOS Mail

#129

Earlier quoted context omitted.

https://www.tomsguide.com/news/police-say-android-phones-are... >This is supported by a look at smartphone cracking company Cellebrite’s effectiveness at breaking into different phones. Cellebrite can easily open up any iPhone X or earlier iPhone, but the same software used on a Google Pixel 2 or Galaxy S9 extracts very little information, and nothing at all in the case of the Huawei P20 Pro. >That’s not to say that…

It's called security through obscurity.

What? the iPhone's closed-source operating system?

Re: Zero click vulnerability in Apple’s macOS Mail

#130
post #87
post #68

Earlier quoted context omitted.

MMS is whack though

I am guessing they already knew GPRS/UMTS and data plans were the future, hence they invested in iMessage. MMS already had an expiration date. Quite sure they only added it because of the PR disaster it had become.

and MMS is still the only thing that works on every phone out of the box...
Post reply on HN