Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

121–130 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#121
post #61

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

Devil's advocate here: I've worked the other side of managing bug bounties. It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it. When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't sha…

Why wouldn't the company communicate to the researcher "we found a larger issue related to this. your bounty will be upgraded to X. Please restart the clock for public disclosure" or something along those lines. Seems like better communication would create a win-win situation.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#122
post #72

Earlier quoted context omitted.

I do wonder how much longer local, machine-based backups will continue to be supported. Could easily see a future model dropping the cable entirely, dropping local backup and modestly upping the free iCloud storage.

iPhones have supported Wifi backup to local computer for a decade now.

That automatically syncs when both your laptop and phone are plugged in and on the same WiFi network. (I think you need power nap enabled if you're using an Intel Mac.)

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#123
post #27

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.

Ideally it would be a privacy regulator who would issue a 7 figure fine and give the reporter a cut.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#124
post #61

Why are people out to crucify Apple for a story that's still being resolved? The article clearly says: "... Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day ..." "... We saw your blog post regarding this issue and your other reports…

Devil's advocate here: I've worked the other side of managing bug bounties. It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it. When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't sha…

I have also worked on managing bug bounties and that is why you keep lines of communication open with the researchers. Not to throw stones in glass houses, but there are a number of ways Apple could improve on their approach to how they do their bug bounty program.

I have heard of many researchers having extremely long delays, poor communication and simple things like not acknowledging the bug submissions.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#125

Earlier quoted context omitted.

You're framing this as if it's all about the bounty and Apple just hasn't gotten around to it yet. That's only a small fraction of the story and could easily be forgiven. If I wanted to make Apple look good, I'd focus on that part, but that would be rather biased to ignore the whole picture... Tokarev discovered 4 iOS 0-days, then reported them all to Apple back in May. After months of Apple's continued refusal to fi…

I don't know anything about Apple's bug bounty program except that there's a prevailing attitude that it is not the well-oiled machine that Google's bug bounty program is perceived to be, and I'm not super interested in making a case for Apple here. But because this is a recurring theme in every discussion about every bug bounty run by anyone: * There are valid reasons that bugs can take longer to fix than you'd expe…

> * These things are bug-dependent, and the process that runs for a zero-interaction RCE won't be the same as the process that runs for a bug that requires a malicious app store app and only gives access to the contact database.

It would be interesting to understand at what point this becomes a GDPR issue, and if the GDPR legislation can be used to pressure companies in expediting this process.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#126

This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.

There is no better alternative (at least for some people)? Just some examples: - Integration between their devices cannot be matched by others - Apple Watch has the largest app collection, great integration between iOS and Watch apps, smooth animations/UX, the most accurate GPS of smart watches - Handover of AirPods between Apple devices is a lot better than with other Bluetooth headphones - (subjective) iOS has a lo…

The killer feature for me beyond Mac-only apps: Time Machine.

Nothing matches it. I had some minor issues setting up my newly purchased M1 from an Intel backup, but it was quickly fixed when I updated the OS.

Always, always, always use a directly connected external hard dive. The networked version is terrible.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#127
post #48

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

Can't we hope they go for full-disclosure instead of selling to the highest bidder? Selling to the highest bidder just hurts apple users not apple.

Apple hurts Apple users all the time.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#128
post #123
post #27

Earlier quoted context omitted.

Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.

Ideally it would be a privacy regulator who would issue a 7 figure fine and give the reporter a cut.

If you want to lobby for the law that enables that to happen, I'm happy to sign your petition, but I wouldn't get your hopes up.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#129

Earlier quoted context omitted.

I don't know anything about Apple's bug bounty program except that there's a prevailing attitude that it is not the well-oiled machine that Google's bug bounty program is perceived to be, and I'm not super interested in making a case for Apple here. But because this is a recurring theme in every discussion about every bug bounty run by anyone: * There are valid reasons that bugs can take longer to fix than you'd expe…

> * These things are bug-dependent, and the process that runs for a zero-interaction RCE won't be the same as the process that runs for a bug that requires a malicious app store app and only gives access to the contact database. It would be interesting to understand at what point this becomes a GDPR issue, and if the GDPR legislation can be used to pressure companies in expediting this process.

There's a "be careful what you wish for" argument here, because my understanding is that the FAANG vendors are snapping up security people just as fast as they possibly can, and, again, ceteris paribus you'd rather have those people working on the actual most serious vulnerabilities rather than the ones causing the noisiest bounty drama. But you could reasonably go either way on this I guess.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#130
post #93

Earlier quoted context omitted.

> Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? Anyone who actually pays money or golden bars within a reasonable timeframe? > It's a significant vulnerability, but there's e.g. no price list entry on Zerodium On this scale I think it's "Contact us and we negotiate" sort of price.

Who? Speculate as to who they might be. The six figure numbers you're familiar with are for code execution bugs. This is obviously not that. So they're not anybody that quotes prices for bugs, or anyone directly comparable to them. Governments can already pay prices comparable to the supposed bounty valuation of this bug for code execution. They're probably not shelling out six figures in gold bars for a bug that exf…

Your comments are the only ones here which aren’t divorced from reality. It’s weird. Who are these supposed guys paying six figures for this sort of thing? It’s just not a valuable thing.
Post reply on HN