> The attacker can exploit this to conduct a successful directory traversal attack by setting an arbitrary path to a file in the ATTACH section with: “FILENAME=../../../PoC.txt”.
Zero-Click Calendar invite vulnerability chain in macOS
121–130 of 166 posts
Re: Zero-Click Calendar invite vulnerability chain in macOS
#122Earlier quoted context omitted.
No, it's because Apple's 'product security' team that investigates and pays out bug bounties is horribly mismanaged and ineffective. It was recently moved from the SWE program office to SEAR (security engineering & arch), and the manager was recently shown the door and went to AirBNB. The team members are mostly new college grads (ICT2's and 3's) who wouldn't pass a coding interview elsewhere in the company, and most…
I have no idea about how well the bounty program at Apple is managed, so, without affirming this, I acknowledge this is another plausible explanation: it's just an understaffed team that needs to get its act together. The only crusade I'm on is against the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false, like, the opposite of the truth. I think it's valuable for…
Re: Zero-Click Calendar invite vulnerability chain in macOS
#123Step 1 is a crazy vulnerability on its own. How did Apple not consider this? > The attacker can exploit this to conduct a successful directory traversal attack by setting an arbitrary path to a file in the ATTACH section with: “FILENAME=../../../PoC.txt”.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#124Step 1 is a crazy vulnerability on its own. How did Apple not consider this? > The attacker can exploit this to conduct a successful directory traversal attack by setting an arbitrary path to a file in the ATTACH section with: “FILENAME=../../../PoC.txt”.
I think this speaks to a larger problem that likely exists in every company: certainly someone at Apple had written a library function to do this safely, but how do you enforce that that function is used, rather than reimplemented unsafely from scratch? Especially if code reviewers are also unfamiliar with the library. Are there any modern solutions for this?
Edit: and there are actually 4 library functions with subtly different behaviors
Re: Zero-Click Calendar invite vulnerability chain in macOS
#125Earlier quoted context omitted.
I have no idea about how well the bounty program at Apple is managed, so, without affirming this, I acknowledge this is another plausible explanation: it's just an understaffed team that needs to get its act together. The only crusade I'm on is against the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false, like, the opposite of the truth. I think it's valuable for…
That's the same thing.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#126Earlier quoted context omitted.
What I haven't had time to learn more about is when bounties are a such a tiny drop in the bucket for such an enormous number of users and revenue, how is it not a win-win?
With tech giants there's really no win win, only 1 win. They win either way. So why bother?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#127Earlier quoted context omitted.
With tech giants there's really no win win, only 1 win. They win either way. So why bother?
They don't win when an important-sized customer cares, especially when they're government-sized and can regulate you.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#128It sure is a good thing that Apple has fixed all these, and has put out patches for all effected versions, since they care about their users' privacy, right? Right? I know Apple has now switched to 10 years for MacOS, and 7ish years of iOS, but I hope the EU passes some laws to make this a requirement, rather than something a company can choose to provide or not.
One thing I think you won't like about this is that it's easier for large commercial vendors to comply than it is for open source projects.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#129Earlier quoted context omitted.
Getting paid to fuck off at conferences and hang out with hackers on the company dime instead of staring at a screen in a cubicle all day sounds pretty awesome. Do I detect some jealousy or resentment that you haven't mastered the art of the corporate grift?
This is like every software security team of every form in the whole industry. Sometimes it's real, sometimes it's not, but it's evergreen problem.
I think they could use a little more ritualized shaming: https://en.wikipedia.org/wiki/Leveling_mechanism
Only Linus is brave enough to do this.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#130Earlier quoted context omitted.
I think both the point you’re making and the idea you’re arguing against ascribe a level of agency and rationality to large organizations that doesn’t reflect their reality. In that way they’re both “not even wrong.” But then I can see your point to a degree at least.
I want to say again that I'm not making this point by way of a first-principles derivation of what's going on. I know for a fact that the norm in large bounty programs is to incentivize payouts. I don't know that for sure about Apple's program, but it seems extraordinarily unlikely that they depart from this norm, given the care and ceremony with which they rolled this out (much later than other big tech firms). None…