Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

131–140 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#131

The problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.

This seems like much more of an organisational dysfunction problem than a computer science problem. I haven’t heard anything like this about Microsoft or Google: both seem responsive and eager to fix within 90 days (mostly), have responsible browser update models (where fixes for 0 days can be pushed to the whole world within hours) instead of Apple’s irresponsible “you need a 3GB OS update even if the only fix is 3 lines of code in Safari, but we don’t push updates when ready since we don’t want to cause update fatigue, so you’ll need to wait 4 weeks for the fix to come in the next programmed OS update”, and so much more. Even Android seems decent security-wise, since many of the processes that would cause security concerns get updated through Play Store, even in really old phones.

Another example: my grandma doesn’t have WiFi, and I bought her an iPhone, but iOS updates can’t be done on 4G, which can only be bypassed by internet-tethering a computer (which she doesn’t have), downloading the full IPSW, and installing it. She was on iOS 14.0 until 2 weeks ago when I fixed it. And with Safari being, according to security researchers, much less secure than Chrome, that makes me shudder. This isn’t an “anecdote” or an edge case, not everyone lives in a developed country and millions are just like my grandma, and Apple’s poor security design leaves her vulnerable for zero good technical reason, where Android wouldn’t. (They just dropped Google Play Services support for Jelly Bean a few months ago, so even an old Android phone would be reasonably secure). Caring about security requires thinking of details like this.

Re: Disclosure of three 0-day iOS vulnerabilities

#133
> My actions are in accordance with responsible disclosure guidelines (Google Project Zero discloses vulnerabilities in 90 days after reporting them to vendor, ZDI - in 120). I have waited much longer, up to half a year in one case.

"Responsible" disclosure guidelines only benefit corporations. They do not protect consumers. Why should independent researchers - working for free, no less (and sorry, the well-below-minimum-wage pittance that is most bounties does not count as not working for free) have to cow tail to corporate guidelines?

If you find a vulnerability, do everyone a favor and disclose it immediately. This places pressure on the corporation to fix it immediately, instead of ignoring it indefinitely.

Re: Disclosure of three 0-day iOS vulnerabilities

#135

Earlier quoted context omitted.

Cybersecurity is a genuinely hard problem, but stuff like this is dropping the ball entirely. It's not hard to solve exploits like faulty permission-checking after they've been reported to you. Sure, there are always going to be problems you miss. I can forgive them shipping with zero-days, it happens. Failing to respond to reports is just that: failing.

It really helps add some color to the motivations behind notorization. It seems ridiculous to me that I have to jump through so many hoops to run an executable that I trust. Especially when Apple can’t be bothered to follow up on real vulnerabilities that have already been reported.

Worse is the fact that the bulk of Apple’s security on Mac is codesigning/notarisation, and a primitive signature-based built-in antivirus. Windows seems to be doing so much better that it’s not even close, and in ways that aren’t user-hostile.

Re: Disclosure of three 0-day iOS vulnerabilities

#136
After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I thought to myself that I'd give long odds against, but let's wait and see. Long story short, the matter has now been escalated two levels and is still not resolved. Funny side-story: at one point the first-tier tech suggested I try upgrading the phone using iTunes. iTunes has not existed in MacOS for quite a while now. The way you talk to iDevices now is through the Finder (which actually makes a lot more sense), but apparently their tech support didn't get the memo.

Apple used to be the company that made devices that were secure and "just worked". Now they are as bad as Microsoft in the bad old days, and no one makes computers that "just work" any more.

:-(

Re: Disclosure of three 0-day iOS vulnerabilities

#137
post #22

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

Bug bounty programs are the antithesis of Apple's internal methodology, culture, and way of doing business. They keep everything close to the chest, they shun "outsiders", etc.. The idea that someone outside of Apple, from the unwashed masses, could find a flaw in Apple's own software is a pretty big pill for them to swallow. Thus it doesn't surprise me there are problems with their bug bounty program. I think if the…

That makes apple (the org, not the fanboys) sound a bit cultish... Can't say I'm surprised though...

Re: Disclosure of three 0-day iOS vulnerabilities

#138

Explain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would b…

I imagine they are just overwhelmed.

Let’s say they have a team of 6 engineers tasked with this. They probably receive hundreds of reports a day, many bogus, some real, but all long winded descriptions like this framed to make the vuln seem as bad as possible. In addition many vuln reports are generated by automated tools and sprayed to thousands of sites/vendors daily in the hope of one of them paying out, they seem coherent at first glance but are often nonsense or not really a vuln at all, and of course there are many duplicates or near duplicates.

If each of these takes 20 mins to triage, 1 hour to properly look at and days to confirm, you can see how a team of any reasonable size would soon be completely submerged and unable to respond to anything but the most severe and succinct vulnerability reports in a timely way.

Re: Disclosure of three 0-day iOS vulnerabilities

#139

If Apple can't handle properly disclosed vulnerabilities on their main revenue generating platform what does this say about other companies? Nothing good I'm afraid. Meanwhile the contact list on my dumbphone is perfectly safe. Time and again that's been proven to be the right decision, convenience seems to trump security in the eyes of many but I just don't want to give this up until there is a 'cloud free' smartpho…

Dumb phone might just be backdoored as well, how do you trust it? Do you have an open source dumb phone?

Re: Disclosure of three 0-day iOS vulnerabilities

#140
post #136

After the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I though…

> Apple used to be the company that made devices that were secure and "just worked".

This is a complete myth. In fact, not only did Apple devices break all the time, but they were near-impossible for regular users to repair on their own. A simple proof: how many broken iPods did people used to have lying around?

Post reply on HN