Earlier quoted context omitted.
> There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor. Wouldn't the payout contract prohibit reporting to anyone else?
I think so, but would Zerodium etc be able to prove it was the same person in each case? An independent researcher might have submitted the same issue to Apple coincidentally shortly after, presented in a slightly different way.
Zero click vulnerability in Apple’s macOS Mail
151–160 of 269 posts
Re: Zero click vulnerability in Apple’s macOS Mail
#152That's gonna be devastating to the three people who use Mail.app
With the Mail.app pegging their CPU to 100%, those three people are unlikely to notice. Frankly, it's unlikely for the attacker to be able to do anything either, aside from force-terminating Mail.app. (Disclaimer: I want to like Mail.app, but I don't need another fan in my office.)
Re: Zero click vulnerability in Apple’s macOS Mail
#153Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!
> 3-letter agency From the wikipedia page for Meltdown: "On 8 May 1995, a paper called "The Intel 80x86 Processor Architecture: Pitfalls for Secure Systems" published at the 1995 IEEE Symposium on Security and Privacy warned against a covert timing channel in the CPU cache and translation lookaside buffer (TLB). This analysis was performed under the auspices of the National Security Agency's Trusted Products Evaluati…
(NSA shortened the key as well so it wasn’t all bunnies and chocolate)
Re: Zero click vulnerability in Apple’s macOS Mail
#154Earlier quoted context omitted.
I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.
Who does the verification?
Re: Zero click vulnerability in Apple’s macOS Mail
#155Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?
In any case, the biggest vulnerability in any system is the end user. No amount of idiot-proofing will stop people from being scammed on an iPhone, nor will it stop someone on Android. When these companies market their "Secure Enclave" or "Titan Security", they're really just dressing up otherwise expected or boring features. The T2 chip was basically a dedicated PRNG chip with basic encoding capabilities, yet Apple paraded it as a boon for device security and game-changer for the end user. In reality, it doesn't solve any practical issues with computer security.
I've tried about every OS on the planet, and I've used them on a decent handful of different devices. I won't tell you what to think or do, but Apple's devices are difficult to appraise and hurt my head when I try to consider their impact on my overall "security". I'd much rather just use a Linux system that's transparent about it's vulnerabilities. Much of that same reasoning is why I still use Android these days.
Re: Zero click vulnerability in Apple’s macOS Mail
#156Earlier quoted context omitted.
> 2021–03–30: Bug Bounty is still being evaluated
The company has billions of dollars. I don't think a $50k-$100k bug bounty payout for them is a big deal. Even $1m wouldn't be a big deal to them.
Re: Zero click vulnerability in Apple’s macOS Mail
#157Earlier quoted context omitted.
If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0] I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way. [0]: https://qz.com/1844937/hong-…
What part of iCloud is the problem?
Re: Zero click vulnerability in Apple’s macOS Mail
#158Earlier quoted context omitted.
Nice morals. In reality, people often take their morals with a side of cash. Let's turn it around. In Russia, the average salary is around $600 per year. Would you turn down a $50k payout? That's 83 years of an average salary. Consider that you may be in a privileged position if you can say no to that kind of money. The solution to this is for vendors to match what the market is paying. If an RCE is worth $50k on Zer…
$600 / month is the average salary per month (according to probably the same Google search you did). Presumably someone reporting security vulnerabilities makes well more than the average.
Re: Zero click vulnerability in Apple’s macOS Mail
#159Earlier quoted context omitted.
If I switch, it will need to be to something that works on more than just macOS, and nonfree software will be excluded from consideration.
Thunderbird? https://www.thunderbird.net/
Re: Zero click vulnerability in Apple’s macOS Mail
#160Earlier quoted context omitted.
The company has billions of dollars. I don't think a $50k-$100k bug bounty payout for them is a big deal. Even $1m wouldn't be a big deal to them.
A company sufficiently large enough for such an amount to not be a big deal will have a money disbursal process nobody understands enough to make a one time transaction of that size in a reasonable amount of time.