Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

151–160 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#151
post #116

Earlier quoted context omitted.

> There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor. Wouldn't the payout contract prohibit reporting to anyone else?

I think so, but would Zerodium etc be able to prove it was the same person in each case? An independent researcher might have submitted the same issue to Apple coincidentally shortly after, presented in a slightly different way.

Contracts usually pay out on a schedule. If the bug gets patched then you don’t get paid.

Re: Zero click vulnerability in Apple’s macOS Mail

#152
post #3

That's gonna be devastating to the three people who use Mail.app

With the Mail.app pegging their CPU to 100%, those three people are unlikely to notice. Frankly, it's unlikely for the attacker to be able to do anything either, aside from force-terminating Mail.app. (Disclaimer: I want to like Mail.app, but I don't need another fan in my office.)

Try taking a sample; it’ll tell you what Mail is doing.

Re: Zero click vulnerability in Apple’s macOS Mail

#153
post #63
post #54

Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!

> 3-letter agency From the wikipedia page for Meltdown: "On 8 May 1995, a paper called "The Intel 80x86 Processor Architecture: Pitfalls for Secure Systems" published at the 1995 IEEE Symposium on Security and Privacy warned against a covert timing channel in the CPU cache and translation lookaside buffer (TLB). This analysis was performed under the auspices of the National Security Agency's Trusted Products Evaluati…

NSA used to have an active effort on information assurance, under the philosophy that it defended the country to have good civilian security (same reason for the NSA’s modification to the DES S-box). This unfortunately has fallen by the wayside.

(NSA shortened the key as well so it wasn’t all bunnies and chocolate)

Re: Zero click vulnerability in Apple’s macOS Mail

#154

Earlier quoted context omitted.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

Who does the verification?

NSA front company probably. They will do it for free so they can front-run the zero days.

Re: Zero click vulnerability in Apple’s macOS Mail

#155
post #38

Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?

From what I've seen, the majority of it is theater. Does that mean it's more secure than Android devices? Not necessarily.

In any case, the biggest vulnerability in any system is the end user. No amount of idiot-proofing will stop people from being scammed on an iPhone, nor will it stop someone on Android. When these companies market their "Secure Enclave" or "Titan Security", they're really just dressing up otherwise expected or boring features. The T2 chip was basically a dedicated PRNG chip with basic encoding capabilities, yet Apple paraded it as a boon for device security and game-changer for the end user. In reality, it doesn't solve any practical issues with computer security.

I've tried about every OS on the planet, and I've used them on a decent handful of different devices. I won't tell you what to think or do, but Apple's devices are difficult to appraise and hurt my head when I try to consider their impact on my overall "security". I'd much rather just use a Linux system that's transparent about it's vulnerabilities. Much of that same reasoning is why I still use Android these days.

Re: Zero click vulnerability in Apple’s macOS Mail

#156
post #4

Earlier quoted context omitted.

> 2021–03–30: Bug Bounty is still being evaluated

The company has billions of dollars. I don't think a $50k-$100k bug bounty payout for them is a big deal. Even $1m wouldn't be a big deal to them.

A company sufficiently large enough for such an amount to not be a big deal will have a money disbursal process nobody understands enough to make a one time transaction of that size in a reasonable amount of time.

Re: Zero click vulnerability in Apple’s macOS Mail

#157
post #76

Earlier quoted context omitted.

If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0] I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way. [0]: https://qz.com/1844937/hong-…

What part of iCloud is the problem?

iCloud has always been suspicious: Apple cancelled end-to-end encryption on iCloud after a certain three-letter agency filed a complaint, saying that it would disrupt investigations and have a considerable impact on the law enforcement capabilities of our country. Not to mention, Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps and relocating servers to government-controlled provinces, respectively.

Re: Zero click vulnerability in Apple’s macOS Mail

#158
post #127

Earlier quoted context omitted.

Nice morals. In reality, people often take their morals with a side of cash. Let's turn it around. In Russia, the average salary is around $600 per year. Would you turn down a $50k payout? That's 83 years of an average salary. Consider that you may be in a privileged position if you can say no to that kind of money. The solution to this is for vendors to match what the market is paying. If an RCE is worth $50k on Zer…

$600 / month is the average salary per month (according to probably the same Google search you did). Presumably someone reporting security vulnerabilities makes well more than the average.

That said... if someone pays me one or multiple annual salaries for something perfectly legal that's slightly morally questionable and indirectly linked to nasty things... I wish I could confidently say I'd say no, but I'm making no guarantees.

Re: Zero click vulnerability in Apple’s macOS Mail

#159
post #49

Earlier quoted context omitted.

If I switch, it will need to be to something that works on more than just macOS, and nonfree software will be excluded from consideration.

Thunderbird? https://www.thunderbird.net/

Thunderbird would be hot garbage even if it didn't constantly phone-home. I'd like an IMAP client that connects to my IMAP server and nothing else (connecting to outside web servers is okay if there are URLs in email and fetching remote resources is enabled).

Re: Zero click vulnerability in Apple’s macOS Mail

#160
post #156

Earlier quoted context omitted.

The company has billions of dollars. I don't think a $50k-$100k bug bounty payout for them is a big deal. Even $1m wouldn't be a big deal to them.

A company sufficiently large enough for such an amount to not be a big deal will have a money disbursal process nobody understands enough to make a one time transaction of that size in a reasonable amount of time.

Finance can always be subverted by management, but it has to be a priority.
Post reply on HN