Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

161–170 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#162

Earlier quoted context omitted.

I don't see how selling to zerodium is more morally bankrupt than working for defense contractors, which plenty of tech people do.

The output of the defense industry is used to hurt civilians less frequently. But I'm not here to excuse either.

> defense industry is used to hurt civilians less frequently

... based on?

Re: Zero click vulnerability in Apple’s macOS Mail

#163
post #9

Earlier quoted context omitted.

It’s my main email client, what’s wrong with it?

I have an issue where it always thinks a couple of accounts are offline. I have to click the squiggle for it to download those accounts. Every restart I have to do the same thing.

That’s really annoying. I self host my email so haven’t seen something like that for a while. Last time I did it was I think related to some sort of contradiction between my port number selection and the encryption type for either the incoming or outgoing server but I can’t quite remember.

Re: Zero click vulnerability in Apple’s macOS Mail

#164
post #19

It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

That may be considered black-mail by some courts.

Re: Zero click vulnerability in Apple’s macOS Mail

#166

Earlier quoted context omitted.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

That may be considered black-mail by some courts.

I guess that's true. Whats the end state if Apple refuses to pay?

Re: Zero click vulnerability in Apple’s macOS Mail

#167

Earlier quoted context omitted.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

That may be considered black-mail by some courts.

I dont think apple is entitled to that information on any basis, and i dont think its a legitimate threat to expose actual ill behaviour

Re: Zero click vulnerability in Apple’s macOS Mail

#168
post #19

It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

How would price discovery work to "correctly price bugs"

What is a bugs correct price? The price that a bad actor would pay for it?

Re: Zero click vulnerability in Apple’s macOS Mail

#170

Earlier quoted context omitted.

What part of iCloud is the problem?

iCloud has always been suspicious: Apple cancelled end-to-end encryption on iCloud after a certain three-letter agency filed a complaint, saying that it would disrupt investigations and have a considerable impact on the law enforcement capabilities of our country. Not to mention, Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps…

> Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps and relocating servers to government-controlled provinces, respectively.

This is a legal requirement to operate the service in China. Apple’s choice is between offering iCloud in China or not offering it at all in China, not between offering it with local servers or with out-of-country servers.

Post reply on HN