Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

161–166 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#161
post #32

Earlier quoted context omitted.

Very yes.

seems this just encourage researchers to sell zero-day exploits to organize crime and/or alphabet letter agencies. No wonder we have no digital security at all! Big tech don't really care about security or privacy. Why are we even using their stuff?

It does not. Bounties and zero-day markets are different things. Lots of people actively sell to both.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#164
post #142
post #140

Earlier quoted context omitted.

> the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false Eh, it's likely usually true, but I've worked for a company which was attracted to the bounty program idea mainly for the optics and very much did push back on/was very reluctant to pay out on bounties. And when I say "for the optics" I mean not only for the company being able to boast about having a bounty p…

Ok but not a company as reputable as Apple, yes? Apple historically used to have a deservedly good reputation for this. I was quite shocked at this story.

> not a company as reputable as Apple, yes?

Definitely not, in fact rather the opposite. I was just sharing the anecdote as a counter to the otherwise fairly blanket claims being made upstream.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#165
post #142
post #140

Earlier quoted context omitted.

> the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false Eh, it's likely usually true, but I've worked for a company which was attracted to the bounty program idea mainly for the optics and very much did push back on/was very reluctant to pay out on bounties. And when I say "for the optics" I mean not only for the company being able to boast about having a bounty p…

Ok but not a company as reputable as Apple, yes? Apple historically used to have a deservedly good reputation for this. I was quite shocked at this story.

> Apple historically used to have a deservedly good reputation for this.

Are they? Apple only started their bug bounty program (with monetary rewards) merely 5 years ago, 12 years after first iOS release and well after everyone else. They are not very transparent about bugs and payouts (which is understandable) so I wonder where this good reputation comes from?

(if you count their invitation-only program then it started in 2016, 8 years ago)

Re: Zero-Click Calendar invite vulnerability chain in macOS

#166

Earlier quoted context omitted.

The cost here is Apple changing their processes which is exceptionally painful for them

What processes would those be, and do you have actual knowledge of them?

The processes that involve interacting with external parties, which has long been something Apple has been really bad at.
Post reply on HN