Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

171–180 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#171

Earlier quoted context omitted.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

That may be considered black-mail by some courts.

Can you explain it more? What can make it a black-mail and why?

If there is no intent to abuse the bug when not paied then there is no additional threat there from simply notifying the company that some threat is already present. How it can become a black-mail?

So every report about discovered bug can be considered as black-mail? If one discovers a bug, reports it to the company and says that after 3 months it will be public it's a black-mail too?

Or the payment request makes it different? And if person doesn't threat to publish the bug then it's ok?

Re: Zero click vulnerability in Apple’s macOS Mail

#172
post #170

Earlier quoted context omitted.

iCloud has always been suspicious: Apple cancelled end-to-end encryption on iCloud after a certain three-letter agency filed a complaint, saying that it would disrupt investigations and have a considerable impact on the law enforcement capabilities of our country. Not to mention, Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps…

> Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps and relocating servers to government-controlled provinces, respectively. This is a legal requirement to operate the service in China. Apple’s choice is between offering iCloud in China or not offering it at all in China, not between offering it with local servers or with out-of…

It is indeed a legal requirement, and both Google and Microsoft have chosen not to provide services in those areas for this exact reason. Apple is the only major tech company that still operates in China, and has become pretty politically passive in the region. I only bring this up because Apple claims that "privacy is a human right", which I suppose is pretty conditional to what kind of human you are.

Re: Zero click vulnerability in Apple’s macOS Mail

#173
post #38

Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?

From what I've seen, the majority of it is theater. Does that mean it's more secure than Android devices? Not necessarily. In any case, the biggest vulnerability in any system is the end user. No amount of idiot-proofing will stop people from being scammed on an iPhone, nor will it stop someone on Android. When these companies market their "Secure Enclave" or "Titan Security", they're really just dressing up otherwis…

And your point being that Android gets more updates/fixes than Apple? Lol, only Apple has a proven track record of providing 5 year old devices with updates/fixes unlike anything from Android, unless you are comfortable flashing your own builds.

Re: Zero click vulnerability in Apple’s macOS Mail

#176

Earlier quoted context omitted.

That may be considered black-mail by some courts.

Can you explain it more? What can make it a black-mail and why? If there is no intent to abuse the bug when not paied then there is no additional threat there from simply notifying the company that some threat is already present. How it can become a black-mail? So every report about discovered bug can be considered as black-mail? If one discovers a bug, reports it to the company and says that after 3 months it will b…

Definition: Blackmail involves a threat to do something that would cause a person to suffer embarrassment or financial loss, unless that person meets certain demands. [0]

[0] https://www.justia.com/criminal/offenses/white-collar-crimes...

Re: Zero click vulnerability in Apple’s macOS Mail

#177
post #4

Earlier quoted context omitted.

> 2021–03–30: Bug Bounty is still being evaluated

The company has billions of dollars. I don't think a $50k-$100k bug bounty payout for them is a big deal. Even $1m wouldn't be a big deal to them.

The value of a bug isn't proportional to how much money the company has.

Re: Zero click vulnerability in Apple’s macOS Mail

#178

How does Apple claim they're "secure by design?" [1] They seem to have the same issues as everyone else. [1] https://www.apple.com/business/docs/site/AAW_Platform_Securi...

More content for the linked list: https://news.ycombinator.com/item?id=24958256

Thanks for taking the time to track this.

Re: Zero click vulnerability in Apple’s macOS Mail

#179

Earlier quoted context omitted.

That may be considered black-mail by some courts.

I guess that's true. Whats the end state if Apple refuses to pay?

“It would be a shame if someone used this vulnerability”

Re: Zero click vulnerability in Apple’s macOS Mail

#180

Earlier quoted context omitted.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

How would price discovery work to "correctly price bugs" What is a bugs correct price? The price that a bad actor would pay for it?

Some value between the cost of not fixing it and the value of exploiting it
Post reply on HN