Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

201–210 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#201
post #24

Earlier quoted context omitted.

A new Mac comes with something like 30 apps in the bar. I clicked and disabled every single one of them except Finder and used Safari to download another browser. If it was any other manufacturer, this mess would be quickly denounced by reviewers as crapware. But because it is by Apple, it is not a problem at all. I am not expecting this to fix by itself. Maybe some major review blogs should first not parrot how magi…

I'm not sure I could classify any of 23 items in the default dock as as crapware. None are demos or trialware. Hell, I use all of them except for FaceTime, Podcasts, Pages, TV and Launchpad. I do remove most of them from the dock since I use spotlight to launch things, but removing System Preferences from my dock hardly makes it crapware.

They lure you into using services you wouldn't use otherwise. I don't see how having FaceTime or TV is any different than when Google was bundling Google+ in Android.

Re: Zero click vulnerability in Apple’s macOS Mail

#202

Earlier quoted context omitted.

That may be considered black-mail by some courts.

It's only blackmail if the threat is to do something you are not otherwise legally allowed to do. It is legal to, say, announce a zero-day on Twitter. Or to sell the zero-day to the NSA, or some grey hat broker like Zerodium.

In the US at least I don’t believe the act has to be illegal.

Re: Zero click vulnerability in Apple’s macOS Mail

#203
post #83

Earlier quoted context omitted.

Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.

> Apple puts rather extreme security effort into preventing iOS jailbreaks. Yes, IMO their business model is more accurately described as “gilded cages/jails” than just general “gilded/good-appearing stuff”. They deeply care about the strength of their DRM — including at the expense of end-user security, eg. you can’t access the internet through the Tor browser installed the normal macOS way without macOS broadcastin…

You don’t provide much evidence. Your second point is just opinion, “they don’t try hard enough.”

Your first point is intended to refute the effort put into stopping jailbreaking in iOS. The example you give is about privacy on Mac OS.

Last, accusing folks of being fanboys is a particularly weak argument. It says, if you don’t agree with me then your blind allegiance to a corporation renders you incapable of critical thought. Basically, if you don’t agree with me, you’re dumb. There is no practical engagement with that thesis.

Re: Zero click vulnerability in Apple’s macOS Mail

#204

For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try t…

Can you be a bit more clear on what you're implying? Genuinely curious. I thought Zerodium was selling to government agencies.. so I'm not sure what you mean by sliced up bodies in embassies. Perhaps I'm just not thinking creatively/pessimistically enough.

The sliced up bodies seems like a reference to Jamil Khashoggi. [1] I am not sure why GP links Khashoggi’s death to Zerodium.

1- https://en.m.wikipedia.org/wiki/Jamal_Khashoggi

Re: Zero click vulnerability in Apple’s macOS Mail

#205
post #150

Earlier quoted context omitted.

The part where it backs up all your messages without using a device specific key. The only things end to end encrypted are listed on this page: https://support.apple.com/en-us/HT202303 If you turn on iCloud syncing, basically you're falling back to simple "in transit" and "at rest" encryption. A lot of iPhone cracks involve just attacking your iCloud account, and then reading all of your messages from backups. This i…

> Pixel which encrypt your device backups with on-device hardware encryption. Can you set up a new android phone from an old phone’s backup? If so, how could this work? This is a standard way to set up a new iPhone: “restore” from a backup of your previous phone. Especially handy when your old phone is no longer available (lost/broken)

Yes, decryption requires the original device's unlock PIN/pattern/password:

https://security.googleblog.com/2018/10/google-and-android-h...

Not that I fully understand how hard it is to circumvent.

Re: Zero click vulnerability in Apple’s macOS Mail

#206
post #177

Earlier quoted context omitted.

The company has billions of dollars. I don't think a $50k-$100k bug bounty payout for them is a big deal. Even $1m wouldn't be a big deal to them.

The value of a bug isn't proportional to how much money the company has.

Why not? The potential damage certainly is proportional.

Re: Zero click vulnerability in Apple’s macOS Mail

#207

Earlier quoted context omitted.

I'm on 10.9 and I don't want to use anything newer. I can deal with some risk, but this vulnerability is unacceptably bad. The core problem is that really dumb feature which auto-expands certain zip files. I need to turn that off. MailWebAttachment.h contains a method: - (BOOL)isAutoArchiveAttachment; I bet that if I Swizzle that to always return false, this "feature" will go away. I'll found out this weekend... Edit…

I’m curious and not attacking. Do you follow all security-related announcements for Mac OS and do your own back ports and fixes? How did you decide 10.9 is the right balance of risk for you?

It might not be a matter of risk balance.

MacOS 10.9 was pretty much when Apple jumped the shark. That was the last version I ran before switching back to Linux, and I ran it pretty damn long in the tooth as well -- until ~2018ish.

I still have a few VM images with MacOS 10.9 that I spin up from time to time in order to run commercial software like Adobe Acrobat.

Re: Zero click vulnerability in Apple’s macOS Mail

#208

Earlier quoted context omitted.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

That may be considered black-mail by some courts.

In the US, blackmail has a very specific meaning: it is a threat to inform law enforcement of a violation of federal law under demand of a thing of value. This would actually be extortion, which is defined in 18 USC 875(d):

Whoever, with intent to extort from any person, firm, association, or corporation, any money or other thing of value, transmits in interstate or foreign commerce any communication containing any threat to injure the property or reputation of the addressee or of another or the reputation of a deceased person or any threat to accuse the addressee or any other person of a crime, shall be fined under this title or imprisoned not more than two years, or both.

https://uscode.house.gov/view.xhtml?path=/prelim@title18/par...

Re: Zero click vulnerability in Apple’s macOS Mail

#209
post #170

Earlier quoted context omitted.

iCloud has always been suspicious: Apple cancelled end-to-end encryption on iCloud after a certain three-letter agency filed a complaint, saying that it would disrupt investigations and have a considerable impact on the law enforcement capabilities of our country. Not to mention, Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps…

> Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps and relocating servers to government-controlled provinces, respectively. This is a legal requirement to operate the service in China. Apple’s choice is between offering iCloud in China or not offering it at all in China, not between offering it with local servers or with out-of…

Apple isn‘t simply running iCloud locally as the law may require. They have transferred the operations of their entire iCloud service to a government owned company, including all keys.

What Apple does in China is more than complying with local laws. They appear to be exceptionally proactive in staying in the regime‘s good graces.

Re: Zero click vulnerability in Apple’s macOS Mail

#210
post #9
post #3

That's gonna be devastating to the three people who use Mail.app

It’s my main email client, what’s wrong with it?

I tried it for a year for a Gmail-backed account. My complaints are:

1. Searches in Mail are slower and less accurate than web-client searches.

2. No access to Gmail filters. I don’t blame Mail for this, but it is a reason I returned to the web client.

3. Applying labels is harder in Mail. Maybe I missed it, but it wasn’t as easy to apply multiple labels or to apply a label to a draft email.

4. I couldn’t find a Send and Archive feature in Mail.

Basically, I like the Gmail experience. I hate Google, and I’d love to move away from them. I have for search, maps, mobile OS. For calendars, contacts, and mail, Google has the features I like.

Post reply on HN