Earlier quoted context omitted.
A new Mac comes with something like 30 apps in the bar. I clicked and disabled every single one of them except Finder and used Safari to download another browser. If it was any other manufacturer, this mess would be quickly denounced by reviewers as crapware. But because it is by Apple, it is not a problem at all. I am not expecting this to fix by itself. Maybe some major review blogs should first not parrot how magi…
I'm not sure I could classify any of 23 items in the default dock as as crapware. None are demos or trialware. Hell, I use all of them except for FaceTime, Podcasts, Pages, TV and Launchpad. I do remove most of them from the dock since I use spotlight to launch things, but removing System Preferences from my dock hardly makes it crapware.
Zero click vulnerability in Apple’s macOS Mail
201–210 of 269 posts
Re: Zero click vulnerability in Apple’s macOS Mail
#202Earlier quoted context omitted.
That may be considered black-mail by some courts.
It's only blackmail if the threat is to do something you are not otherwise legally allowed to do. It is legal to, say, announce a zero-day on Twitter. Or to sell the zero-day to the NSA, or some grey hat broker like Zerodium.
Re: Zero click vulnerability in Apple’s macOS Mail
#203Earlier quoted context omitted.
Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.
> Apple puts rather extreme security effort into preventing iOS jailbreaks. Yes, IMO their business model is more accurately described as “gilded cages/jails” than just general “gilded/good-appearing stuff”. They deeply care about the strength of their DRM — including at the expense of end-user security, eg. you can’t access the internet through the Tor browser installed the normal macOS way without macOS broadcastin…
Your first point is intended to refute the effort put into stopping jailbreaking in iOS. The example you give is about privacy on Mac OS.
Last, accusing folks of being fanboys is a particularly weak argument. It says, if you don’t agree with me then your blind allegiance to a corporation renders you incapable of critical thought. Basically, if you don’t agree with me, you’re dumb. There is no practical engagement with that thesis.
Re: Zero click vulnerability in Apple’s macOS Mail
#204For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try t…
Can you be a bit more clear on what you're implying? Genuinely curious. I thought Zerodium was selling to government agencies.. so I'm not sure what you mean by sliced up bodies in embassies. Perhaps I'm just not thinking creatively/pessimistically enough.
Re: Zero click vulnerability in Apple’s macOS Mail
#205Earlier quoted context omitted.
The part where it backs up all your messages without using a device specific key. The only things end to end encrypted are listed on this page: https://support.apple.com/en-us/HT202303 If you turn on iCloud syncing, basically you're falling back to simple "in transit" and "at rest" encryption. A lot of iPhone cracks involve just attacking your iCloud account, and then reading all of your messages from backups. This i…
> Pixel which encrypt your device backups with on-device hardware encryption. Can you set up a new android phone from an old phone’s backup? If so, how could this work? This is a standard way to set up a new iPhone: “restore” from a backup of your previous phone. Especially handy when your old phone is no longer available (lost/broken)
https://security.googleblog.com/2018/10/google-and-android-h...
Not that I fully understand how hard it is to circumvent.
Re: Zero click vulnerability in Apple’s macOS Mail
#206Earlier quoted context omitted.
The company has billions of dollars. I don't think a $50k-$100k bug bounty payout for them is a big deal. Even $1m wouldn't be a big deal to them.
The value of a bug isn't proportional to how much money the company has.
Re: Zero click vulnerability in Apple’s macOS Mail
#207Earlier quoted context omitted.
I'm on 10.9 and I don't want to use anything newer. I can deal with some risk, but this vulnerability is unacceptably bad. The core problem is that really dumb feature which auto-expands certain zip files. I need to turn that off. MailWebAttachment.h contains a method: - (BOOL)isAutoArchiveAttachment; I bet that if I Swizzle that to always return false, this "feature" will go away. I'll found out this weekend... Edit…
I’m curious and not attacking. Do you follow all security-related announcements for Mac OS and do your own back ports and fixes? How did you decide 10.9 is the right balance of risk for you?
MacOS 10.9 was pretty much when Apple jumped the shark. That was the last version I ran before switching back to Linux, and I ran it pretty damn long in the tooth as well -- until ~2018ish.
I still have a few VM images with MacOS 10.9 that I spin up from time to time in order to run commercial software like Adobe Acrobat.
Re: Zero click vulnerability in Apple’s macOS Mail
#208Earlier quoted context omitted.
I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.
That may be considered black-mail by some courts.
Whoever, with intent to extort from any person, firm, association, or corporation, any money or other thing of value, transmits in interstate or foreign commerce any communication containing any threat to injure the property or reputation of the addressee or of another or the reputation of a deceased person or any threat to accuse the addressee or any other person of a crime, shall be fined under this title or imprisoned not more than two years, or both.
https://uscode.house.gov/view.xhtml?path=/prelim@title18/par...
Re: Zero click vulnerability in Apple’s macOS Mail
#209Earlier quoted context omitted.
iCloud has always been suspicious: Apple cancelled end-to-end encryption on iCloud after a certain three-letter agency filed a complaint, saying that it would disrupt investigations and have a considerable impact on the law enforcement capabilities of our country. Not to mention, Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps…
> Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps and relocating servers to government-controlled provinces, respectively. This is a legal requirement to operate the service in China. Apple’s choice is between offering iCloud in China or not offering it at all in China, not between offering it with local servers or with out-of…
What Apple does in China is more than complying with local laws. They appear to be exceptionally proactive in staying in the regime‘s good graces.
Re: Zero click vulnerability in Apple’s macOS Mail
#210That's gonna be devastating to the three people who use Mail.app
It’s my main email client, what’s wrong with it?
1. Searches in Mail are slower and less accurate than web-client searches.
2. No access to Gmail filters. I don’t blame Mail for this, but it is a reason I returned to the web client.
3. Applying labels is harder in Mail. Maybe I missed it, but it wasn’t as easy to apply multiple labels or to apply a label to a draft email.
4. I couldn’t find a Send and Archive feature in Mail.
Basically, I like the Gmail experience. I hate Google, and I’d love to move away from them. I have for search, maps, mobile OS. For calendars, contacts, and mail, Google has the features I like.