Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

211–220 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#211
post #170

Earlier quoted context omitted.

> Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps and relocating servers to government-controlled provinces, respectively. This is a legal requirement to operate the service in China. Apple’s choice is between offering iCloud in China or not offering it at all in China, not between offering it with local servers or with out-of…

Apple isn‘t simply running iCloud locally as the law may require. They have transferred the operations of their entire iCloud service to a government owned company, including all keys. What Apple does in China is more than complying with local laws. They appear to be exceptionally proactive in staying in the regime‘s good graces.

Running cloud services in China requires establishing a JV with a local partner. Look at AWS China as another example of this, but there are many.

Can you provide a reference for Apple's JV partners being government owned? Any company in China of course has to do as the Party tells them to, so I guess the difference is largely academic, but I haven't seen it mentioned before that Apple's China partners are government-owned.

Re: Zero click vulnerability in Apple’s macOS Mail

#212
post #170

Earlier quoted context omitted.

> Apple's behavior has been decreasingly auspicious in places like Russia and China, where they've started preinstalling state-sponsored apps and relocating servers to government-controlled provinces, respectively. This is a legal requirement to operate the service in China. Apple’s choice is between offering iCloud in China or not offering it at all in China, not between offering it with local servers or with out-of…

It is indeed a legal requirement, and both Google and Microsoft have chosen not to provide services in those areas for this exact reason. Apple is the only major tech company that still operates in China, and has become pretty politically passive in the region. I only bring this up because Apple claims that "privacy is a human right", which I suppose is pretty conditional to what kind of human you are.

> Apple is the only major tech company that still operates in China

This is not even remotely true, even if you define "major tech company" to mean "major US tech company".

Both AWS and Azure have actual cloud regions in China (delivered with a local JV partner just like Apple's cloud services are).

Even Google operates there in various ways - they have four offices there, they manufacture hardware there, and they sell tons of ads to Chinese companies via their local subsidiaries (for display outside of China obviously).

Re: Zero click vulnerability in Apple’s macOS Mail

#213
post #211

Earlier quoted context omitted.

Apple isn‘t simply running iCloud locally as the law may require. They have transferred the operations of their entire iCloud service to a government owned company, including all keys. What Apple does in China is more than complying with local laws. They appear to be exceptionally proactive in staying in the regime‘s good graces.

Running cloud services in China requires establishing a JV with a local partner. Look at AWS China as another example of this, but there are many. Can you provide a reference for Apple's JV partners being government owned ? Any company in China of course has to do as the Party tells them to, so I guess the difference is largely academic, but I haven't seen it mentioned before that Apple's China partners are governmen…

This is what was reported at the time:

https://techcrunch.com/2018/07/17/apples-icloud-user-data-in...

There are conflicting reports and vague language around how exactly the keys are handled.

Re: Zero click vulnerability in Apple’s macOS Mail

#214
post #211

Earlier quoted context omitted.

Running cloud services in China requires establishing a JV with a local partner. Look at AWS China as another example of this, but there are many. Can you provide a reference for Apple's JV partners being government owned ? Any company in China of course has to do as the Party tells them to, so I guess the difference is largely academic, but I haven't seen it mentioned before that Apple's China partners are governmen…

This is what was reported at the time: https://techcrunch.com/2018/07/17/apples-icloud-user-data-in... There are conflicting reports and vague language around how exactly the keys are handled.

Thanks for the link, very interesting.

Re: Zero click vulnerability in Apple’s macOS Mail

#215
post #9

Earlier quoted context omitted.

It’s my main email client, what’s wrong with it?

I tried it for a year for a Gmail-backed account. My complaints are: 1. Searches in Mail are slower and less accurate than web-client searches. 2. No access to Gmail filters. I don’t blame Mail for this, but it is a reason I returned to the web client. 3. Applying labels is harder in Mail. Maybe I missed it, but it wasn’t as easy to apply multiple labels or to apply a label to a draft email. 4. I couldn’t find a Send…

Agree with your points. My use case doesn’t involve gmail so can see how that complicated things especially from a UX perspective. I wish IMAP/standards had more of a say in email like they did (sort of) for web.

Re: Zero click vulnerability in Apple’s macOS Mail

#216

Earlier quoted context omitted.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

How would price discovery work to "correctly price bugs" What is a bugs correct price? The price that a bad actor would pay for it?

We have CVSS scores for grading vulnerabilities. So that could be useful as a start.

Re: Zero click vulnerability in Apple’s macOS Mail

#217

Earlier quoted context omitted.

Can you be a bit more clear on what you're implying? Genuinely curious. I thought Zerodium was selling to government agencies.. so I'm not sure what you mean by sliced up bodies in embassies. Perhaps I'm just not thinking creatively/pessimistically enough.

The sliced up bodies seems like a reference to Jamil Khashoggi. [1] I am not sure why GP links Khashoggi’s death to Zerodium. 1- https://en.m.wikipedia.org/wiki/Jamal_Khashoggi

Very confusing; A Saudi national was assassinated in the Saudi embassy by agents of the Saudi government. Linking this to Zerodium makes Zero sense. You don't need to do any digging to find out when someone is at your doorstep

Re: Zero click vulnerability in Apple’s macOS Mail

#218

Earlier quoted context omitted.

I’m curious and not attacking. Do you follow all security-related announcements for Mac OS and do your own back ports and fixes? How did you decide 10.9 is the right balance of risk for you?

It might not be a matter of risk balance. MacOS 10.9 was pretty much when Apple jumped the shark. That was the last version I ran before switching back to Linux, and I ran it pretty damn long in the tooth as well -- until ~2018ish. I still have a few VM images with MacOS 10.9 that I spin up from time to time in order to run commercial software like Adobe Acrobat.

Just curious, what did Apple do (or not do) in 10.10 to earn the “jumped the shark” description?

Re: Zero click vulnerability in Apple’s macOS Mail

#219

Earlier quoted context omitted.

What web-based client will allow you to read email without an Internet connection in Safari? What marginal advantage does a third-party iOS client provide, that outweighs the risks of installing another app that is going to spy on me, have weaker integration with the OS and force me to relearn every new UI design language they come up with that in no way resembles the rest of the OS or its function and behavior?

>What web-based client will allow you to read email without an Internet connection in Safari? I understand why it might be a deal breaker for you, but browsing email offline is not a use case everyone has.

I want to downvote you because what you said sounds so absurd to me as an “old” (self identify at 40 thanks tech) person.

Thanks for saying this - it’s important to understand that the way things were are not alway the way things are :)

Re: Zero click vulnerability in Apple’s macOS Mail

#220

Earlier quoted context omitted.

A big difference is that the software running on Apple devices is less complex. For example there is significantly less hardware support. iMessage only talks to other iMessage instances (eg no browser support). There is only one web browser engine. Third party apps can't do JIT code generation. Older APIs are actively removed, breaking existing apps (vs providing backwards compatibility). In general less complexity i…

> Android had it since ~2012. I seriously wonder: what difference did it make? Was there any groundbreaking thing iOS users missed for 8 years? Apple is just great in omitting things and keeping focus to deliver a great product and then expand on that basis. Most famous example: First iPhones didn’t have MMS

Sharing what's currently on screen (be it either a picture, a webpage or mean entire app) by touching two phones (Android Beam) was really convenient and ahead of its time. It is now being replaced by Nearby Share though, which works similar to AirDrop.
Post reply on HN