Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

211–220 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#211

Earlier quoted context omitted.

> would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere Having an e-mail from the company confirming the bug is serious and systemic massively raises its market value. Security is necessarily trust less. These game dynamics are unavoidable.

Having an email from the company confirming that they know about the bug probably erases its market value.

Unless it's harder to fix, and easy to short term exploit?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#212
post #75

>Apple silently fixes iOS zero-day, asks bug reporter to keep quiet Isn't that standard procedure for any company faced with a 0-day, prudent, and the right thing to do?

Why would asking the reporter to keep quiet be prudent, especially after the bug has been fixed?

Because not everyone has updated yet, not everything related to the vulnerability is fixed yet, the vulnerability is kind of bullshit, people are still figuring out if there are lots of adjacent or similar vulnerabilities to handle, etc. Not sure which of these is the case here.

You can, of course, disclose vulnerabilities whenever you like. But don't expect to get a bounty if you piss off the vendor in the process.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#213
post #207

Earlier quoted context omitted.

> We pay big bounties https://zerodium.com/ >One person who will share those sales numbers is a South African hacker who goes by the name “the Grugq” and lives in Bangkok. For just over a year the Grugq has been supplementing his salary as a security researcher by acting as a broker for high-end exploits, connecting his hacker friends with buyers among his government contacts. He says he takes a 15% commission on sal…

For those who figure this is a great way to monetize their security skills and actually have the chops to do it: It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it.

> It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it.

By this logic, americans should stop using cars at all, cause all that oil is coming from middle east, saudi arabia.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#214
post #213
post #207

Earlier quoted context omitted.

For those who figure this is a great way to monetize their security skills and actually have the chops to do it: It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it.

> It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it. By this logic, americans should stop using cars at all, cause all that oil is coming from middle east, saudi arabia.

What? This does not follow at all. You’re implying that any degree of involvement in activities that have negative consequences is equivalent. That’s incorrect!

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#215
post #18

Earlier quoted context omitted.

I'm sure people are selling them, although I think it would only become public by accident. At least some are going the back to the Full Disclosure days... https://twitter.com/jonathandata1/status/1448037463419674625

FYI: that person is at best very confused, and at worst willfully fraudulent.

Why is that?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#216
post #87

Earlier quoted context omitted.

"Android" doesn't but Google Play services & bundled apps do

Google Play Services and bundled apps don't have to be enabled and sends less data to Google than the equivalent services on iOS, which must be enabled.

Google Play Services does need to be enabled to use many (most?) mainstream apps.

Have a source for them sending less data? Even if it were true, the use of that data differs.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#217

Earlier quoted context omitted.

And iOS users should be grateful that they report those bugs to Apple to get paid. They could also sell it to some spying companies and may be those pay well and very fast

> and may be those pay well and very fast Pay very well? Often, assuming they actually pay, sometimes you can get stiffed there too. Very fast? Nope. Easy to work with? Nope. Communicate with you any better than Apple through the process? Not usually.

Have you dealt with terrorist orgs in the past, or is this all conjecture?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#218

Earlier quoted context omitted.

My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…

They can’t be that worried - the bug that allows you to input behind the lockscreen on OS X has now been a thing for… six years, over three or four versions of macOS? I’ve reported it, but they each time said it was a feature, not a bug. Damn strange feature that allows me to compromise any screen-locked mac.

How do you do that?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#219
post #206

Earlier quoted context omitted.

I have a feeling that HN recently had an influx of users from other sites. It seems like the exodus from Reddit, for example, has resulted in a significantly larger signal to noise ratio of comments. There's a lot more impassioned nonsense that's based on article headlines rather than detailed discussion of technology and either it's just more pronounced because of the pandemic or it's actually new users that are dil…

> "Apple wants to scan your phone" and "Apple is suing mom and pop repair shops" or other hot takes that completely misunderstand their situations But, IIUC, both of those are completely true.

They are not. They completely lack any nuance and are based on misunderstandings of both situations.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#220

Earlier quoted context omitted.

Why? What would be valuable about that? Specifically, what would be valuable about getting someone's GameCenter contacts? These aren't business or family contacts. These are people the person games with. It's a privacy violating bug but not a show-stopping bug. Important but not valuable.

You're misunderstanding the vulnerability. The bug is in gamed, the Game Center daemon, but it allows access to the entire CoreDuet database, which does on-device intelligence stuff. Duet essentially logs everything you do on your phone, which means that if you look at the database it'll contain logs for all your interactions, not just those with Game Center contacts.

You are correct. I did misunderstand that portion of it but that doesn't change the fact that Apple is willing to pay $100k for a bounty like that but no one else does and Apple's actions don't suggest at all that they won't pay out the bounty. If you've ever been part of a program like this, on the developer side, it's possible that they discovered a larger bug that this was a part of or that someone else had already reported this bug. Tracking down the origin of this and the tickets involved takes time and fixing the bug is always the priority. They haven't acknowledged that he's the originator of the report so his insistence that he be credited immediately is a big immature and premature.

There's nothing here that suggests Zerodium, or someone similar, would pay the same amount Apple is offering and there's nothing that suggests that Apple doesn't intend to pay this or credit him. That's all completely conjecture.

Post reply on HN