Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

231–240 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#231

Earlier quoted context omitted.

That may be considered black-mail by some courts.

I dont think apple is entitled to that information on any basis, and i dont think its a legitimate threat to expose actual ill behaviour

All blackmail involves exposing something that someone doesn't want exposed - usually because the "something" is illegal. And yet, blackmail itself is illegal.

Most countries have a culture against whistleblowers, starting from childhood ("don't be a tattletale", "don't be a rat").

Re: Zero click vulnerability in Apple’s macOS Mail

#232

Earlier quoted context omitted.

Can you be a bit more clear on what you're implying? Genuinely curious. I thought Zerodium was selling to government agencies.. so I'm not sure what you mean by sliced up bodies in embassies. Perhaps I'm just not thinking creatively/pessimistically enough.

The sliced up bodies seems like a reference to Jamil Khashoggi. [1] I am not sure why GP links Khashoggi’s death to Zerodium. 1- https://en.m.wikipedia.org/wiki/Jamal_Khashoggi

The Saudi's secret service is infamous for hacking dissidents' phones.

Re: Zero click vulnerability in Apple’s macOS Mail

#233
post #19

It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.

Did he phone them to check? I get a lot of fake invoices in my junk mail. I also know someone who lost £50k paying an invoice with bank details that had been tampered with by hackers. I hate phoning people but I always phone about invoices.

Re: Zero click vulnerability in Apple’s macOS Mail

#234
post #196

I can't find any information on the following questions: Are all past versions of OS X / Apple Mail affected? For what OS X Version does Apple provide a security update regarding this issue? Has anyone found a fix that prevents auto-uncompression (such as a "defaults write com.apple.mail xyz False" command)? Due to several reasons, I am also on an older Version of OS X and this issue makes me a bit nervous.

From Apple's patch notes [0]:

> Available for: macOS Mojave 10.14.6, macOS High Sierra 10.13.6, macOS Catalina 10.15.5

[0]: https://support.apple.com/en-us/HT211289

Re: Zero click vulnerability in Apple’s macOS Mail

#235
post #88

Earlier quoted context omitted.

This is the same exact issue that used to plague Outlook back in the day with the automatic handling of attachments. You'd think Apple would have learned from others' mistakes.

I don't exactly have a dog in this, but I think this is a strange framing: this feels like exactly the kind of niche feature that was added by one engineer and then forgotten about. MS and Apple are both large companies that maintain individual pieces of software that are probably older than many of the engineers who currently work on them; the lessons here are more organizational than technical.

It's because Apple framed themselves as the company of "LOL Macs don't get viruses" and emphasize themselves to be more privacy focused than Android...

...and they made the same basic mistake of allowing one of the single most exploitable attack vectors ever. They kinda shoulda known better, honestly.

Re: Zero click vulnerability in Apple’s macOS Mail

#236
post #196

I can't find any information on the following questions: Are all past versions of OS X / Apple Mail affected? For what OS X Version does Apple provide a security update regarding this issue? Has anyone found a fix that prevents auto-uncompression (such as a "defaults write com.apple.mail xyz False" command)? Due to several reasons, I am also on an older Version of OS X and this issue makes me a bit nervous.

[deleted]

Re: Zero click vulnerability in Apple’s macOS Mail

#237
post #161

So, is this an issue on my old mac running 10.11.6 that will not get fixed?

I'm on 10.9 and I don't want to use anything newer. I can deal with some risk, but this vulnerability is unacceptably bad. The core problem is that really dumb feature which auto-expands certain zip files. I need to turn that off. MailWebAttachment.h contains a method: - (BOOL)isAutoArchiveAttachment; I bet that if I Swizzle that to always return false, this "feature" will go away. I'll found out this weekend... Edit…

^ Yeah, that didn't work, the method never gets called. I'll have dig more...

Re: Zero click vulnerability in Apple’s macOS Mail

#238

Earlier quoted context omitted.

That may be considered black-mail by some courts.

Can you explain it more? What can make it a black-mail and why? If there is no intent to abuse the bug when not paied then there is no additional threat there from simply notifying the company that some threat is already present. How it can become a black-mail? So every report about discovered bug can be considered as black-mail? If one discovers a bug, reports it to the company and says that after 3 months it will b…

Yes, it's the payment request.

Re: Zero click vulnerability in Apple’s macOS Mail

#239
post #156

Earlier quoted context omitted.

A company sufficiently large enough for such an amount to not be a big deal will have a money disbursal process nobody understands enough to make a one time transaction of that size in a reasonable amount of time.

Maybe a company so large it can’t track its own finances is too large to be responsible for its obligations and should be held to standards at least as strict as its less capable business and human peers. And I’m an Apple fan to be clear. But their wealth is the opposite of an excuse.

That's not an excuse. It's just a blunt explanation. Out of the ordinary processes can only proceed so quickly in the presence of massive bureaucracy.

Re: Zero click vulnerability in Apple’s macOS Mail

#240
post #177

Earlier quoted context omitted.

The value of a bug isn't proportional to how much money the company has.

Why not? The potential damage certainly is proportional.

You state this confidently but I don't see why it's true a priori. I don't see a strong correlation between Apple's cash on hand, assets or market cap and the severity of a zero day in Mail.app.

The better comparison is active users, weighted according to how many apply automatic updates. The vulnerability half-life probably isn't as devastating as you might think it is since Apple has centralized control to push out updates, limited only by users deliberately not installing them.

I would consider a vulnerability in OpenSSH to be far more economically devastating, and there isn't even a company with a market cap behind that software.

Post reply on HN