It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.
I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.
Zero click vulnerability in Apple’s macOS Mail
241–250 of 269 posts
Re: Zero click vulnerability in Apple’s macOS Mail
#242It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.
I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.
People tend to vastly overestimate the economic impact of an exploited security vulnerability. A vulnerability which can be patched in a centralized manner has a low value half-life: it rapidly decreases in value over time. I would guess over 90% of active daily users of macOS already have the patch for this bug due to automatic updates. New buyers are essentially guaranteed not to have the vulnerability at all. The vulnerability would have to be absolutely catastrophic to be worth something, and in that case it would probably be used for targeted exploitation and burned after a short period of time.
Contrast with something like heartbleed, which is still around. That is a vulnerability with serious half-life and significant economic impact. The pool of available victims who can be exploited by heartbleed is nontrivial and persistent years later. Criminals will actually pay for something like that.
Re: Zero click vulnerability in Apple’s macOS Mail
#243Earlier quoted context omitted.
A company sufficiently large enough for such an amount to not be a big deal will have a money disbursal process nobody understands enough to make a one time transaction of that size in a reasonable amount of time.
Maybe a company so large it can’t track its own finances is too large to be responsible for its obligations and should be held to standards at least as strict as its less capable business and human peers. And I’m an Apple fan to be clear. But their wealth is the opposite of an excuse.
Re: Zero click vulnerability in Apple’s macOS Mail
#244Earlier quoted context omitted.
This is the same exact issue that used to plague Outlook back in the day with the automatic handling of attachments. You'd think Apple would have learned from others' mistakes.
They still treat PDF files as “safe” to automatically open when downloaded so nope.
Re: Zero click vulnerability in Apple’s macOS Mail
#245Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?
If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0] I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way. [0]: https://qz.com/1844937/hong-…
Edit: your linked article says nothing about icloud
Re: Zero click vulnerability in Apple’s macOS Mail
#246Earlier quoted context omitted.
Can you be a bit more clear on what you're implying? Genuinely curious. I thought Zerodium was selling to government agencies.. so I'm not sure what you mean by sliced up bodies in embassies. Perhaps I'm just not thinking creatively/pessimistically enough.
The sliced up bodies seems like a reference to Jamil Khashoggi. [1] I am not sure why GP links Khashoggi’s death to Zerodium. 1- https://en.m.wikipedia.org/wiki/Jamal_Khashoggi
https://edition.cnn.com/2019/01/12/middleeast/khashoggi-phon...
Re: Zero click vulnerability in Apple’s macOS Mail
#247Earlier quoted context omitted.
The sliced up bodies seems like a reference to Jamil Khashoggi. [1] I am not sure why GP links Khashoggi’s death to Zerodium. 1- https://en.m.wikipedia.org/wiki/Jamal_Khashoggi
Very confusing; A Saudi national was assassinated in the Saudi embassy by agents of the Saudi government. Linking this to Zerodium makes Zero sense. You don't need to do any digging to find out when someone is at your doorstep
https://edition.cnn.com/2019/01/12/middleeast/khashoggi-phon...
Re: Zero click vulnerability in Apple’s macOS Mail
#248Re: Zero click vulnerability in Apple’s macOS Mail
#249Earlier quoted context omitted.
I dont think apple is entitled to that information on any basis, and i dont think its a legitimate threat to expose actual ill behaviour
All blackmail involves exposing something that someone doesn't want exposed - usually because the "something" is illegal. And yet, blackmail itself is illegal. Most countries have a culture against whistleblowers, starting from childhood ("don't be a tattletale", "don't be a rat").
Re: Zero click vulnerability in Apple’s macOS Mail
#250Earlier quoted context omitted.
Maybe a company so large it can’t track its own finances is too large to be responsible for its obligations and should be held to standards at least as strict as its less capable business and human peers. And I’m an Apple fan to be clear. But their wealth is the opposite of an excuse.
It isn’t that finances aren’t tracked. They are tracked and audited and the audits are audited and there are many safeguards in place so that money doesn’t leak out and the knowledge for that operation is specialized, so much so that entire departments handle only part of the process and can’t just talk to one another due to the “segregation of duties” the auditors want. A company that decided to incentivize bug boun…