Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

241–250 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#241
post #19

It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

Bug bounty doesn't mean that the reporter is selling the bug they find for a reward. It's a gesture of gratitude from the company. This whole conversation is coming from a place of entitlement.

Re: Zero click vulnerability in Apple’s macOS Mail

#242
post #19

It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.

I like this idea. 1. Company verifies the bug 2. Assigns it a price according to impact 3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access. Different bug markets can compete to correctly price bugs.

In all likelihood, Apple would just refuse to play ball and tell them to go ahead and sell it to someone else if they're so confident. Zerodium and other markets already exist, and I don't think people at Apple lose much sleep over it. And you better hope you close that deal before Google Project Zero finds it independently and tells Apple for free. Plus the mere mention that a vulnerability exists in a specific piece of software may lead Apple engineers to finding and patching it before you can sell it. Give away too many details and it's burned.

People tend to vastly overestimate the economic impact of an exploited security vulnerability. A vulnerability which can be patched in a centralized manner has a low value half-life: it rapidly decreases in value over time. I would guess over 90% of active daily users of macOS already have the patch for this bug due to automatic updates. New buyers are essentially guaranteed not to have the vulnerability at all. The vulnerability would have to be absolutely catastrophic to be worth something, and in that case it would probably be used for targeted exploitation and burned after a short period of time.

Contrast with something like heartbleed, which is still around. That is a vulnerability with serious half-life and significant economic impact. The pool of available victims who can be exploited by heartbleed is nontrivial and persistent years later. Criminals will actually pay for something like that.

Re: Zero click vulnerability in Apple’s macOS Mail

#243
post #156

Earlier quoted context omitted.

A company sufficiently large enough for such an amount to not be a big deal will have a money disbursal process nobody understands enough to make a one time transaction of that size in a reasonable amount of time.

Maybe a company so large it can’t track its own finances is too large to be responsible for its obligations and should be held to standards at least as strict as its less capable business and human peers. And I’m an Apple fan to be clear. But their wealth is the opposite of an excuse.

It isn’t that finances aren’t tracked. They are tracked and audited and the audits are audited and there are many safeguards in place so that money doesn’t leak out and the knowledge for that operation is specialized, so much so that entire departments handle only part of the process and can’t just talk to one another due to the “segregation of duties” the auditors want. A company that decided to incentivize bug bounty like Google got support for the program on high and all the wheels of the org went to work to create policy, procedure, forms, auditor review, SARBOX compliance, etc and payouts will move like any other invoice. A company where some mid rank sees a need for such a program but doesn’t get full organizational alignment will be stuck with a pre-broken unreliable process.

Re: Zero click vulnerability in Apple’s macOS Mail

#244
post #88

Earlier quoted context omitted.

This is the same exact issue that used to plague Outlook back in the day with the automatic handling of attachments. You'd think Apple would have learned from others' mistakes.

They still treat PDF files as “safe” to automatically open when downloaded so nope.

What’s dangerous in a PDF besides JS which is not executed in macos Preview.app?

Re: Zero click vulnerability in Apple’s macOS Mail

#245
post #76
post #38

Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?

If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0] I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way. [0]: https://qz.com/1844937/hong-…

This is true of your primary worry is nation states. If your primary worry is criminals/domestic partners/employers, this isn't the case. You can't give security advice without considering what you're protecting against.

Edit: your linked article says nothing about icloud

Re: Zero click vulnerability in Apple’s macOS Mail

#246

Earlier quoted context omitted.

Can you be a bit more clear on what you're implying? Genuinely curious. I thought Zerodium was selling to government agencies.. so I'm not sure what you mean by sliced up bodies in embassies. Perhaps I'm just not thinking creatively/pessimistically enough.

The sliced up bodies seems like a reference to Jamil Khashoggi. [1] I am not sure why GP links Khashoggi’s death to Zerodium. 1- https://en.m.wikipedia.org/wiki/Jamal_Khashoggi

Not Zerodium, but there's some evidence a different hacking for hire group helped them track him

https://edition.cnn.com/2019/01/12/middleeast/khashoggi-phon...

Re: Zero click vulnerability in Apple’s macOS Mail

#247

Earlier quoted context omitted.

The sliced up bodies seems like a reference to Jamil Khashoggi. [1] I am not sure why GP links Khashoggi’s death to Zerodium. 1- https://en.m.wikipedia.org/wiki/Jamal_Khashoggi

Very confusing; A Saudi national was assassinated in the Saudi embassy by agents of the Saudi government. Linking this to Zerodium makes Zero sense. You don't need to do any digging to find out when someone is at your doorstep

Wrong. They used tools by the Israeli NSO group to track him.

https://edition.cnn.com/2019/01/12/middleeast/khashoggi-phon...

Re: Zero click vulnerability in Apple’s macOS Mail

#249

Earlier quoted context omitted.

I dont think apple is entitled to that information on any basis, and i dont think its a legitimate threat to expose actual ill behaviour

All blackmail involves exposing something that someone doesn't want exposed - usually because the "something" is illegal. And yet, blackmail itself is illegal. Most countries have a culture against whistleblowers, starting from childhood ("don't be a tattletale", "don't be a rat").

And that anti-whistleblower culture enables fraud like theranos to be undiscovered for years

Re: Zero click vulnerability in Apple’s macOS Mail

#250
post #243

Earlier quoted context omitted.

Maybe a company so large it can’t track its own finances is too large to be responsible for its obligations and should be held to standards at least as strict as its less capable business and human peers. And I’m an Apple fan to be clear. But their wealth is the opposite of an excuse.

It isn’t that finances aren’t tracked. They are tracked and audited and the audits are audited and there are many safeguards in place so that money doesn’t leak out and the knowledge for that operation is specialized, so much so that entire departments handle only part of the process and can’t just talk to one another due to the “segregation of duties” the auditors want. A company that decided to incentivize bug boun…

[deleted]
Post reply on HN