Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

261–269 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#261

For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try t…

I think the real alternative here is that fewer folks will spend time looking at Apple products or not fully investigating weird behavior encountered normally that could be a security issue.

The author specifically said that they were looking based on bug bounty guidelines. The next person in the same shoes will look at some other company's products instead.

Re: Zero click vulnerability in Apple’s macOS Mail

#262
post #253

Earlier quoted context omitted.

It's only blackmail if the threat is to do something you are not otherwise legally allowed to do. It is legal to, say, announce a zero-day on Twitter. Or to sell the zero-day to the NSA, or some grey hat broker like Zerodium.

No it's not. Pay me $10,000 or I tell everyone you slept with your secretary is blackmail.

Ok, you got me. But there must be more to the definition of blackmail than simply, pay me or else. If that were the definition, then everyone would be a blackmailer by virtue of "pay me for this or else I'll sell it to someone else," which is a "threat" we all implicitly make every day.

Re: Zero click vulnerability in Apple’s macOS Mail

#263

Earlier quoted context omitted.

They still treat PDF files as “safe” to automatically open when downloaded so nope.

What’s dangerous in a PDF besides JS which is not executed in macos Preview.app?

PDF has had a zillion vulnerabilities over the years. And Apple doesn’t guarantee in Safari that Preview.app is the default handler, so that expands the scope of potential vulnerabilities to Acrobat, which is notorious for its history of vulnerabilities.

Re: Zero click vulnerability in Apple’s macOS Mail

#264

Earlier quoted context omitted.

Why not? The potential damage certainly is proportional.

You state this confidently but I don't see why it's true a priori. I don't see a strong correlation between Apple's cash on hand, assets or market cap and the severity of a zero day in Mail.app. The better comparison is active users, weighted according to how many apply automatic updates. The vulnerability half-life probably isn't as devastating as you might think it is since Apple has centralized control to push out…

Then I'm sure you can easily see why Apple having money matters. openssh users may be damaged and yet there isn't an apparatus in place to reward those who can provide value. What a shame, but who is confused?

Who is wondering why Patreon and a blog post isn't sufficient to facilitate value transfer in metaphorical openssh scenarios?

Re: Zero click vulnerability in Apple’s macOS Mail

#265
post #221

Earlier quoted context omitted.

Bug bounty factoring! From wikipedia: > Factoring is a financial transaction and a type of debtor finance in which a business sells its accounts receivable (i.e., invoices) to a third party (called a factor) at a discount.[1][2][3] A business will sometimes factor its receivable assets to meet its present and immediate cash needs.[4][5] Forfaiting is a factoring arrangement used in international trade finance by expo…

This sounds like discounting a Bill of Exchange. Although the Bill of Exchange is drawn only against the delivery of a physical good, so this may be the difference between the two. For example, let's say I own a sheep farm. I hire people to trim the sheep, and they produce a bunch of cotton. Without the Bill of Exchange, if I want to pay the people I've hired then I will need to ship this cotton to the spinner, who t…

Small nit: you get wool from sheep, not cotton :). Otherwise, that’s really interesting and I didn’t know that was a thing!

Re: Zero click vulnerability in Apple’s macOS Mail

#266
post #243

Earlier quoted context omitted.

Maybe a company so large it can’t track its own finances is too large to be responsible for its obligations and should be held to standards at least as strict as its less capable business and human peers. And I’m an Apple fan to be clear. But their wealth is the opposite of an excuse.

It isn’t that finances aren’t tracked. They are tracked and audited and the audits are audited and there are many safeguards in place so that money doesn’t leak out and the knowledge for that operation is specialized, so much so that entire departments handle only part of the process and can’t just talk to one another due to the “segregation of duties” the auditors want. A company that decided to incentivize bug boun…

That's still an organization that's too large or mismanaged to be trusted. We trust people who are capricious with their personal finances far less. A large organization with wealth impossible to humans but systems failing them and everyone else who depends on it... is a large corporation with wealth that has no excuse for not solving it.

Re: Zero click vulnerability in Apple’s macOS Mail

#267
post #241

Earlier quoted context omitted.

Bug bounty doesn't mean that the reporter is selling the bug they find for a reward. It's a gesture of gratitude from the company. This whole conversation is coming from a place of entitlement.

Here's an alternative view: - Apple is a $2T company, that we trust with our data. That valuation is in part based on that trust. It's entitled of Apple to produce a product that contains shitty exploitable symlink handling and continue to have no meaningful repercussions (which is true in the industry as a whole). If this was a bug in a small, under-resourced FOSS email client, or the exploit required many highly sk…

Both of these points can be true.

Re: Zero click vulnerability in Apple’s macOS Mail

#268

Earlier quoted context omitted.

What web-based client will allow you to read email without an Internet connection in Safari? What marginal advantage does a third-party iOS client provide, that outweighs the risks of installing another app that is going to spy on me, have weaker integration with the OS and force me to relearn every new UI design language they come up with that in no way resembles the rest of the OS or its function and behavior?

>What web-based client will allow you to read email without an Internet connection in Safari? I understand why it might be a deal breaker for you, but browsing email offline is not a use case everyone has.

> not a use case everyone has

That’s not what the original question was. It was:

> what’s right with [Mail for iOS]

So me implying that reading mail offline is one thing that’s right with it is not invalidated by the fact that it’s not a universally demanded feature (and yes, it has helped me many times, even recently).

Do you really need to remove that feature to build a “better” email client? What exactly is the tradeoff you see?

Re: Zero click vulnerability in Apple’s macOS Mail

#269
post #72

Use MailMate! https://freron.com/

How has maintenance & bug fixing been? I'm OK with mature apps stabilizing and needing few updates, though since it is a single dev with somewhat infrequent changes I thought I'd ask ( https://updates.mailmate-app.com/release_notes ).

I’ve not noticed any issues. The author is very active on the mailing list.
Post reply on HN