Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

41–50 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#41
post #4

Earlier quoted context omitted.

> 2021–03–30: Bug Bounty is still being evaluated

If Apple are actually serious, why are they taking so long to give the bounty? It's sounds like madness to me.

This is clearly what triggered the post.

Work was done but not paid. Shitty business on Apple side...

Re: Zero click vulnerability in Apple’s macOS Mail

#42
post #4

> 2020–05–16: Issue found > 2020–05–24: PoC done and reported to Apple > 2020–06–04: Catalina 10.15.6 Beta 4 with [hotfix released] > 2020–07–15: Catalina 10.15.6 Update with hotfix released

> 2021–03–30: Bug Bounty is still being evaluated

The company has billions of dollars. I don't think a $50k-$100k bug bounty payout for them is a big deal. Even $1m wouldn't be a big deal to them.

Re: Zero click vulnerability in Apple’s macOS Mail

#45
post #24
post #3

That's gonna be devastating to the three people who use Mail.app

A new Mac comes with something like 30 apps in the bar. I clicked and disabled every single one of them except Finder and used Safari to download another browser. If it was any other manufacturer, this mess would be quickly denounced by reviewers as crapware. But because it is by Apple, it is not a problem at all. I am not expecting this to fix by itself. Maybe some major review blogs should first not parrot how magi…

I assume you mean the Dock? I am with you there, on a new install of macOS I drag pretty much all their apps out of it (to be fair, I do the same thing on a new Ubuntu desktop install too...). Of course in a sense the Dock is an anachronism, I find it useful once in the while to drag a file onto an app there, but generally for launching apps I prefer Spotlight (actually Alfred).

Re: Zero click vulnerability in Apple’s macOS Mail

#46
post #40
post #38

Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?

Apple's entire business model is based on appearances. To be fair so is Microsoft's and many others. Security is usually the last priority for nearly every for profit entity because it doesn't drive revenue.

Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well.

They aren’t perfect but I don’t think it’s fair to say they don’t try.

Re: Zero click vulnerability in Apple’s macOS Mail

#47
post #16
post #6

Earlier quoted context omitted.

That's not what the statistics say: https://emailclientmarketshare.com

Wow, Mail.app has more market share than Outlook. I'm pleasantly surprised. Ditto for GMail only having ~30%. Although, > Since determining the client in which an email is opened requires images to be displayed, the data for some email clients and mobile devices might be over- or under-represented due to automatic image blocking. Outlook doesn't display external images by default, while Mail.app does, so....

As far as I know and recall from the years I've been using Mail.app, it does not download external images by default.

Re: Zero click vulnerability in Apple’s macOS Mail

#48
post #3

That's gonna be devastating to the three people who use Mail.app

;_; one of us. one of us. Whats a good alternative for macos these days? I loved sparrow back in the day, before I got acquired and killed by google.

I personally love Mimestream. Its a native Gmail client

Re: Zero click vulnerability in Apple’s macOS Mail

#49
post #30
post #10

Earlier quoted context omitted.

I am one of those three people. Do you know of any decent gui IMAP clients?

I like Mailmate

If I switch, it will need to be to something that works on more than just macOS, and nonfree software will be excluded from consideration.

Re: Zero click vulnerability in Apple’s macOS Mail

#50
post #40
post #38

Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?

Apple's entire business model is based on appearances. To be fair so is Microsoft's and many others. Security is usually the last priority for nearly every for profit entity because it doesn't drive revenue.

Security drives profit if it is marketed well. Apple does this. Think about even their branding for certain things, e.g. “Secure Enclave”.
Post reply on HN