Live data from Hacker News

Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

bleepingcomputer.com

41–50 of 254 posts

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#41
post #10

This is just one more nail in the already air-tight coffin Apple has built for themselves. I seriously don't understand why people stick with Apple products, they are getting much harder to use, they lock you in to their gimped ecosystem, and their hardware is constantly failing to be reliable.

I'm so happy Linux is an option on the computer. When it comes to phones I feel stuck behind a rock and a hard place - choose iPhone, with poor Linux integration and threats to passively scan files on my phone and forward them to LEO? Sure, they have a decent record with security but these bug bounty reports haven't been great. Or choose Android, with its poor privacy record, a result of being built by an ad company…

> I don't see how it's possible without the support of the large tech players - Facebook, Instagram, Snapchat, WhatsApp, Twitter, and Spotify at minimum, to say nothing of the long tail.

This wouldn't be much of a problem if it wasn't for Google's SafetyNet that prevents Android apps from running on hardware and software platforms that Google doesn't approve of. You wouldn't need support from large companies if you were able to run the apps they already release for Android.

Compatibility layers like Anbox or Waydroid that allow you to run Android apps on Linux can't run SafetyNet-enabled apps, despite having no problem running other Android apps.

SafetyNet prevents compatibility layers like WSL 1 & 2, Proton or WINE with Android support from coming to Windows or other platforms, as well.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#42
post #15
post #7

Here's a fun conspiracy theory proposed entirely in jest: Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices. So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ulti…

Next level conspiracy theory: Apple employs, knowingly or unknowingly, CIA/NSA agents who intentionally introduce these bugs.

It would indeed be a next-level conspiracy theory to suggest the NSA planted an employee at Apple to introduce a GameCenter bug that lets you read a cache of contacts, rather than, you know, just taking the whole device over, which is what "zero day" usually implies.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#43
post #35
post #10

Earlier quoted context omitted.

I'm so happy Linux is an option on the computer. When it comes to phones I feel stuck behind a rock and a hard place - choose iPhone, with poor Linux integration and threats to passively scan files on my phone and forward them to LEO? Sure, they have a decent record with security but these bug bounty reports haven't been great. Or choose Android, with its poor privacy record, a result of being built by an ad company…

I get that a lot of the Android-based projects don't pan out, but LineageOS has been going for quite a while now, CalyxOS is relatively new, and GrapheneOS (previously CopperheadOS) have successfully established themselves as the defacto hardened Android platform. You can download the source, modify it, and build them all freely. Hopefully more people can get involved and move the needle instead of only lamenting how…

> Hopefully more people can get involved and move the needle instead of only lamenting how they don't succeed while not actively trying to help them succeed.

That's totally fair. I don't really have the time or Java/Kotlin/mobile familiarity to jump in here, and these aren't skills I can easily apply elsewhere in my career, personally.

> LineageOS has been going for quite a while now, CalyxOS is relatively new, and GrapheneOS (previously CopperheadOS)

My impression of these OSes is that they still rely on Google Play Services - or if not, micro-G which has many shortcomings. When most of the ecosystem doesn't work until you invite Google back in, it doesn't seem like a true alternative IMO.

Admittedly I haven't personally tried running any of them. Which one would you recommend trying if I were aiming to rid myself of Google's omnipresence?

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#44

Earlier quoted context omitted.

Trillion dollar companies don't care about merit for doing the right thing. Why should this guy in the future?

Maybe he doesn't want dissident journalists and activists to get spied on and chopped to pieces? That sounds like a good enough reason to report these bugs for someone with morals.

Dissident journalists and activists can use devices from vendors that care about security enough to run a working bug bounty program.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#45

Seems that no credit, no bount, nothing, has become the way that Apple deals with the iBugs Hunters. And all it takes is one of those unsong heros giving up on reporting to Apple and, instead, reporting to some 0-day company, and some ransonware go brrrr

This comment is just nonsense. They regularly credit security researchers:

https://support.apple.com/en-au/HT201222

Seems like this in case it's just a mistake that was made.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#46
post #7

Here's a fun conspiracy theory proposed entirely in jest: Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices. So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ulti…

If Apple was complicit in US authorities breaking into their devices they wouldn't be doing so via publicly exploitable vulnerabilities. Bugs making their way into the "wrong" hands decreases trust in their ecosystem. It makes much more sense to just add a backdoor.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#47
post #10

Earlier quoted context omitted.

I'm so happy Linux is an option on the computer. When it comes to phones I feel stuck behind a rock and a hard place - choose iPhone, with poor Linux integration and threats to passively scan files on my phone and forward them to LEO? Sure, they have a decent record with security but these bug bounty reports haven't been great. Or choose Android, with its poor privacy record, a result of being built by an ad company…

Likewise. I'm in the market for a new phone. I want to get something top of the line and then keep it for at least 5 years, so good updates etc. But I have serious issues with both Google and Apple at this point. For me it isn't really the tech companies that need to buy in to make an alternative phone OS viable, but things like banks. Online mobile banking is one of the main things I use my phone for after web brows…

Great point. I recall some banking apps placing restrictions on logging in without SafetyNet, e.g. which also puts some of the other Android-based OS's out of the running.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#48

What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.

Can't we hope they go for full-disclosure instead of selling to the highest bidder? Selling to the highest bidder just hurts apple users not apple.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#49
Why are people out to crucify Apple for a story that's still being resolved? The article clearly says:

"...Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day..."

"...We saw your blog post regarding this issue and your other reports. We apologize for the delay in responding to you," Apple told Tokarev 24 hours after publishing the zero-days and the exploit code on his blog...

"...We want to let you know that we are still investigating these issues and how we can address them to protect customers. Thank you again for taking the time to report these issues to us, we appreciate your assistance..."

The company hasn't denied the bounty, they're just incompetent / slow on this process.

Feels like everyone is out to paint company with just confirmatory bias using whatever half-baked story is available. Even I feel for company leaders in this kind of shitty journalism environment. And the rest of the comments here are just autopilot piling on the echo fest.

Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

#50
post #24

Earlier quoted context omitted.

>And thereby accomplishing what, exactly? ...$$$$?

I could accomplish the same thing by robbing a bank - doesn’t make it the right thing to do.

Unless it's a mafia's bank.
Post reply on HN