Live data from Hacker News

Disclosure of three 0-day iOS vulnerabilities

habr.com

51–60 of 464 posts

Re: Disclosure of three 0-day iOS vulnerabilities

#51
post #28
post #11

Earlier quoted context omitted.

Full disclosure is always responsible, even if the vendor is not notified in advance.

This is a part of our industry I do not follow beyond headlines. A lot of those headlines are about hackers trying to be responsible getting screwed out of supposed bounties that to my mind already appear quite small. Also responsible companies doing very little to quickly close them. Does anyone have any insight into how the market for vulnerabilities operates? Is there is a significant disparity in price between of…

Private buyers almost certainly pay a higher amount and their payments arrive much sooner.

Apple's published rates are high (up to $1M), but in practice they pay a lot lower.

Re: Disclosure of three 0-day iOS vulnerabilities

#52
post #27

Why must iOS use WiFi to run critical security updates? I assume it’s a kickback from telecoms to reduce network bandwidth from users with unlimited mobile data plans?

This has changed on the newer phones (12, 13):

https://www.macrumors.com/2020/10/21/iphone-12-can-download-...

Re: Disclosure of three 0-day iOS vulnerabilities

#53
post #49
post #22

Earlier quoted context omitted.

Bug bounty programs are the antithesis of Apple's internal methodology, culture, and way of doing business. They keep everything close to the chest, they shun "outsiders", etc.. The idea that someone outside of Apple, from the unwashed masses, could find a flaw in Apple's own software is a pretty big pill for them to swallow. Thus it doesn't surprise me there are problems with their bug bounty program. I think if the…

that's just dumb, like third parties do all the work and contact you about critical bugs the only effort on Apple's part of verification and some coordination which shouldn't be a huge issue for a company the size of apple.. just hire a team to do it and be done with it the whole 'secrecy culture' is a bunch of hogwash

And yet here we are ;)

Re: Disclosure of three 0-day iOS vulnerabilities

#54

If your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data leaking vulnerabilities within 90 days, or pay out everyone who bought your product. I just updated to iOS 15 and it now tells you which sites you have been compromised on, or had your passwords/info compromised on. To be clear, I use a password manager with a…

God, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of…

> crap like GDPR (which makes basically all normal interaction cumbersome)

Only if you count "tracking users on first visit before they do anything else" as normal. Otherwise, there isn't a banner needed; sites could simply have a link to opt-in to tracking in the header or footer, and not track unless the user opts in.

This is like passing a law making it illegal to just hit people in the street, requiring you have to ask them for consent first. So most of the people who want to hit others up come up with some gish gallop that most people fall for, and then hit them.

And people bitch about the law, and claim it "makes it necessary for people to chew off the ear of other people they pass by in the streets"... with a straight face, that's what they twist it into, with an air of indignation even... and not just for a few weeks, until they read up and the initial misunderstandings are cleared up, but year in and year out, because they never read up, and the falsehoods you just posted keep getting repeated.

Re: Disclosure of three 0-day iOS vulnerabilities

#55

It must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.

There is no $100K coming.

Apple hopes you'll stay silent by dangling a hypothetical $100K (or whatever large amount) in the vague future. Once they've fixed the bug, they no longer have an incentive to pay you so they won't.

Re: Disclosure of three 0-day iOS vulnerabilities

#56

It must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.

Given that (according to the author) they've already lied at least twice ("processing error, will be in next release")...

... what gives you such high hopes that he will ever get his 100K?

Re: Disclosure of three 0-day iOS vulnerabilities

#57
post #40
post #37

Earlier quoted context omitted.

Does iOS have any way of telling if you’re on an unlimited data plan? If not, maybe it’s just to prevent the footgun (and subsequent bad PR) of somebody accidentally updating the OS over an expensive metered connection. But it could also be a carrier demand, not really sure.

Settings > Cellular It shows my carrier, amount of data used and shows remaining on my plan. Mine reads, Usage: Used 7.43GB - Unlimited If I click on it it has 3 fields. Data, Calls, Messages Data reads the same here. Calls and Messages simply say ‘Unlimited’

My phone does not have this (iPhone on 15.0 in the US, AT&T).

Re: Disclosure of three 0-day iOS vulnerabilities

#58

It must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.

There is no $100K coming. Apple hopes you'll stay silent by dangling a hypothetical $100K (or whatever large amount) in the vague future. Once they've fixed the bug, they no longer have an incentive to pay you so they won't.

Haven't they done this in the past? "Oh thank you!" then "Actually we already knew about it and had a fix planned, so no bounty for you"?

Re: Disclosure of three 0-day iOS vulnerabilities

#59
post #35

Obscure ad-tech companies would love to get those installed apps like they were aggressively doing (Facebook & Twitter too) about 5 years ago.

Facebook and Twitter exploited 0-day security vulnerabilities to collect private data?

Can show the proof link please?

Re: Disclosure of three 0-day iOS vulnerabilities

#60
post #28
post #11

Earlier quoted context omitted.

Full disclosure is always responsible, even if the vendor is not notified in advance.

This is a part of our industry I do not follow beyond headlines. A lot of those headlines are about hackers trying to be responsible getting screwed out of supposed bounties that to my mind already appear quite small. Also responsible companies doing very little to quickly close them. Does anyone have any insight into how the market for vulnerabilities operates? Is there is a significant disparity in price between of…

So most public companies don't even run bug bounties. The ones that do may or may not acknowledge your disclosure, and they decide what your vulnerabilities are worth regardless of any scales they might post on a blog. So in a best case scenario, you get maybe 10-100k for a world ending RCE + escalation but most of the time you get no response or <1k. On the gray market, though, something like that will easily sell for over 100k, sometimes several million. Generally it's frowned upon in academic circles, but there are a handful of large brokers like zerodium who are happy to pay out for interesting bugs.
Post reply on HN