Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

51–60 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#51
post #46
post #39

Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…

Unless the implication is that the author of this point is misrepresenting things, I'm struggling to think of what "very good reason" there could be when there's a clear record of someone reporting a bug well before it's fixed. At best, it seems like typical slow bureaucracy, which I don't think is a particularly good reason. There's no reason it should take over a year for someone to approve something like this if t…

Vulnerability researchers misapprehend the dynamics of bug bounty programs all. the. time. and are virtually never doing that in bad faith. I don't need to determine which of these two entities are above board; I presume they both are.

If you think that any major vendor bug bounty has incentives to stiff researchers, I'm commenting to tell you that's a strong sign you should dig deeper into the dynamics of bounty programs. They do not have those incentives.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#53

Should have sold it to the Israelis NSO Group would have paid more, quicker

It's unclear that NSO group is interested in gaining access to iCloud accounts or Photos, nor is it clear that this entrypoint is something that would meet the bar or be useful for signals intelligence, since it requires sending a calendar invite and clicking on the attachment.

Bug bounties will pay for any bug. Offensive firms only pay for things that are practical, and they don't pay everything up front---it depends on the lifetime of the exploit. The business model is closer to a subscription or services.

There is no reason to believe NSO group would pay more, and they certainly wouldn't pay quicker.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#54

Earlier quoted context omitted.

I'd want to whitelist specific people before they could send me a calendar invite. Every other invite request should never reach my device. If I don't even know you, why would I want your invites anyway?

Because you work with people outside of your company, support, vendors, sales people etc. Boss: Why aren't you in the meeting with our vendor to upgrade our X system? You: Oh I whitelist all my invites. You see, I am thinking about security and don't want to receive invites from someone I don't know. Boss: Clear your desk, security will walk you out.

> Because you work with people outside of your company, support, vendors, sales people etc.

If I work with them, I would have them whitelisted. If I've never even heard of them they have no business sending my devices calendar invites.

Boss: Why aren't you working on that project I gave you?

You: Some stranger in Indonesia invited me to a sales meeting instead.

Boss: If I need you to go to a sales meeting with someone from Indonesia I'll tell you to! Clear your desk!

Re: Zero-Click Calendar invite vulnerability chain in macOS

#55
post #47

Thankfully I don't use iCloud Photo Library, but it's both weird to learn that when the photo library location has been changed, the new location does not get any protection. I would have expected the exploit to fail after setting /var/tmp/mypictures/Syndication.photoslibrary as the system photo library and opening Photos because the Photos app should know to protect this directory. I just did a quick test on my Sono…

I kind of get it. /tmp has historically been a world-readable/world-writable location in the directory hierarchy. If you want to save something private, it's not a great choice.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#56
post #51
post #46

Earlier quoted context omitted.

Unless the implication is that the author of this point is misrepresenting things, I'm struggling to think of what "very good reason" there could be when there's a clear record of someone reporting a bug well before it's fixed. At best, it seems like typical slow bureaucracy, which I don't think is a particularly good reason. There's no reason it should take over a year for someone to approve something like this if t…

Vulnerability researchers misapprehend the dynamics of bug bounty programs all. the. time. and are virtually never doing that in bad faith. I don't need to determine which of these two entities are above board; I presume they both are. If you think that any major vendor bug bounty has incentives to stiff researchers, I'm commenting to tell you that's a strong sign you should dig deeper into the dynamics of bounty pro…

Other than bad press there's no immediate incentive for the company to avoid stiffing researchers. Bug bounty programs work if the company is vulnerable to bad press and it would actually impact their bottom line.

This is not from an examination of when bug programs work but when they have very demonstrably not worked in the past.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#57
post #21
post #19

Earlier quoted context omitted.

Not to be smart -- but how else would invites work?

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

Not unrealistic as a consultant. My boss sells me to a project. Then clients might be asked to send me the meeting invite to kick things of. I might not have directly communicated with client at any point at this time.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#58

Earlier quoted context omitted.

Because you work with people outside of your company, support, vendors, sales people etc. Boss: Why aren't you in the meeting with our vendor to upgrade our X system? You: Oh I whitelist all my invites. You see, I am thinking about security and don't want to receive invites from someone I don't know. Boss: Clear your desk, security will walk you out.

> Because you work with people outside of your company, support, vendors, sales people etc. If I work with them, I would have them whitelisted. If I've never even heard of them they have no business sending my devices calendar invites. Boss: Why aren't you working on that project I gave you? You: Some stranger in Indonesia invited me to a sales meeting instead. Boss: If I need you to go to a sales meeting with someon…

Idk, other members of the third party company get pulled in all the time and might schedule something. I can't imagine using a calendar whitelist or why you'd even want to.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#59
post #51

Earlier quoted context omitted.

Vulnerability researchers misapprehend the dynamics of bug bounty programs all. the. time. and are virtually never doing that in bad faith. I don't need to determine which of these two entities are above board; I presume they both are. If you think that any major vendor bug bounty has incentives to stiff researchers, I'm commenting to tell you that's a strong sign you should dig deeper into the dynamics of bounty pro…

Other than bad press there's no immediate incentive for the company to avoid stiffing researchers. Bug bounty programs work if the company is vulnerable to bad press and it would actually impact their bottom line. This is not from an examination of when bug programs work but when they have very demonstrably not worked in the past.

Press is a perfect example of incentive alignment in these programs, since not paying a bounty a researcher believes is deserved is practically a guarantee of an uncharitable blog post.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#60
post #53

Should have sold it to the Israelis NSO Group would have paid more, quicker

It's unclear that NSO group is interested in gaining access to iCloud accounts or Photos, nor is it clear that this entrypoint is something that would meet the bar or be useful for signals intelligence, since it requires sending a calendar invite and clicking on the attachment. Bug bounties will pay for any bug. Offensive firms only pay for things that are practical, and they don't pay everything up front---it depend…

> since it requires sending a calendar invite and clicking on the attachment.

I thought it was a zero click exploit?

As for being interested in iCloud and photos, is the argument that the people they’re looking to attack are unlikely to use iCloud? Cause otherwise getting photos and potentially email access seems quite valuable.

Post reply on HN