Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…
Zero-Click Calendar invite vulnerability chain in macOS
61–70 of 166 posts
Re: Zero-Click Calendar invite vulnerability chain in macOS
#62Earlier quoted context omitted.
> Because you work with people outside of your company, support, vendors, sales people etc. If I work with them, I would have them whitelisted. If I've never even heard of them they have no business sending my devices calendar invites. Boss: Why aren't you working on that project I gave you? You: Some stranger in Indonesia invited me to a sales meeting instead. Boss: If I need you to go to a sales meeting with someon…
Idk, other members of the third party company get pulled in all the time and might schedule something. I can't imagine using a calendar whitelist or why you'd even want to.
If someone is going to make some demand for my time, the very least they can do is give me notice outside of my icloud calendar. An email, an IM, a phone call, etc are all very easy and they allow me to make sure it's real before it has any chance to interfere with my schedule. "Hey Boss, this guy says he's our new IT guy and he wants to talk about my network settings" or "Hey $vendor, I just got a call from $rando saying he's our new contact, can you verify that for me before I tell him everything I know about your propriety applications?"
It helps that I like to keep my work devices and my personal devices entirely separate. If someone in the office wants to pull me into a work meeting through outlook, they'll already have to have an account set up on the company's exchange server. Anyone outside of the company I should already have a relationship with or at least a heads up.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#63Should have sold it to the Israelis NSO Group would have paid more, quicker
That mentality is cancerous to society.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#64Earlier quoted context omitted.
Not to be smart -- but how else would invites work?
How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?
Re: Zero-Click Calendar invite vulnerability chain in macOS
#65Earlier quoted context omitted.
This is a regular part of the recruiting process, where you may start chatting in LinkedIn and then get an invite on your email.
If the recruiter doesn't ask me first (or I don't agree to a meeting), this is called "spam", and I would be happy for the system to just not allow it.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#66Earlier quoted context omitted.
Other than bad press there's no immediate incentive for the company to avoid stiffing researchers. Bug bounty programs work if the company is vulnerable to bad press and it would actually impact their bottom line. This is not from an examination of when bug programs work but when they have very demonstrably not worked in the past.
Press is a perfect example of incentive alignment in these programs, since not paying a bounty a researcher believes is deserved is practically a guarantee of an uncharitable blog post.
If the cost of an uncharitable blog post is less than the cost of paying out the bounty, then a company would still be incentivized to find as many reasons to reject a payout as possible, as long as future reporters still believe they have a good chance of receiving a payout (e.g., if they believe they can sideskirt any rejection reasons).
Re: Zero-Click Calendar invite vulnerability chain in macOS
#67Earlier quoted context omitted.
Vulnerability researchers misapprehend the dynamics of bug bounty programs all. the. time. and are virtually never doing that in bad faith. I don't need to determine which of these two entities are above board; I presume they both are. If you think that any major vendor bug bounty has incentives to stiff researchers, I'm commenting to tell you that's a strong sign you should dig deeper into the dynamics of bounty pro…
Other than bad press there's no immediate incentive for the company to avoid stiffing researchers. Bug bounty programs work if the company is vulnerable to bad press and it would actually impact their bottom line. This is not from an examination of when bug programs work but when they have very demonstrably not worked in the past.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#68Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…
Shaming Ivan, the head of SEAR, on Twitter is how people who should get paid bounties, but aren't, make progress.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#69Should have sold it to the Israelis NSO Group would have paid more, quicker
It's unclear that NSO group is interested in gaining access to iCloud accounts or Photos, nor is it clear that this entrypoint is something that would meet the bar or be useful for signals intelligence, since it requires sending a calendar invite and clicking on the attachment. Bug bounties will pay for any bug. Offensive firms only pay for things that are practical, and they don't pay everything up front---it depend…
This one didn't.
Re: Zero-Click Calendar invite vulnerability chain in macOS
#70Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…
What I haven't had time to learn more about is when bounties are a such a tiny drop in the bucket for such an enormous number of users and revenue, how is it not a win-win?