Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

61–70 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#61
post #39

Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…

What I haven't had time to learn more about is when bounties are a such a tiny drop in the bucket for such an enormous number of users and revenue, how is it not a win-win?

Re: Zero-Click Calendar invite vulnerability chain in macOS

#62

Earlier quoted context omitted.

> Because you work with people outside of your company, support, vendors, sales people etc. If I work with them, I would have them whitelisted. If I've never even heard of them they have no business sending my devices calendar invites. Boss: Why aren't you working on that project I gave you? You: Some stranger in Indonesia invited me to a sales meeting instead. Boss: If I need you to go to a sales meeting with someon…

Idk, other members of the third party company get pulled in all the time and might schedule something. I can't imagine using a calendar whitelist or why you'd even want to.

Well, to eliminate a source of spam, reduce exposure to phishing, and prevent vulnerabilities like the one talked about in the article by reducing attack surface.

If someone is going to make some demand for my time, the very least they can do is give me notice outside of my icloud calendar. An email, an IM, a phone call, etc are all very easy and they allow me to make sure it's real before it has any chance to interfere with my schedule. "Hey Boss, this guy says he's our new IT guy and he wants to talk about my network settings" or "Hey $vendor, I just got a call from $rando saying he's our new contact, can you verify that for me before I tell him everything I know about your propriety applications?"

It helps that I like to keep my work devices and my personal devices entirely separate. If someone in the office wants to pull me into a work meeting through outlook, they'll already have to have an account set up on the company's exchange server. Anyone outside of the company I should already have a relationship with or at least a heads up.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#64
post #21
post #19

Earlier quoted context omitted.

Not to be smart -- but how else would invites work?

How often do you get a calendar invite from a person who you never interacted through email before and don't have in contacts vs the opposite, and actually take the meeting?

Pretty often at work. I'm often interacting with client/vendor teams or even new people at the company I work for. Probably a few times a week I'll get an invite from someone I have never exchanged an actual email with. Maybe Teams/other chat messages, maybe exchanged information with one of their colleagues, or talked over the phone.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#65
post #44

Earlier quoted context omitted.

This is a regular part of the recruiting process, where you may start chatting in LinkedIn and then get an invite on your email.

If the recruiter doesn't ask me first (or I don't agree to a meeting), this is called "spam", and I would be happy for the system to just not allow it.

Often, a coordinator sends the invite - not the recruiter.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#66
post #59

Earlier quoted context omitted.

Other than bad press there's no immediate incentive for the company to avoid stiffing researchers. Bug bounty programs work if the company is vulnerable to bad press and it would actually impact their bottom line. This is not from an examination of when bug programs work but when they have very demonstrably not worked in the past.

Press is a perfect example of incentive alignment in these programs, since not paying a bounty a researcher believes is deserved is practically a guarantee of an uncharitable blog post.

Which process ensures that the company should actually care in the slightest about an uncharitable blog post or two, especially when its motivations are opaque enough that the lack of payment might be chalked up to "there's a good reason for that"?

If the cost of an uncharitable blog post is less than the cost of paying out the bounty, then a company would still be incentivized to find as many reasons to reject a payout as possible, as long as future reporters still believe they have a good chance of receiving a payout (e.g., if they believe they can sideskirt any rejection reasons).

Re: Zero-Click Calendar invite vulnerability chain in macOS

#67
post #51

Earlier quoted context omitted.

Vulnerability researchers misapprehend the dynamics of bug bounty programs all. the. time. and are virtually never doing that in bad faith. I don't need to determine which of these two entities are above board; I presume they both are. If you think that any major vendor bug bounty has incentives to stiff researchers, I'm commenting to tell you that's a strong sign you should dig deeper into the dynamics of bounty pro…

Other than bad press there's no immediate incentive for the company to avoid stiffing researchers. Bug bounty programs work if the company is vulnerable to bad press and it would actually impact their bottom line. This is not from an examination of when bug programs work but when they have very demonstrably not worked in the past.

Maybe not “immediate” but withholding rewards results in fewer researchers participating in bounty programs which defeats the purpose.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#68
post #39

Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…

No, it's because Apple's 'product security' team that investigates and pays out bug bounties is horribly mismanaged and ineffective. It was recently moved from the SWE program office to SEAR (security engineering & arch), and the manager was recently shown the door and went to AirBNB. The team members are mostly new college grads (ICT2's and 3's) who wouldn't pass a coding interview elsewhere in the company, and mostly function as bug triagers. They spend more time going to conferences and hanging out with hackers, than in front of a computer screen working. Their portal of 'open investigations' shows a graph that only goes up (aka they only get more swamped with emails and don't even try to catch up).

Shaming Ivan, the head of SEAR, on Twitter is how people who should get paid bounties, but aren't, make progress.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#69
post #53

Should have sold it to the Israelis NSO Group would have paid more, quicker

It's unclear that NSO group is interested in gaining access to iCloud accounts or Photos, nor is it clear that this entrypoint is something that would meet the bar or be useful for signals intelligence, since it requires sending a calendar invite and clicking on the attachment. Bug bounties will pay for any bug. Offensive firms only pay for things that are practical, and they don't pay everything up front---it depend…

> Bug bounties will pay for any bug.

This one didn't.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#70
post #61
post #39

Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…

What I haven't had time to learn more about is when bounties are a such a tiny drop in the bucket for such an enormous number of users and revenue, how is it not a win-win?

It is a win-win.
Post reply on HN