Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

71–80 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#72

Use MailMate! https://freron.com/

How has maintenance & bug fixing been? I'm OK with mature apps stabilizing and needing few updates, though since it is a single dev with somewhat infrequent changes I thought I'd ask (https://updates.mailmate-app.com/release_notes).

Re: Zero click vulnerability in Apple’s macOS Mail

#73
post #54

Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!

Is this referencing the slow turnaround time, or the lack of a bounty paid so far? If it's the latter, I think it's already well known that bug bounties pay far less than the "market" value of such exploits.

Re: Zero click vulnerability in Apple’s macOS Mail

#74

Earlier quoted context omitted.

Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.

I wouldn't call it extreme when there was a known public website allowing one-click jailbreak for good few months (not sure if it was actually ever patched or just the iOS version got eol)

10 years ago, yeah.

https://en.m.wikipedia.org/wiki/JailbreakMe

Re: Zero click vulnerability in Apple’s macOS Mail

#75
post #7
post #3

That's gonna be devastating to the three people who use Mail.app

What are the options for those who foolishly installed an OS version later than Snow Leopard and can't run Eudora?

Porting the Mac version to a modern Mac OS will be a serious challenge, but source code is available (BSD-licensed). See https://computerhistory.org/blog/the-eudora-email-client-sou....

Re: Zero click vulnerability in Apple’s macOS Mail

#76
post #38

Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?

If you turn on iCloud, it's theater.

Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0]

I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way.

[0]: https://qz.com/1844937/hong-kongs-mass-arrests-give-police-a...

Re: Zero click vulnerability in Apple’s macOS Mail

#77
post #73
post #54

Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!

Is this referencing the slow turnaround time, or the lack of a bounty paid so far? If it's the latter, I think it's already well known that bug bounties pay far less than the "market" value of such exploits.

> well known

Well I didn't know, until now. I saw the bug bounty page at Apple before, was dazzled by the numbers, and didn't think twice about approaching them if I found a bug. Now after this article I know better than to trust them to pay.

Re: Zero click vulnerability in Apple’s macOS Mail

#78
post #63
post #54

Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!

> 3-letter agency From the wikipedia page for Meltdown: "On 8 May 1995, a paper called "The Intel 80x86 Processor Architecture: Pitfalls for Secure Systems" published at the 1995 IEEE Symposium on Security and Privacy warned against a covert timing channel in the CPU cache and translation lookaside buffer (TLB). This analysis was performed under the auspices of the National Security Agency's Trusted Products Evaluati…

My understanding is that people at the time were aware of potential problems but no vulnerability had been identified. I found some discussion here: https://security.stackexchange.com/a/177256

Re: Zero click vulnerability in Apple’s macOS Mail

#79
post #38

Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?

>While the police managed to crack into Wong’s iPhone, which was locked with a four-digit passcode, they did not manage to access the contents of Chow’s Google Pixel phone using the force’s existing digital forensics tools, according to the court filing. Chow says her phone is still in police possession. https://qz.com/1844937/hong-kongs-mass-arrests-give-police-a...

[deleted]
Post reply on HN