Earlier quoted context omitted.
Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.
I wouldn't call it extreme when there was a known public website allowing one-click jailbreak for good few months (not sure if it was actually ever patched or just the iOS version got eol)
Zero click vulnerability in Apple’s macOS Mail
81–90 of 269 posts
Re: Zero click vulnerability in Apple’s macOS Mail
#82Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!
Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs?
It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.
Re: Zero click vulnerability in Apple’s macOS Mail
#83Earlier quoted context omitted.
Apple's entire business model is based on appearances. To be fair so is Microsoft's and many others. Security is usually the last priority for nearly every for profit entity because it doesn't drive revenue.
Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.
Yes, IMO their business model is more accurately described as “gilded cages/jails” than just general “gilded/good-appearing stuff”. They deeply care about the strength of their DRM — including at the expense of end-user security, eg. you can’t access the internet through the Tor browser installed the normal macOS way without macOS broadcasting that you used Tor Project products to Apple’s DRM servers.¹
> They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well.
They definitely care about the appearance of trying to prevent that exfiltrating (they don’t publicly appear to help the FBI do it), but they don’t try hard enough to actually prevent it (including in situations were preventing exfiltration seems to have been proven possible, see nearby comment https://news.ycombinator.com/item?id=26667141).
¹Edit: ocsp.apple.com, enabling targeting of the people who need or want security the most.
To the people downvoting: I’m trying to make an evidence based refutation of the less supported speculation/assertions in the parent post. If you have counter-evidence or any reason to downvote other than fanboyism, please explain it so we or I can learn.
Re: Zero click vulnerability in Apple’s macOS Mail
#84Earlier quoted context omitted.
That's not what the statistics say: https://emailclientmarketshare.com
I'm surprised how high the iPhone share is. Specifically in light of it usually being stated in any thread discussing apple and regulation that Apple do not have anything close to a controlling share of the market
Re: Zero click vulnerability in Apple’s macOS Mail
#85It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.
Re: Zero click vulnerability in Apple’s macOS Mail
#86That's gonna be devastating to the three people who use Mail.app
It’s my main email client, what’s wrong with it?
Re: Zero click vulnerability in Apple’s macOS Mail
#87Earlier quoted context omitted.
> Android had it since ~2012. I seriously wonder: what difference did it make? Was there any groundbreaking thing iOS users missed for 8 years? Apple is just great in omitting things and keeping focus to deliver a great product and then expand on that basis. Most famous example: First iPhones didn’t have MMS
MMS is whack though
Re: Zero click vulnerability in Apple’s macOS Mail
#88> Mail will parse it to find out any attachments with x-mac-auto-archive=yes header in place. Mail will uncompress those files automatically. What could possibly go wrong? ;-/
Re: Zero click vulnerability in Apple’s macOS Mail
#89Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!
Zerodium is interesting. Apparently this bug would fetch "Up to $50k": https://zerodium.com/images/zerodium_prices.png Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs? It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.
Wouldn't the payout contract prohibit reporting to anyone else?
Re: Zero click vulnerability in Apple’s macOS Mail
#90Earlier quoted context omitted.
Apple's entire business model is based on appearances. To be fair so is Microsoft's and many others. Security is usually the last priority for nearly every for profit entity because it doesn't drive revenue.
Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.