Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

81–90 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#81

Earlier quoted context omitted.

Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.

I wouldn't call it extreme when there was a known public website allowing one-click jailbreak for good few months (not sure if it was actually ever patched or just the iOS version got eol)

They then hired the guy creating those exploit chains.

Re: Zero click vulnerability in Apple’s macOS Mail

#82
post #54

Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!

Zerodium is interesting. Apparently this bug would fetch "Up to $50k": https://zerodium.com/images/zerodium_prices.png

Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs?

It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.

Re: Zero click vulnerability in Apple’s macOS Mail

#83
post #40

Earlier quoted context omitted.

Apple's entire business model is based on appearances. To be fair so is Microsoft's and many others. Security is usually the last priority for nearly every for profit entity because it doesn't drive revenue.

Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.

> Apple puts rather extreme security effort into preventing iOS jailbreaks.

Yes, IMO their business model is more accurately described as “gilded cages/jails” than just general “gilded/good-appearing stuff”. They deeply care about the strength of their DRM — including at the expense of end-user security, eg. you can’t access the internet through the Tor browser installed the normal macOS way without macOS broadcasting that you used Tor Project products to Apple’s DRM servers.¹

> They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well.

They definitely care about the appearance of trying to prevent that exfiltrating (they don’t publicly appear to help the FBI do it), but they don’t try hard enough to actually prevent it (including in situations were preventing exfiltration seems to have been proven possible, see nearby comment https://news.ycombinator.com/item?id=26667141).

¹Edit: ocsp.apple.com, enabling targeting of the people who need or want security the most.

To the people downvoting: I’m trying to make an evidence based refutation of the less supported speculation/assertions in the parent post. If you have counter-evidence or any reason to downvote other than fanboyism, please explain it so we or I can learn.

Re: Zero click vulnerability in Apple’s macOS Mail

#84
post #61
post #6

Earlier quoted context omitted.

That's not what the statistics say: https://emailclientmarketshare.com

I'm surprised how high the iPhone share is. Specifically in light of it usually being stated in any thread discussing apple and regulation that Apple do not have anything close to a controlling share of the market

Things may have changed, but to my knowledge iDevices have traditionally been disproportionately represented in many metrics due to getting heavier usage from their owners. Android wins by far in sheer units sold and in use, but iOS users use their devices so much more heavily and frequently that the average iOS user has a larger usage footprint than their Android counterpart.

Re: Zero click vulnerability in Apple’s macOS Mail

#86
post #9
post #3

That's gonna be devastating to the three people who use Mail.app

It’s my main email client, what’s wrong with it?

I have an issue where it always thinks a couple of accounts are offline. I have to click the squiggle for it to download those accounts. Every restart I have to do the same thing.

Re: Zero click vulnerability in Apple’s macOS Mail

#87
post #68

Earlier quoted context omitted.

> Android had it since ~2012. I seriously wonder: what difference did it make? Was there any groundbreaking thing iOS users missed for 8 years? Apple is just great in omitting things and keeping focus to deliver a great product and then expand on that basis. Most famous example: First iPhones didn’t have MMS

MMS is whack though

I am guessing they already knew GPRS/UMTS and data plans were the future, hence they invested in iMessage. MMS already had an expiration date. Quite sure they only added it because of the PR disaster it had become.

Re: Zero click vulnerability in Apple’s macOS Mail

#88

> Mail will parse it to find out any attachments with x-mac-auto-archive=yes header in place. Mail will uncompress those files automatically. What could possibly go wrong? ;-/

This is the same exact issue that used to plague Outlook back in the day with the automatic handling of attachments. You'd think Apple would have learned from others' mistakes.

Re: Zero click vulnerability in Apple’s macOS Mail

#89
post #54

Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!

Zerodium is interesting. Apparently this bug would fetch "Up to $50k": https://zerodium.com/images/zerodium_prices.png Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs? It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.

> There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.

Wouldn't the payout contract prohibit reporting to anyone else?

Re: Zero click vulnerability in Apple’s macOS Mail

#90
post #40

Earlier quoted context omitted.

Apple's entire business model is based on appearances. To be fair so is Microsoft's and many others. Security is usually the last priority for nearly every for profit entity because it doesn't drive revenue.

Apple puts rather extreme security effort into preventing iOS jailbreaks. They are pretty serious about trying to prevent data exfiltration from locked iOS devices as well. They aren’t perfect but I don’t think it’s fair to say they don’t try.

[deleted]
Post reply on HN