Live data from Hacker News

Security researcher Charlie Miller booted from Apple Developer Program

news.cnet.com

81–90 of 116 posts

Re: Security researcher Charlie Miller booted from Apple Developer Program

#81
post #31
post #22

Earlier quoted context omitted.

And security research does not trump the developer agreement. The guy submitted a real live exploit to the Joe-User facing App Store. What on earth did he expect would happen?

Maybe he expected a "thanks for showing us this vulnerability, we've pulled your app from the store and are working on a fix to the problem", as a sane response would be.

He could also just have sent them an email about it. Instead he put a malicious app on the store and announced a talk at a security conference. Diplomacy was never his skill.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#82
post #73

Earlier quoted context omitted.

Hold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.

He's pretty well known because of his series of 0-day exploits at CanSecWest.

Indeed. When you think OSX and iOS Security, Charlie Miller is the first name that comes to mind.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#83
post #74

Earlier quoted context omitted.

So how do you prove the DDoS vector exists unless you DDoS someone's site? How do you prove the SQL injection vector exists unless you take over someone's site? etc., etc. This was far from a harmless proof-of-concept app, and "I just wanted to prove I could" isn't sufficient justification for it.

You don't need to "take over someone's site" to prove that their site has a SQLI vector, just put in a little string somewhere.

In the UK, using SQL injection to "put a little string somewhere" would be illegal.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#85
post #69
post #27

Earlier quoted context omitted.

when you submit a security related bug report to apple - granted my experience dates from 99-2005 - you get: A/ ignored (mail auto reply "we might fix it, don't tell anyone or we'll go after you" B/ bug don't get fixed for 2 or 3 years C/ bug get fixed, you get no credits

Submitting a security bug report to the Chromium project was a delight compared to submitting one to Apple. It was obvious that the engineers working on Chromium cared about the problem and were competent. On the other hand, I mightaswell have been reporting the Apple bug to a brick wall or a black hole.

Odd use of the word "competent", you implying Apple personnel aren't competent because they didn't send a message saying "thank you" with gold stars all over it?

Re: Security researcher Charlie Miller booted from Apple Developer Program

#86
post #74

Earlier quoted context omitted.

You don't need to "take over someone's site" to prove that their site has a SQLI vector, just put in a little string somewhere.

In the UK, using SQL injection to "put a little string somewhere" would be illegal.

Oh probably. But I'm pointing out that you can demonstrate a SQLI attack without having to completly take down someone's site.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#87
post #19
post #11

It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…

I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.

Perhaps he's not the first one to do it? Only the first to tell Apple that he did it.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#88
post #11

It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…

Hold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.

Everyone at Apple who does security knows of Charlie Miller. The guy has a phd and hacks Apple products and wins prizes and writes research papers, etc. If they don't know of him I'd be very surprised.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#89
post #19
post #11

It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…

I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.

From Miller's twitter stream last night:

For the record, without a real app in the AppStore, people would say Apple wouldn't approve an app that took advantage of this flaw.

https://twitter.com/#!/0xcharlie/status/133739410662494208

Re: Security researcher Charlie Miller booted from Apple Developer Program

#90
post #59

Earlier quoted context omitted.

So how do you prove that it's possible to get this kind of exploit into the store unless you submit it to the store?

So how do you prove the DDoS vector exists unless you DDoS someone's site? How do you prove the SQL injection vector exists unless you take over someone's site? etc., etc. This was far from a harmless proof-of-concept app, and "I just wanted to prove I could" isn't sufficient justification for it.

Since he has control over pricing, couldn't he submit with a free price tag, and change it to something insanely high once accepted. That way no sane person would buy it, and he'd still prove his point. He _had_ to submit an app and get it in for this to work ofcourse, otherwise this was a moot point. And it's a good wakeup call to everyone. Security awewareness helps sometimes unfortunately when you make a splash.
Post reply on HN