Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

81–90 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#81
post #74

Earlier quoted context omitted.

No, it's because Apple's 'product security' team that investigates and pays out bug bounties is horribly mismanaged and ineffective. It was recently moved from the SWE program office to SEAR (security engineering & arch), and the manager was recently shown the door and went to AirBNB. The team members are mostly new college grads (ICT2's and 3's) who wouldn't pass a coding interview elsewhere in the company, and most…

I have no idea about how well the bounty program at Apple is managed, so, without affirming this, I acknowledge this is another plausible explanation: it's just an understaffed team that needs to get its act together. The only crusade I'm on is against the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false, like, the opposite of the truth. I think it's valuable for…

[deleted]

Re: Zero-Click Calendar invite vulnerability chain in macOS

#82

Earlier quoted context omitted.

Other than bad press there's no immediate incentive for the company to avoid stiffing researchers. Bug bounty programs work if the company is vulnerable to bad press and it would actually impact their bottom line. This is not from an examination of when bug programs work but when they have very demonstrably not worked in the past.

Maybe not “immediate” but withholding rewards results in fewer researchers participating in bounty programs which defeats the purpose.

Not if the (true) purpose of having the bounty program is simply PR, rather than an honest desire to find and fix bugs.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#83
post #61
post #39

Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…

What I haven't had time to learn more about is when bounties are a such a tiny drop in the bucket for such an enormous number of users and revenue, how is it not a win-win?

With tech giants there's really no win win, only 1 win. They win either way. So why bother?

Re: Zero-Click Calendar invite vulnerability chain in macOS

#84
post #74

Earlier quoted context omitted.

No, it's because Apple's 'product security' team that investigates and pays out bug bounties is horribly mismanaged and ineffective. It was recently moved from the SWE program office to SEAR (security engineering & arch), and the manager was recently shown the door and went to AirBNB. The team members are mostly new college grads (ICT2's and 3's) who wouldn't pass a coding interview elsewhere in the company, and most…

I have no idea about how well the bounty program at Apple is managed, so, without affirming this, I acknowledge this is another plausible explanation: it's just an understaffed team that needs to get its act together. The only crusade I'm on is against the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false, like, the opposite of the truth. I think it's valuable for…

Honestly, Apple is a 3.5 trillion dollar company. If the bug bounty program is understaffed then it's an intentional choice and they should fix it. And I say that as someone who's generally sympathetic to Apple.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#85
post #82

Earlier quoted context omitted.

Maybe not “immediate” but withholding rewards results in fewer researchers participating in bounty programs which defeats the purpose.

Not if the (true) purpose of having the bounty program is simply PR, rather than an honest desire to find and fix bugs.

The true purpose of these programs is to direct research to specific threats and engineering areas.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#86
post #78

Earlier quoted context omitted.

Look, I believe you, but people complain about all these bounty programs, some of which I know to have been extraordinarily well managed, and usually when you get to the bottom of those complaints it comes down to a misapprehension the researchers have about what the bounty program is doing and what its internal constraints are. I acknowledge that another possibility is that the bounty program itself isn't performing…

My point is that while the sums might be "not real money", the costs of stiffing researchers is even moreso "not real money", so that it makes sense on the margin to do it, whenever the situation isn't incredibly clear-cut. After all, it's not like Apple goes around handing out free iPhones on the street, even though a few thousand units are similarly "not real money". Businesses care about small effects on the margi…

No, I don't think this logic holds, at all.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#87
post #84
post #74

Earlier quoted context omitted.

I have no idea about how well the bounty program at Apple is managed, so, without affirming this, I acknowledge this is another plausible explanation: it's just an understaffed team that needs to get its act together. The only crusade I'm on is against the idea that companies ruthlessly avoid paying bounties, which is, on information and belief, flatly false, like, the opposite of the truth. I think it's valuable for…

Honestly, Apple is a 3.5 trillion dollar company. If the bug bounty program is understaffed then it's an intentional choice and they should fix it. And I say that as someone who's generally sympathetic to Apple.

Sure. My comment isn't really about Apple specifically so much as bounty program misconceptions generally.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#88
post #86

Earlier quoted context omitted.

My point is that while the sums might be "not real money", the costs of stiffing researchers is even moreso "not real money", so that it makes sense on the margin to do it, whenever the situation isn't incredibly clear-cut. After all, it's not like Apple goes around handing out free iPhones on the street, even though a few thousand units are similarly "not real money". Businesses care about small effects on the margi…

No, I don't think this logic holds, at all.

Which part does not follow? Even supposing that the members of Apple's bug bounty team are all well-meaning, but that the program itself is chronically mismanaged, one might conjecture that Apple is disincentivized from investing in making the program better-managed.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#89
post #63

Should have sold it to the Israelis NSO Group would have paid more, quicker

No he shouldn’t. That mentality is cancerous to society.

Yes that is right! That is cancerous. Apple, not paying the peanuts as a bounty, is fully responsible for spreading these terminal diseases.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#90
post #53

Earlier quoted context omitted.

It's unclear that NSO group is interested in gaining access to iCloud accounts or Photos, nor is it clear that this entrypoint is something that would meet the bar or be useful for signals intelligence, since it requires sending a calendar invite and clicking on the attachment. Bug bounties will pay for any bug. Offensive firms only pay for things that are practical, and they don't pay everything up front---it depend…

> since it requires sending a calendar invite and clicking on the attachment. I thought it was a zero click exploit? As for being interested in iCloud and photos, is the argument that the people they’re looking to attack are unlikely to use iCloud? Cause otherwise getting photos and potentially email access seems quite valuable.

The bigger thing here I think is that the target platform is macOS. An important detail to internalize about major grey market buyers of vulnerabilities: they tend not to stockpile; every vulnerability they buy they need to maintain, and there's not much benefit to maintaining vulnerabilities you aren't going to use. There is, how should we put this, probably not a whole lot of scarcity in macOS RCE vulnerabilities? It would be wild to learn that a threat actor at NSO's scale doesn't already have macOS (and Windows, and Ubuntu) wired for sound already.

(This stockpiling thing isn't me guessing; it's something I learned pretty recently).

Post reply on HN