Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

91–100 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#91
post #76
post #38

Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?

If you turn on iCloud, it's theater. Android with syncing enabled does much better in real world tests. Notably in hong kong, they were able to crack the iPhones, but not the Pixels[0] I'm pretty sure without iCloud and a long enough password (or fast enough self destruct mode) iPhones could be as secure, but I don't know anyone that uses an iPhone and does not use iCloud in any way. [0]: https://qz.com/1844937/hong-…

What part of iCloud is the problem?

Re: Zero click vulnerability in Apple’s macOS Mail

#93
post #38

Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?

>While the police managed to crack into Wong’s iPhone, which was locked with a four-digit passcode, they did not manage to access the contents of Chow’s Google Pixel phone using the force’s existing digital forensics tools, according to the court filing. Chow says her phone is still in police possession. https://qz.com/1844937/hong-kongs-mass-arrests-give-police-a...

There is literally no other detail than the phone model name. For all we know it could be an ancient iPhone with a severely outdated OS and a brand new Pixel phone.

4-digit passcode hasn't been the default passcode option in iOS for a long time.

Re: Zero click vulnerability in Apple’s macOS Mail

#96
For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium:

The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day.

Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try to earn a dishonest living with pain and death in their wake. Are you using your skills to improve life on this rock, or are you trying to make it worse for a pay day?

Re: Zero click vulnerability in Apple’s macOS Mail

#97

Earlier quoted context omitted.

A big difference is that the software running on Apple devices is less complex. For example there is significantly less hardware support. iMessage only talks to other iMessage instances (eg no browser support). There is only one web browser engine. Third party apps can't do JIT code generation. Older APIs are actively removed, breaking existing apps (vs providing backwards compatibility). In general less complexity i…

> Android had it since ~2012. I seriously wonder: what difference did it make? Was there any groundbreaking thing iOS users missed for 8 years? Apple is just great in omitting things and keeping focus to deliver a great product and then expand on that basis. Most famous example: First iPhones didn’t have MMS

I think there has been a lack of interest in smartphone NFC because iOS has no support for it.

For example, I have set up a tag to automatically connect friends phones to my WiFi network. You can also stick tags on places to trigger specific actions/mode/app: office, meeting room, car, bedroom.

Also one thing that could have been great to share pictures/files/urls with your computer or other phones: Android beam [1]. Sadly Google is removing it.

[1]https://en.wikipedia.org/wiki/Android_Beam#Usage

Re: Zero click vulnerability in Apple’s macOS Mail

#98

Earlier quoted context omitted.

>While the police managed to crack into Wong’s iPhone, which was locked with a four-digit passcode, they did not manage to access the contents of Chow’s Google Pixel phone using the force’s existing digital forensics tools, according to the court filing. Chow says her phone is still in police possession. https://qz.com/1844937/hong-kongs-mass-arrests-give-police-a...

There is literally no other detail than the phone model name. For all we know it could be an ancient iPhone with a severely outdated OS and a brand new Pixel phone. 4-digit passcode hasn't been the default passcode option in iOS for a long time.

https://www.tomsguide.com/news/police-say-android-phones-are...

>This is supported by a look at smartphone cracking company Cellebrite’s effectiveness at breaking into different phones. Cellebrite can easily open up any iPhone X or earlier iPhone, but the same software used on a Google Pixel 2 or Galaxy S9 extracts very little information, and nothing at all in the case of the Huawei P20 Pro.

>That’s not to say that these Android devices are unbreakable. It's just that it requires a different, more labor-intensive process to get the data requested.

>The sheer variety of Android hardware and customized software builds makes it hard for phone-crackers to build a universal tool to break into Android phones. Meanwhile, a "jailbreak" released late last year permanently bypasses the security functions of every iPhone model from the iPhone 4s to the iPhone X.

This perfectly squares with what I personally know from law enforcement friends but I'm just an internet stranger.

Re: Zero click vulnerability in Apple’s macOS Mail

#99
post #54

Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!

Yes, the current meaning of “responsible disclosure” is bullshit

There should likely be a governing body that independently values an exploit and forces companies to pay

Like how the SEC’s whistleblower program works

Its completely broken to have corporations pinky promise not to sue you if you tell them and arbitrarily decide payouts if at all

Re: Zero click vulnerability in Apple’s macOS Mail

#100
post #54

Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!

Zerodium is interesting. Apparently this bug would fetch "Up to $50k": https://zerodium.com/images/zerodium_prices.png Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs? It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.

[deleted]
Post reply on HN