Live data from Hacker News

Zero-Click Calendar invite vulnerability chain in macOS

mikko-kenttala.medium.com

91–100 of 166 posts

Re: Zero-Click Calendar invite vulnerability chain in macOS

#91
post #86

Earlier quoted context omitted.

No, I don't think this logic holds, at all.

Which part does not follow? Even supposing that the members of Apple's bug bounty team are all well-meaning, but that the program itself is chronically mismanaged, one might conjecture that Apple is disincentivized from investing in making the program better-managed.

I'm not deriving this axiomatically. The bounty programs I'm familiar with incentivize their teams to grant more bounties. I don't have recent specific knowledge of how Apple's program works. Obviously, Apple is more fussy than other programs! They want very specific things. But a just-so story that posits Apple's bounty incentives are just wildly different than the rest of the industry isn't going to get you and I anywhere. It's fine that we disagree. I do not believe Apple ruthlessly denies bounty payouts, and further think that claims they do are pretty wild.

(I have no opinions in either direction about whether Apple is denying bounty payments because of difficulties operating the program!)

Re: Zero-Click Calendar invite vulnerability chain in macOS

#92
post #44

Earlier quoted context omitted.

This is a regular part of the recruiting process, where you may start chatting in LinkedIn and then get an invite on your email.

If the recruiter doesn't ask me first (or I don't agree to a meeting), this is called "spam", and I would be happy for the system to just not allow it.

I have never encountered a situation where recruiter starts immediately with an invite without prior conversation (such invite also blocks the time slot of the sender - it would be stupidly ineffective to do that). It is hypothetical and improbable scenario that is not even worth mentioning here.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#93
post #91

Earlier quoted context omitted.

Which part does not follow? Even supposing that the members of Apple's bug bounty team are all well-meaning, but that the program itself is chronically mismanaged, one might conjecture that Apple is disincentivized from investing in making the program better-managed.

I'm not deriving this axiomatically. The bounty programs I'm familiar with incentivize their teams to grant more bounties. I don't have recent specific knowledge of how Apple's program works. Obviously, Apple is more fussy than other programs! They want very specific things. But a just-so story that posits Apple's bounty incentives are just wildly different than the rest of the industry isn't going to get you and I a…

Perhaps I've been somewhat too harsh: I don't see any particular 'ruthlessness' in Apple's actions. But I do think that its program, as well as many other bug bounty programs, can easily end up more byzantine in their rules than they'd otherwise be, since there's not much incentive counteracting such fussiness.

After all, one might easily imagine a forgiving rule of "we'll pay some amount of money (whether large or small) for any security issue we actively fix based on the information in the report", and yet Apple seemingly chooses to be more fussy than that in this case, unless they're just being extremely slow. I just don't see any way to square such apparent fussiness with your experience of bug bounty programs leaning toward paying out more.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#94
post #39

Lots of comments on this thread about bounty payouts. If a tech giant with a standing bounty program isn't paying a bounty, the odds are very strong that there's a good reason for that. All of the incentives for these programs are to award bounties to legitimate submissions. This is a rare case where incentives actually align pretty nicely: companies stand up bounty programs to incentivize specific kinds of research;…

> the odds are very strong that there's a good reason for that

The easiest way to show this would be to give the responsibility of managing the bug bounty to a third party who isn't involved in the business.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#95

Does Lockdown Mode prevent this?

Totally speculating, but I’d hope so. After all the prior zero-click image attachment related exploits, which I think lockdown mode was built to address, I’d figure all files are treated in that manner.

You can't treat "all files" like that. This would be akin to the "why don't they just make all the file handling out of Lockdown mode code" ;)

Re: Zero-Click Calendar invite vulnerability chain in macOS

#96
post #45

Earlier quoted context omitted.

HR / Recruiter setting up interviews? The person doing the inviting might be different from previous calls/emails. Customer meetings I get invited to often come from someone I’ve never dealt with before, but include others who I work with who were responsible for bringing me into it.

I think there's a pretty big gap between "people at my company are allowed to add things to my calendar" and "random stranger anywhere in the world can add things to my calendar".

Neither of the above examples would come from people in my company.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#97
post #33
post #27

Earlier quoted context omitted.

Dude likely could have sold this to malicious threat actors for 6 figures. Weird that it's been 2 years now and Apple still hasn't paid anything. Really highlights why people might tend to gravitate towards that route instead of going thru the legit bug bounty process.

Does it work on an iPhone? If not, you're probably not selling it for 6 figures, or even 5.

It does not.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#99
post #71

Earlier quoted context omitted.

Which process ensures that the company should actually care in the slightest about an uncharitable blog post or two, especially when its motivations are opaque enough that the lack of payment might be chalked up to "there's a good reason for that"? If the cost of an uncharitable blog post is less than the cost of paying out the bounty, then a company would still be incentivized to find as many reasons to reject a pay…

The cost of an uncharitable blog post is massively more than the price of a bounty, like, it's not even close. The cost of an uncharitable blog post is potentially unbounded (as in: not many people in a large tech company would know how to put a ceiling on the cost), and the cost of a bounty, even a high one, is more or less chump change. Another in my long-running dramatic series "businesses pay spectacularly more f…

Companies are not set up to accurately and effectively gauge the impact of intangible costs to themselves.

Re: Zero-Click Calendar invite vulnerability chain in macOS

#100
post #47

Thankfully I don't use iCloud Photo Library, but it's both weird to learn that when the photo library location has been changed, the new location does not get any protection. I would have expected the exploit to fail after setting /var/tmp/mypictures/Syndication.photoslibrary as the system photo library and opening Photos because the Photos app should know to protect this directory. I just did a quick test on my Sono…

TCC has historically always been kind of weird and full of holes in this way.
Post reply on HN