9 ms·
On the other hand zero days in OS kernels that run on millions of devices worldwide aren’t your ordinary black market exploits. I agree with publishing after 90
by kahnjw 8y ago
On the other hand zero days in OS kernels that run on millions of devices worldwide aren’t your ordinary black market exploits. I agree with publishing after 90 days. This incentivizes shipping patches quickly and fixing root causes later.
- tptacek 8y agoZero-day privilege escalation bugs for macOS (not iOS) probably have no black market at all (or, whatever, the ceiling price in that black market is the public bounty value of the bug). iOS is of course a very different story and some localhost macOS bugs might have parallels in iOS (not this one though).
- saagarjha 8y agoIs macOS not large enough target, or is there something else at play here?
- kahnjw 8y agoThe opposite, it’s a massive target. I believe the reasoning is that because it is such a large target the black market doesn’t set the price. It gets set by the bounty price the maintainer offers. I’m not familiar with the dynamics of the zero-day black market so I wouldn’t know myself.
- pvg 8y agoIt's just that the bug is worthless, beyond what the vendor will pay for it in a bounty.
- josteink 8y agoIt’s a minuscule market. 1% of the desktop market, which itself is a market in decline.
- saagarjha 8y ago1% of the desktop market? No way. It's at least 10%.
- josteink 8y agoProbably not that high worldwide. Either way, it’s still tiny and shrinking.
- coldtea 8y ago10% is neither "tiny" nor shrinking. If anything their year over year numbers are better compared to the overall market...
- chrisseaton 8y ago10% of laptops maybe but 10% of desktops? Think of all those thousands of Windows desktops in offices everywhere around the world.
- alxlaz 8y agoThe size of the market alone is not a good indicator. Macs are routinely sighted among C-level executives or journalists, and among their family members. And it looks like the kind of issue that could be exploited as part of an APT. It's pretty much the kind of thing that you expect to pop up for sale in shady places.
- josteink 8y agoI sometimes see people make the argument that the tiny amount of Mac-users are somehow more important/valuable compared to the immense swath of non-Macs out there, and I always suspect it’s Mac-users trying to assert their own importance, stroke their own ego and/or justify their needless expenditure. So tell me kind sir: what OS do you use?
- jkaplowitz 8y ago
- CJefferson 8y agoI would guess most of the things you'd want to do on a mac, you can just do as a user - - you can already access everything in the user's home directory for example.
- coldtea 8y ago>you can just do as a user - - you can already access everything in the user's home directory for example As opposed to what other operating system? Even Linux with SELINUX allows that...
- Aissen 8y agoAs opposed to Android, iOS… and some rare case of sandbox linux apps (small subset of flatpak, snap, etc.)
- coldtea 8y agoIf we're talking about sandboxing, then macOS has that too. Apps installed through the MAS have specific sandboxes they can play in and require permission for the others.
- saagarjha 8y agoNot in macOS Mojave. Sensitive directories (Safari, Mail, etc.) are inaccessible to apps without permission.
- michaelt 8y agohttps://xkcd.com/1200/ https://xkcd.com/1200/ points out that if malicious code runs as a user they can read my e-mails, access all my files, and keylog my passwords. By escalating to root, they can... what? Install OS updates and drivers? Mount and unmount disks? Access the serial port? Persist their access in a slightly harder to detect manner? Of course, it's a different matter for shared computers in school computer labs. Or if mac servers were a thing.
- kahnjw 8y agoWhy is iOS a different story?
- saagarjha 8y agoIt’s a big and hard-to-exploit target?
- tptacek 8y agoiOS is one of the world's 3 most important COTS platform targets, along with Chrome and (guessing?) Windows. Localhost privilege escalation on iOS can be a a link in a drive-by jailbreak chain.
- whatusername 8y agoAre there non COTS platform targets more important/valuable than iOS/Chrome/Windows? Some kind of embedded/industrial control system? z/OS?
- iceninenines 8y agoIf the COW bug applied to the xnu kernel generally (shared by macOS, AppleTV, iOS, etc.), it would've been a big kerfuffle. It's still a big deal because it lets malware write to memory/files it shouldn't if they have a way to trick an user or unattended run a local executable. Even with SIP enabled, it would still be bad based on what could be implanted and always running as a root daemon by clever exploitation of this.
- geofft 8y agoiOS has universal inter-app sandboxing. macOS is getting there, but not quite yet. So on iOS, a privilege escalation vulnerability is useful for getting data out of a different unprivileged context; on macOS, you might already be in that context.
- calgoo 8y agoWell, as a lot of developers use OSX, i could see the potential of making code / token / authentication sniffing malware that sniffs out git credentials and other authentication tokens. This could then be used to gain access to backend servers and/or injecting backdoors and malware into software.
- acdha 8y agoThis bug requires local code execution capabilities. How many of the scenarios you describe are there where someone couldn’t simply use that to harvest credentials directly?
- coldtea 8y agoYeah, who would want to be able to target a 5% of the most well-off people in the US (based on the demographics to splurge for Apple laptops), or people in positions of influence and power (seeing that 1 in 2 politicians/CEOs/writers/journalists/musicians/etc interviewed seem to use one).
- patio11 8y agoBut if you have arbitrary code execution on a MacBook, you probably have everything you want from that MacBook, because consumer desktop OSes and application software is insufficiently locked down to prevent you from getting everything you'd want. Escalating from arbitrary code execution to rooting the MacBook doesn't really increase its level of interesting to you. This is untrue for iOS, because iOS actually does have a pretty robust security model which has only-semi-trusted apps running on your skeleton key to everything.
- toyg 8y agoIsh. I think with a user process in OsX you don’t get passwords saved in keychain, which might well be what you are really after, these days.
- breatheoften 8y agoDoes root access directly get you keychain credentials (or does it only get it via the possibility of key logging)?
- acdha 8y agoIn the past, you’d be able to read it out of the process memory when the keychain was unlocked. I believe that’s been locked down in the last couple of releases, however.
- dzhiurgis 8y agoHow about all the other password managers, especially Chrome's?
- zwerdlds 8y agoIt would be easier to justify this if apple responded to their bugs.
- thisisweirdok 8y agoSeriously, there are open Safari bugs that have existed in Apple's system for 6+ years. At least slap a wontfix on there.