11 ms·
What is Apple trying to gain by publishing this article? The tone is accusatory and defensive in a combination that does not make me sympathetic towards Apple.
by bjornedstrom 7y ago
What is Apple trying to gain by publishing this article? The tone is accusatory and defensive in a combination that does not make me sympathetic towards Apple.
When Google posted the Project Zero articles, that did not impact my view of Apple in any way. However this press piece affects my view of Apple negatively, so from my perspective this press article has turned a more or less neutral event into one that is negative.
- _bxg1 7y agoThe general population of iPhone owners don't have the technical knowledge to understand the nuance of the actual vulnerability and exploit, so for many of them it probably wasn't a "neutral event". The subject of the article does come off as a bit defensive - though much less so than it could've - but I understand why they felt the need to tell their side of the story.
- 3JPLW 7y agoI mean, it is by definition defensive. They're pushing back against some of P0's claims. Project Zero (whether it's housed at Google or not) has a vested interest in making their detections as newsworthy as possible. Apple has a vested interest in downplaying those claims as much as possible.
- _bxg1 7y agoEdit: This article points out that some of Apple's wording wasn't as good-faith as it may've seemed: https://www.theverge.com/2019/9/6/20853393/apple-iphone-ios-exploits-statement-security-google-false-impressions https://www.theverge.com/2019/9/6/20853393/apple-iphone-ios-...
- dpkonofa 7y agoWhile I do admit that I agree with a few of those points, the Verge isn't exactly reporting in good-faith either, IMO. They are very biased against Apple, for whatever reason.
- elicash 7y agoI had only seen the headlines, but I learned new facts from this personally. So in that way it was effective. That said, I agree with you that Apple should be THANKING Google for bringing potential issues to them (no matter the intent behind it, even if in this specific case they already were aware of it).
- AgloeDreams 7y agoI'm sure they thanked in private, but once you start going to press with false information the good will is dead. The fact of the matter is that while Project Zero might be good for the general population; its most good for Google who stands to gain from bad press of their competitors.
- ijpoijpoihpiuoh 7y agoWhat information in the P0 blog posts on this topic was false or misleading? I read Apple's response, then I read the P0 blog post, but I don't see anything in Apple's response that actually rebuts anything that the P0 blog post said about this vulnerability. Apple says "Google’s post ... creates the false impression of 'mass exploitation' to 'monitor the private activities of entire populations in real time,'". But Google's post doesn't do that. Those sentences occur late in the blog post, and aim to educate about the risks posed by software vulnerabilities in general, not these specific vulns. That is abundantly clear from the text. The only way to get the impression that Google was doing otherwise is to merely skim the post. It seems like Apple is mostly annoyed that the press latched on to this, although honestly I question how much it matters since nobody seems to pay any lasting attention to these types of stories anyway.
- AgloeDreams 7y agoTimeline, Google said 2 years, Apple said 2 months.
- cromwellian 7y ago2 months for those particular websites. There's a difference between the timeline that a vulnerability existed, and the timeline of a specific known usage of them. Apple is trying to confuse the two. If I discover a security hole that's been present in Windows for 10 years, but only know of an active usage of it say, in the Ukraine by Russia, I'm going to say that the vulnerability is 10 years, not 2-months. 10 years is the length of time you could have been exposed. 2months, Ukraine, tells you how much more likely you were in danger for that location. But you should not act as if the vulnerability existing for 10 years didn't affect you, because you don't know about how many other people were using it.
- xvector 7y agoCompletely agreed. Security is a collaborative endeavor. Project Zero was not accusatory and did not over-hype the scope of the vulnerability. Project Zero is an amazing team that has only helped the state of security worldwide. Apple's defensive and accusatory response makes zero sense and goes against the very spirit of security today.
- pjmlp 7y agoPity that they miss Android bugs. https://arstechnica.com/information-technology/2019/09/android-zeroday-gives-hackers-a-way-to-elevate-attacks/ https://arstechnica.com/information-technology/2019/09/andro...
- monocasa 7y agohttps://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html https://googleprojectzero.blogspot.com/2017/04/over-air-expl... They have no problem covering Android bugs, they just don't write about bugs they didn't find.
- outside1234 7y agoThat just seems too super convenient to me. Why would they not laser focused on Android bugs? I suspect they are, but backchannel them to the development team, versus airing them.
- monocasa 7y agoThey're some of the top security researchers in the world and are given autonomy is why. Which is what the security community has settled on being the right incentive structure when optimizing for end user security.
- asveikau 7y agoIn the case of these recent iOS bugs, they didn't "air them" until after the fix was released. So any "back channel", if you could call it that, seems to exist for Apple too.
- Despegar 7y agoThere were subtle jabs at Apple in the original post.
- Wowfunhappy 7y agoWhat in the post did you consider to be "jabs"? Nothing read that way to me.
- itp 7y agoI agree! It felt like reading a (less egregious version of a) Trump denial, with the same impact -- no one cared before, but now it's a thing. As sibling points out though, we may just not be the target audience.
- smachiz 7y agoI disagree with your assessment here - mostly because you're implying that your views reflect the majority of people. You're reading hackernews, you're not an average iPhone user. The Project Zero announcement was sensationalized - press is good for them. It was then picked up and further sensationalized by large news outlets whose readers are nowhere near as technically literate as HN's audience is. They didn't understand what was being written other than "zomg, website can hax my entire phone and could've for two years, I assume all my data is on the darkweb". The nuance, and details were completely lost to an average iPhone user. Google has some responsibility when identifying flaws in consumer devices and software to be more clear about the actual impact, ramifications, and likelihood that your device was compromised.
- deleted 7y ago[deleted]
- akersten 7y ago> Google has some responsibility when identifying flaws in consumer devices and software to be more clear about the actual impact, ramifications, and likelihood that your device was compromised I don't think that's Google's job at all, especially for a competitor's product. Their project is to identify security vulnerabilities and disclose them to the public, in the name of public interest. We always have to assume worst case for security vulnerabilities, it's kind of the whole job of being a security researcher to determine what could have happened. Their job isn't to make Apple's users feel better. It's also not Google's fault that media known for being wildly off-base when reporting on technical news was predictably off-base again.
- smachiz 7y ago> I don't think that's Google's job at all, especially for a competitor's product. To be credible, it would be especially true for a competitors product. If you're even remotely insinuating that they can or should go softer on themselves than others, they're 100% not credible, and that would only make Apple's stance that much more legitimate. If they aren't at least as tough on themselves - and they should probably be tougher on themselves than others - it's just a marketing team. But I do think they have that responsibility. Disclosing flaws and vulnerabilities for consumer use cases requires nuance and less "just the facts, ma'am" otherwise you're actually doing more harm than good. The stories will be blown out of proportion, and the world will go numb to them. Because the little, low impact issues are constant background noise - when they get blown out of proportion and 0.000001% are affected, and 90%+ were patched 6 months ago, all this does is contribute to the noise, and doesn't improve the signal.
- olliej 7y agoI feel part of this is Google published a very large article about the iOS vulnerabilities, but did not do the same for the Android and Windows attacks that were also reported - just not by Google. Given Google has already gone down the "use our security posts to discuss competitors bugs but not our own", it seems entirely reasonable for other companies to start treating the PZ blog as a marketing tool.
- saagarjha 7y ago> Given Google has already gone down the "use our security posts to discuss competitors bugs but not our own" Project Zero finds and publishes bugs for most major platforms. Just look through their archives: https://googleprojectzero.blogspot.com https://googleprojectzero.blogspot.com
- olliej 7y agoYet this very large post detailed only the iOS vulnerabilities in the "large scale untargeted attack" that also had android and windows vulnerabilities. It does not take a genius to read that article and realize that the omission of the other targeted platforms was intentional.
- saagarjha 7y agoThey dropped five 0-day web chains against a platform where this was largely unheard of. I think this is significant enough for a blog post. FYI, Project Zero mentions when other bugs they find were found being exploited: https://googleprojectzero.blogspot.com/search?q=in+the+wild https://googleprojectzero.blogspot.com/search?q=in+the+wild
- simonh 7y agoHow many Google bugs have received the same volume of exposition as this Apple bug?
- saagarjha 7y ago
- simonh 7y agoThey’re trying to refute false information and unwarranted insinuations, and share factual context. It seems to me like this is all relevant information.
- gist 7y ago> a combination that does not make me sympathetic towards Apple Apple does not want sympathy and is not concerned with what someone in the tech community with advanced knowledge (and opinions) think. They are concerned with what is thought of them in the broader community that they sell to and that buy their products. This was the right thing to do. To point out what they could to clear up the issue. > When Google posted the Project Zero articles, that did not impact my view of Apple in any way. However this press piece affects my view of Apple negatively, so from my perspective this press article has turned a more or less neutral event into one that is negative. The vast majority of Apple customers not only don't know what Project Zero is or does but don't care. What they do care about is what is written in the mainstream media about Apple. And what the mainstream media digs up to stoke fear in order to continue to sell advertising. Apple did the right thing here. I was glad to read this info. I have been using Apple products since the 80's and computers prior to that (mainframes in college).
- snazz 7y agoI think they are fighting the sensational headlines and poorly researched mass media articles, not the original Project Zero post.
- endorphone 7y agoWhen Google posted the Project Zero articles, that did not impact my view of Apple in any way. Google claimed an exploit was being actively used for two+ years (with no evidence beyond a variety of versions being exploited, which could also simply be the targeting of different versions). They also added editorial narrative like "we'll see cases of code which seems to have never worked, code that likely skipped QA or likely had little testing or review before being shipped to users." They then obviously sideband released the group that was targeted, making it a big news story. Unstated was that the same sites had Android and Windows exploits on them. Project Zero is hugely valuable, but this was the first time it seemed like it became a marketing tool, using classic media release patterns for the biggest bang. Android is by far the most popular OS, with many serious exploits over its history (a 0-day privilege elevation just released by third-parties) -- does anyone remember Project Zero doing such an analysis of Android bugs?
- dwild 7y ago> Unstated was that the same sites had 0-day Android and Windows exploits on them. Have any source of that?
- endorphone 7y agoI was lazy in saying 0-day because details of them are not out (though coincidentally a privilege elevation 0-day was just revealed for Android). However reports are that any Android version was being used to report a comprehensive list of information about the device, and that there were Windows exploits as well. Which of course there was as presumably they'd comprise the vast majority of the targeted group.
- kllrnohj 7y ago> does anyone remember Project Zero doing such an analysis of Android bugs? Yes, many times in fact. So besides that "question" just being a terrible "Whataboutism" fallacy, it's also just wrong. From 2019 alone here's a handful of deep-dives into issues with Google software (well the last is linux but is done against Android specifically): https://googleprojectzero.blogspot.com/2019/03/android-messaging-few-bugs-short-of.html https://googleprojectzero.blogspot.com/2019/03/android-messa... https://googleprojectzero.blogspot.com/2019/04/virtually-unlimited-memory-escaping.html https://googleprojectzero.blogspot.com/2019/04/virtually-unl... https://googleprojectzero.blogspot.com/2019/02/the-curious-case-of-convexity-confusion.html https://googleprojectzero.blogspot.com/2019/02/the-curious-c... https://googleprojectzero.blogspot.com/2019/01/taking-page-from-kernels-book-tlb-issue.html https://googleprojectzero.blogspot.com/2019/01/taking-page-f...
- gatherhunterer 7y agoYour assessment is based on a feeling of doubt derived from behavioral queues rather than an objective analysis of the available facts. You have better information now because of this statement from Apple, there is no rationale for thinking less of Apple because of this.
- Spooky23 7y agoThey are in a no-win position and keeping silent is worse. Android security has always been a bit of a contradiction of terms, and while Google has improved the OS, the combination of limited availability of upgrades due to carrier nonsense and the state of apps on the platform. An Android zeroday isn’t news. The iOS defects are particularly jarring as they have been rare to date.
- mandevil 7y agoThis is not what Zerodium says[1]. They claim, and are backing it up with millions of dollars, that current Android exploits are more valuable than current iOS, because of a large supply of iOS issues. [1]: https://www.wired.com/story/android-zero-day-more-than-ios-zerodium/ https://www.wired.com/story/android-zero-day-more-than-ios-z...
- Spooky23 7y agoIn the article they discuss that it’s lkelly a publicity stunt.
- lern_too_spel 7y agoNo, it says they might be trying to influence market prices. Another researcher quoted in the article confirms that the market price for an exploit of a high end Android device is 30% more than an equivalent iOS exploit and gives Safari's poor security as the reason. Despite Safari having such a large attack surface, iOS cannot update it without a reboot, which only exacerbates the problem.
- mandevil 7y ago0dium's actual prices are likely a publicity stunt, but it says quite clearly, citing several different, independent sources, that attacks against a fully patched Android system are now worth more than the equivalent attack against a fully patched iOS machine. That is in part because Android has hardened up recently, Safari and iMessage in particular are highly vulnerable, and also because there was more money recently in iOS and so there was more attention on it. To a certain extent, of course, attacks against Android outside of flagship Samsung and Google phones are much cheaper- look at any patchset and attack, and given that 30+% of the Android user base is on Nougat/Oreo and 10% is on Kitkat or earlier as a whole they are far more exposed.
- danny_taco 7y agoTo me it does the opposite. It shows that Apple communicates and cares about security for their users. I don't see how them addressing and responding to Google's claims makes them appear in a worse light. To each his own I guess.
- radicaldreamer 7y agoIt's to assure government and enterprise customers that iOS is a secure platform and they need not worry.
- hmx48 7y agoNot only that, but it comes across as downplaying the incident because it "just affected Uyghurs"
- wankerrific 7y agoI know. What Apple should do is setup a crack privacy team to expose and publish all the ways the Android platform allows Google and third parties to collect data and generally invade privacy.
- AsyncAwait 7y agoThey should, everyone would benefit.
- wstrange 7y agoPretty sure the P0 team would love that. And maybe Microsoft spins up their own team. That would be fantastic for all involved.
- yellow_postit 7y agoMicrosoft does already, its the MSRC, but they take a different approach to disclosure: https://www.microsoft.com/en-us/msrc/cvd https://www.microsoft.com/en-us/msrc/cvd
- zelon88 7y agoIf I found a bug in your code and told you about it (responsible disclosure style), watched you fix it, help you validate that it was fixed, and then write a blog post about it that would be pretty predictable and reasonable. But waiting 6 months? To release an embellished piece about a non-exploitable bug that was patched 6 months earlier? 2 WEEKS before Apple unveils the iPhone 11 no less. And you all STILL downvote me when I post about how I believe PZ is a clandestine group of hackers paid to dig up zero-days on competing products so competitors can get bug-doxxed days before large/important events.
- thom 7y agoI'm very glad they published it because up until now I have been fretting over whether my phone was affected and whether I needed to reset every password in my keychain. As far as I knew until now, all iPhone users were at risk and Apple had secretly patched the affected devices without notifying anyone. I'm glad that doesn't appear to be the case.
- throw0101a 7y ago> What is Apple trying to gain by publishing this article? John Gruber's take: > Reading between the lines here, what Apple is pushing back on is the fact that Google’s report on this attack against the Uyghur [1] community only mentioned iOS. Coverage of Google’s report created the impression that only iOS users were hacked, when in fact, the Chinese government also exploited Windows and Android users, [2] and that these exploits may have been targeting people everywhere. * https://daringfireball.net/linked/2019/09/06/apple-pushes-back https://daringfireball.net/linked/2019/09/06/apple-pushes-ba... Though he does also comment: > Conspicuously unmentioned in Apple’s response: “China”.
- wintercharm 7y agoChina was also Conspicuously unmentioned in Google's / P0's original disclosure :P
- GeekyBear 7y agoTo me, the weird thing was that Google failed to mention that the hack was carried out by a by a nation state (China), and that it was narrowly targeted at China's often oppressed Muslim ethnic minority. Google also failed to mention that Android and Windows had been targeted by China as well. These omissions certainly leave me less sympathetic towards Google.
- mav3rick 7y agoRight, no respect for the work and effort they put in. Arm chair critics being "less sympathetic".
- GeekyBear 7y agoI certainly lost respect for them. If you want to discuss the exploit itself, that's great. If you are going to bring how it is targeted into the discussion, there is simply no excuse for leaving out the fact that this is a narrowly targeted attack from a nation state adversary who is also actively targeting your own devices. I don't know if their motivation was to harm a competitor or to avoid annoying China while you are hoping to resume doing business there, but they certainly left themselves open to both interpretations. If you don't intend to tell the truth, then it's better avoid bringing up the topic altogether.
- mav3rick 7y agoSo it's okay to not tell the world about the exploit in the first place ? If Apple posted this against Google you wouldn't say a word. You'd just be happy for Google to get bad press no matter what they do. This post made the world's iOS devices more secure. Have fun countering that in your head with "but but HN says Google is bad..."
- skywhopper 7y agoI'm going to guess the Project Zero article pissed some people off at Apple in a major way, because Apple is right that the headline and the content of the article vastly overstated several aspects about the vulnerabilities. The impression most people would come away with after seeing the headline and skimming the Project Zero article is that most iPhones have been compromised for years. That is emphatically untrue, and so I think it's reasonable for Apple to take a strong tone with this message.
- amazingman 7y agoSeems to me that they felt they had to respond to FUD reporting such as https://www.zdnet.com/article/apple-has-let-down-every-iphone-user/ https://www.zdnet.com/article/apple-has-let-down-every-iphon...
- thrwawsy454598 7y agoI totally agree with your reading of the tone and I was kind of floored by it. To me, it seems that there must have been a tempest about it that I (we) missed. What I mean is that it's extremely reactive, accusatory, and defensive, but in response to something that we aren't seeing. It can make sense if someone was running a huge news story about it, that we're just not in the audience for.
- sigzero 7y agoThe tone is matter of fact to me.
- partiallypro 7y agoGoogle has very conveniently used Project Zero to target its competitors, while omitting key facts about itself.