8 ms·
Apple patches CVE-2020-9859 (unc0ver)
- s010c011ab 6y agohm
- paypks 6y agounc
- based2 6y agohttps://www.macrumors.com/2020/06/01/apple-releases-ios-13-5-1/ https://www.macrumors.com/2020/06/01/apple-releases-ios-13-5... and for macOs https://support.apple.com/en-us/HT211215 https://support.apple.com/en-us/HT211215
- deleted 6y ago[deleted]
- Flockster 6y agoSee also from 8 days ago: https://news.ycombinator.com/item?id=23287364 https://news.ycombinator.com/item?id=23287364
- saagarjha 6y agoI think this might be the fastest patch of a security issue affecting Apple's operating systems, ever. Aside from *.0.1 releases that fixed critical bugs with core features in new OSes, has anything been patched this fast? (I'm also obligated to post that the bug that this fixes is not new; it was discovered back in iOS 11, fixed, and Apple reopened it in an iOS 13 update: https://www.synacktiv.com/posts/exploit/return-of-the-ios-sandbox-escape-lightspeeds-back-in-the-race.html https://www.synacktiv.com/posts/exploit/return-of-the-ios-sa...)
- saurik 6y agoI have a pretty clear memory of the JailbreakMe 2/3 bugs (which, for anyone else reading, were bugs that could be used from the web browser, and so were of the form "you click a link or have some evil iframe and are pwned") being fixed in six days (which I mentally cataloged as the minimum turnaround time Apple could muster).
- saagarjha 6y agoThat's a bit before I was using iOS, so I'll take your word on that one ;) AFAIK some system call filtering went into WebKit at some point to make this specific exploit unreachable from the web process, so I guess you could call it "less severe" than JailbreakMe was. That being said, I guess "zero day affecting all current devices" is probably good enough to get priority. (FWIW, heavily publicized non-security bugs often get quicker updates, sometimes within one or two days, which I assume pushes close to how quickly they can get a fix merged and through B&I.)
- why_only_15 6y agoThat syscall filtering still exists and broke a build for three or four days recently.
- saagarjha 6y agoIs this something that made it into the public WebKit sources? Would be curious to see the commit for that :)
- prvc 6y agoIf that doesn't illustrate their true priorities re: user security/ privacy, then I'm not sure what could.
- blinkingled 6y agohttps://twitter.com/s1guza/status/1266433756270866433 https://twitter.com/s1guza/status/1266433756270866433 This may also illustrate their priority to reintroduce the same bug and re-fix it at faster speeds to wow their fanbase. Or you know the priority may also be keeping the walled garden - walled? Also it might just be security response 101 - like every other major OS vendor out there depending on the bug. But yeah privacy and security for users that's a much nicer marketing pitch.
- api 6y agoJailbreaking is not a threat to the walled garden. The majority of users want the walls there to protect them from malware and crappy software breaking their device. The obvious market preference for managed devices that "just work" is lost on the HN crowd because most of us belong to a different market with different preferences. My reading is that this bug could potentially allow apps to install rootkits. The speed of the fix tells me maybe it's being exploited that way right now in the wild. BTW MacOS got the fix in record time too in spite of it being far less strictly walled than iOS. That supports my suspicion that this bug is being used in nasty ways.
- Thorrez 6y ago> Or you know the priority may also be keeping the walled garden - walled? That's actually what I interpreted prvc's comment to be saying. But I guess I might have misinterpreted it.
- Wowfunhappy 6y agoFrom the equivalent macOS patch: https://support.apple.com/en-us/HT211215 https://support.apple.com/en-us/HT211215 > Available for: macOS High Sierra 10.13.6, macOS Catalina 10.15.5 That's interesting—did the bug exist on both 10.13 and 10.15, but not 10.14?
- saagarjha 6y agoYes: it was fixed for that period and then rebroken for Catalina.
- vmchale 6y agoOh dear. My laptop is saying 10.15.4 is the latest. Huh.
- xerces8 6y agoSo, it is a bug in macOS or iOS? Both?
- saagarjha 6y agoFixes were pushed out for all four major platforms today, presumably as the affected system call is available on all of them.
- 0x0 6y agoIf it is true the bug was present in iOS 11 and fixed in iOS 12 before being reintroduced in iOS 13, that might align with macOS 10.14 (≈ iOS 12) being unaffected.
- baggy_trough 6y agoBe nice if they could patch a kernel bug in macOS with less than a 1.5GB download.
- andarleen 6y agoForces users to buy larger storage. Clever marketing.
- saagarjha 6y agoUpdate sizes has little to do with needing larger storage, especially on Macs.
- andarleen 6y agoDid your boss ask you to police hn against negative apple feedback?
- saagarjha 6y agoI currently don't have one, so…no? I do usually try to keep Hacker News clean of low-quality comments, though, which is fairly distinct from "negative apple feedback".
- andarleen 6y agoYeah people like you did a lot of work to hide apple’s planned obsolence in the past, wouldnt be entirely shocked if this was the case. Now you can apply for a job at apple showing what a good sheeple you are.
- dang 6y agoWe've banned this account for repeatedly breaking HN's guidelines and using multiple accounts to abuse the site. If you'd please stop doing that, we'd appreciate it. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- KenanSulayman 6y agoThe more interesting part is that unc0ver exploits a bug that was reintroduced by Apple: https://twitter.com/s1guza/status/1266433756270866433 https://twitter.com/s1guza/status/1266433756270866433 ..
- myko 6y agoI jailbroke for the first time in nearly a decade when unc0ver came out. It's actually pretty useful. I really love having the ability to use Flex on any app on my device.
- mangix 6y agoPhew. Just updated to 13.5. Good to know I'm good on the jailbreak front.