27 ms·
Disclosure of three 0-day iOS vulnerabilities
- smoldesu 5y agoI really wonder how different the mobile security landscape would look if researchers were treated seriously. This is a mistake that Google, Apple and even Microsoft (for the short time they made phones) all made, and now we have to live with the consequences of that. Along with your "post privacy" world, we may as well march this as the epoch of "post security". It just depends on how much someone is willing to spend to engineer one (or three) zero-days from your target's machine. This used to be feasible, but recent ransomware and surveillance malware has proven that it's commoditized now.
- bcook 5y ago>This is a mistake that Google, Apple and even Microsoft (for the short time they made phones) all made, and now we have to live with the consequences of that. What consequences are we living with?
- bottled_poe 5y agoFear of data leaks for one. That’s never going to be zero, but it could be a lot better than it is.
- krater23 5y agoI never thought that hacking like in Star Trek will be anytime truth. But it looks like we slowy head for it...
- b8 5y agoIsn't this why most researchers just sell their 0days to Zerodium or drop it publicly? I've heard of multiple companies doing this type of BS. There was a person called Polarbear/sandboxescaper who dropped a few Win10 LPE's on GitHub. They claimed that Zerodium also only pays out a small amount then resells the exploit.
- ianhawes 5y agoYes, that person did drop 0days publicly and then promptly faced an FBI investigation causing a tremendous level of stress and irreparable mental health damage.
- b8 5y agoIt looks like that they no longer work for Microsoft anymore. Weren't they making some not so great comments before the FBI investigation though?
- ryanlol 5y agoShe said all kinds of things that would trigger investigations, everything from threatening the president to searching for foreign state hackers to attack the US with her. Surprisingly MSFT still hired her after this
- ryanlol 5y agoShe faced a FBI investigation over the threats she was making during her rants, not because she dropped 0days publicly. It is not very cool of you to falsely insinuate that these things are related.
- google234123 5y agoThere aren't worth anything to Zerodium afaik
- b8 5y agoMaybe they would've been to ZDI.
- diebeforei485 5y agoThis is crazy. At this point it's pretty well established that Apple isn't really going to pay you much if at all. Might as well disclose in 90 days at this point.
- sneak 5y agoFull disclosure is always responsible, even if the vendor is not notified in advance.
- mrslave 5y agoThis is a part of our industry I do not follow beyond headlines. A lot of those headlines are about hackers trying to be responsible getting screwed out of supposed bounties that to my mind already appear quite small. Also responsible companies doing very little to quickly close them. Does anyone have any insight into how the market for vulnerabilities operates? Is there is a significant disparity in price between official/responsible disclosures and private sales?
- diebeforei485 5y agoPrivate buyers almost certainly pay a higher amount and their payments arrive much sooner. Apple's published rates are high (up to $1M), but in practice they pay a lot lower.
- eyegor 5y agoSo most public companies don't even run bug bounties. The ones that do may or may not acknowledge your disclosure, and they decide what your vulnerabilities are worth regardless of any scales they might post on a blog. So in a best case scenario, you get maybe 10-100k for a world ending RCE + escalation but most of the time you get no response or <1k. On the gray market, though, something like that will easily sell for over 100k, sometimes several million. Generally it's frowned upon in academic circles, but there are a handful of large brokers like zerodium who are happy to pay out for interesting bugs.
- 5y ago
- 58x14 5y agoThis is such an incredible amount of vulnerable mission-critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi and formerly, - medical info - device usage - screen time - device accessories I don't keep anything mission critical on mobile, but this is still a gargantuan set of exploits, and each appear extremely straightforward to validate and pay out the security researcher (and maybe even patch). It's utterly tragic how Apple (and others) have devolved to become the same monolithic, careless organizations they once displaced. I really, really hope something changes. Soon.
- hsbauauvhabzb 5y agoIf these are gargantuan, how would you describe a remote zero click complete device compromise (complete with camera/microphone access)? What about an exploit that can cause the users phone to explode?
- kbenson 5y ago> What about an exploit that can cause the users phone to explode? Possibly world ending, at least from the perspective of the user whose phone explodes next to their face?
- hsbauauvhabzb 5y agoI’m not saying the above issues don’t matter, but they’re hardly the most critical things you could do to an iPhone.
- klyrs 5y agoDo like GM, keep your phone at least 5 feet away from other phones while not in use.
- sam0x17 5y agoYou can do a lot more damage with someone's bank account than you can by exploding their phone.
- thatswrong0 5y agoExplain I'm naive: why would Apple's bug bounty program be so poorly run? Is it simply a sign of organizational failure? (e.g. perhaps the managers running the program have been promoted to a position that they simply don't belong in, and higher up execs don't care? Or are they prioritizing profit over success?) I would think that, given the profitability and positioning of Apple in the marketplace, that they would be heavily incentivized to provide large bounties for finding such destructive vulnerabilities. And I imagine that there are plenty of security people working there who genuinely care about fixing fix these issues right away.
- sam0x17 5y agoBug bounty programs are the antithesis of Apple's internal methodology, culture, and way of doing business. They keep everything close to the chest, they shun "outsiders", etc.. The idea that someone outside of Apple, from the unwashed masses, could find a flaw in Apple's own software is a pretty big pill for them to swallow. Thus it doesn't surprise me there are problems with their bug bounty program. I think if they could they would prefer to just silence all vulnerability/bug reports with a gag order rather than acknowledging or even investigating them.
- snuser 5y agothat's just dumb, like third parties do all the work and contact you about critical bugs the only effort on Apple's part of verification and some coordination which shouldn't be a huge issue for a company the size of apple.. just hire a team to do it and be done with it the whole 'secrecy culture' is a bunch of hogwash
- sam0x17 5y agoAnd yet here we are ;)
- jcims 5y agoI’ve worked on the bug bounty program for a large company. We did the whole thing. It’s hard. The part you’re talking about can be the hardest. Is probably less than believable to read because it sounds like it should be easy. I don’t have any good answers there. I’m also not suggesting that customers and researchers accept that, but saying it’s easy just diminishes the efforts of those that run good ones.
- fortran77 5y agoI wonder if the culture of leaking and dissent within Apple is enabling information to leak which assists the 0day authors?
- aetherspawn 5y agoIf your annual revenue is above $100M, you should be held accountable to a strict version of GPDR enforced by an ombudsman, that requires you to patch all data leaking vulnerabilities within 90 days, or pay out everyone who bought your product. I just updated to iOS 15 and it now tells you which sites you have been compromised on, or had your passwords/info compromised on. To be clear, I use a password manager with a unique password on every site, so it is difficult for something like this to have a significant impact. Nethertheless, I was compromised on hundreds of sites and products, and those were just the accounts that iOS Safari knew about. None of them bothered to reach out and tell me. Even my coffee machine was compromised. Ridiculous.
- whoknowswhat11 5y agoGod, I would HATE if the US follows the EU with this craziness. I'm already sick of the cookie popups, now layer on the GDPR insanity and we will definitely lose the privacy fight to users who will be sick of this nonsense as well. I've seen studies that show crap like GDPR (which makes basically all normal interaction cumbersome) has like 10% of folks clicking around to "opt-out" while 90% can't be bothered. And of course, you COULD just clear your own cookies. There is no more real security in the EU. Your mental health records will be leaked there. The EU will spy on you like crazy. And more.
- arvindamirtaa 5y agoIs there a point to this...? Or did you just want to crap on GDPR? Not saying it's good or bad. But just...relevance?
- cmeacham98 5y agoGDPR cookie consent banners that make it more difficult to opt out than opt in are illegal, and only continue to exist because the GDPR is poorly and inconsistently enforced.
- thatswrong0 5y agoMost of the cookie consent banners I see are illegal in that case..
- Cieplak 5y agoWhy must iOS use WiFi to run critical security updates? I assume it’s a kickback from telecoms to reduce network bandwidth from users with unlimited mobile data plans?
- deleted 5y ago[deleted]
- 542458 5y agoDoes iOS have any way of telling if you’re on an unlimited data plan? If not, maybe it’s just to prevent the footgun (and subsequent bad PR) of somebody accidentally updating the OS over an expensive metered connection. But it could also be a carrier demand, not really sure.
- rovr138 5y agoSettings > Cellular It shows my carrier, amount of data used and shows remaining on my plan. Mine reads, Usage: Used 7.43GB - Unlimited If I click on it it has 3 fields. Data, Calls, Messages Data reads the same here. Calls and Messages simply say ‘Unlimited’
- easton 5y agoMy phone does not have this (iPhone on 15.0 in the US, AT&T).
- rovr138 5y agoHuh, I’m on the US too, T-Mobile.
- shever73 5y agoMine doesn't have this either (Europe), and I have unlimited data too. I have a "Data Plan" setting under "Mobile Data", which is not activated, so I'm guessing that setting is only there if your provider gives you a data plan that Apple recognises.
- 5y ago
- tyingq 5y ago>com.apple.gamed I like the poetic nature of exploiting that one.
- alphabettsy 5y agoMaybe it's just me, but these aren't what I think of when I hear 0-day. These are serious, but I was guessing remote code execution or sandbox escape. It seems like we're talking about bypassing privacy controls though. That said, Apple needs to take this much more seriously. They created the program reluctantly and it shows.
- H8crilA 5y agoFYI, 0-day just means "first time made public".
- alphabettsy 5y agoCompletely aware of that. Just a weird perception thing for me.
- tinus_hn 5y agoIt means a vulnerability is made public while there is no patch available. As opposed to releasing the information a number of days after the patch was released.
- cjbprime 5y agoIt doesn't even really mean that anymore. From the blog post here: > I've reported four 0-day vulnerabilities this year They're just using 0-day to mean "a new vulnerability finding disclosed to the vendor privately", which is becoming the new definition of the term.
- gzer0 5y agoFrom an earlier post: This is a boat load of mission critical data. - all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi - medical info - device usage - screen time - device accessories
- alphabettsy 5y ago
- floatingatoll 5y agoIt must be nice to give up $100k by being impatient. I do understand that OP probably feels a moral reason to do so, but that $100k would be life-changing for me, even if it took 3 years to pay out.
- diebeforei485 5y agoThere is no $100K coming. Apple hopes you'll stay silent by dangling a hypothetical $100K (or whatever large amount) in the vague future. Once they've fixed the bug, they no longer have an incentive to pay you so they won't.
- FireBeyond 5y agoHaven't they done this in the past? "Oh thank you!" then "Actually we already knew about it and had a fix planned, so no bounty for you"?
- diebeforei485 5y agoYes. In some cases when they did pay, they paid significantly less than their published rates.
- moepstar 5y agoFrom the PoV of a security researcher - why even bother disclosing responsibly (moral obligations aside)? Best case scenario: you don't get sued into oblivion, will be ghosted and gaslightened, receive pocket change arbitrary amount of time later. Compared to that, i suppose the exploit brokers got their stuff together - after all, time is money - chances are someone else may stumble upon the same vulnerability...
- floatingatoll 5y agoIf the payout is higher priority to you than the ethics of selling an exploit that governments around the world will end up using to hunt and capture or kill political dissidents, then you are of course free to sell it on the exploit market :) I prefer to sleep at night, though.
- MrGando 5y agoObscure ad-tech companies would love to get those installed apps like they were aggressively doing (Facebook & Twitter too) about 5 years ago.
- asteroidbelt 5y agoFacebook and Twitter exploited 0-day security vulnerabilities to collect private data? Can show the proof link please?
- robterrell 5y agoI believe the poster was referring to the practice of testing if an app was installed by calling [UIApplication canOpenURL:] —- as I recall Twitter was found to check for hundreds of different apps, to feed into their ads and analytics business, and Apple later changed it to only be callable 50 times.
- jonahx 5y agoAre there any partial mitigations you can take until these are patched?
- babesh 5y agoDon’t update your apps till after Apple releases a patch. The first two are API calls that apps can make. An exploit wishing to exploit these vulnerabilities has to be coded to make these calls. Most apps don’t dynamically construct arbitrary API calls. In fact, you can’t do that in Swift AFAIK. You have to drop to Objective-C or C to do that. So most apps need to be updated to exploit the vulnerability. The only exceptions would be apps that are intentionally constructed to call arbitrary APIs or at least with arbitrary parameters. The first would be a violation of developer agreements but that hasn’t stopped people in the past. Also, these aren’t even private APIs. These are public APIs that got exploited due to not properly checking parameters/entitlements. I wonder if Apple isn’t running static analysis tools right now to look for these vulnerabilities against all apps.
- saagarjha 5y agoIt’s pretty trivial to encode a backdoor into your app that would let you remotely call native code of your choice.
- yccs27 5y agoI guess this is the reason Apple restricts apps from executing downloaded code.
- saagarjha 5y agoThis is without downloading additional code. Reuse attacks such as ROP, or you could just embed an interpreter with the ability to alter native register state. It’s not hard to get Turing completeness into your app in a way that lets it call whatever it wants.
- 5y ago
- rkagerer 5y agoGood on you. I'd be happy to make a small contribution to your legal fund if Apple tries to send lawyers after you. Even if these vulns weren't critical there's no excuse for their inept handling. Thank you for pressuring them to get their act together.
- JoeOfTexas 5y agoThe problem is that cybersecurity is ridiculous hard problem. The junior to senior developers are just using existing frameworks with poor documentation. Any consumer technology will be beaten to submission. It's the same never-ending war as anti-cheat vs cheat.
- hungryforcodes 5y agoYou know, I'd love to think that the problem is cyber security is hard -- which it IS -- but I'm starting to get the feeling that the actual problem is that Apple doesn't care about this kind of stuff. So many incredible vulnerabilities going back generations of iPhones and iOS...the zero click iMessages one floored me.
- tyrfing 5y ago> the zero click iMessages one floored me. In case there is any confusion, there has been at least one of those a year for the past 3 years.
- easton 5y agoWhat is dumb about it to me is that the solution in my mind is simple: don’t give Messages.app private API access. They get access other messaging apps from the App Store can’t have and that’s what’s causing these vulnerabilities, but all they need is APNS and access to the SMS service (which is private but shouldn’t be dangerous… right?).
- kenferry 5y agoThis last one was an issue in an image decoding.. it was public API. It’s extremely common for an attacker to find a way to exploit a maliciously crafted image. Take a look at libpng, https://www.cvedetails.com/vulnerability-list/vendor_id-7294/Libpng.html https://www.cvedetails.com/vulnerability-list/vendor_id-7294...
- emsy 5y ago
- Thorrez 5y agoProps to the author. One small critique though: > I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7 It would have been clearer if in each of the 4 vulnerabilities the timeline was given. The article only gives a timeline for the last vuln (the fixed one).
- idoubtit 5y agoThe second sentence of the article gives a sufficient timeline. > I've reported four 0-day vulnerabilities this year between March 10 and May 4 So the vulnerabilities were reported at least 140 days ago. He also mentions 3 upgrades of iOS were published after his reports.
- Thorrez 5y agoYeah, I quoted it myself. My point is that the article is formatted in a confusing way. It's formatted into 4 vulnerabilities, but only 1 of them has a timeline, which immediately made me wonder why there weren't 3 more timelines. Even though I read the sentence at the beginning saying the author reported all 4 to Apple, when I saw there was a reporting timeline on 1 vuln but not the other 3 I started doubting my own memory and thought maybe the author only reported 1 vuln to Apple. I had to go back and re-read the first paragraph again to reassure myself that all 4 were reported to Apple.
- illusionofchaos 5y agoI've updated the article to include a timeline for each vulnerability
- Thorrez 5y agoThanks!
- Bellamy 5y agoAll the hard working security researchers are this much appreciated by the rotten Apple.
- filoeleven 5y agoDoes this rise to the level of a class action lawsuit? Especially if I theoretically started receiving spam texts with more personal info (my name, contacts’ names) in them starting about seven hours ago? I haven’t, I’m just curious.
- r00fus 5y agoAt some point Apple has to realize their bounty program as its currently being run is tarnishing their privacy branding.
- tumblewit 5y agoI really hate the path Apple is taking. They make excellent products, really the average Joe simply loves Apple products. But they need to stop acting anti-consumer and anti-developer to “protect” their IP. At this point they could release the schematics of iPhone 13 and still people will buy Apple’s iPhone than someone who copied them. Rant over.
- someguydave 5y agoActually, these vulnerabilities are good evidence that Apple does not make excellent products.
- xyst 5y agoProbably means they make "good looking" products. But underneath the hood, it's spaghetti.
- neha1989 5y agoApple might have left these vulnerabilities for Pegasus like softwares including the sotfware used by FBI and other agencies.
- samhw 5y agoI don't know why you're being downvoted. My mind immediately went to this, given the relative obviousness of the exploits (compared to the massive supercomputer fuzzing runs done by Project Zero &c), and given their refusal to either document or fix these serious vulnerabilities in several releases.
- throwawayswede 5y agoAs bad as this is for people who use iOS, I think it's good in the long run. People here are getting boggled down in details about how is it possible for this to happen and what sort of policies apple has internally for it to be possible, but that doesn't really matter. Any company even 10% the size of APple should not be given the benefit of the doubt because obviously they'd all prefer not to have the major/minor embarrassment, if they can. Bounty programs exist not because they care about security of their customers only, but it's also a way to promote the company as security-conscious and avoid having 0days sold on the black market. But to overcome this you can just continue publishing 0-days straight to the public. Put really easy to use sourcecode on github/bucket/srht/etc... allowing script-kiddies and copy-pasters to make use of them easily. This will either drive people to lose trust or force Apple to scramble to release fixes, either way it will push them to respect researchers and fix their bounty program or setup better security guidelines in general. Props to the author for following through and releasing.
- speedgoose 5y agoWhy anyone at Apple decided that it was acceptable to log medical data in such an unsafe way? I currently work in an IT health care company in Europe, and we must alway store the data fully encrypted with strict access control. We even decided to not make sure to not persist any medical data on user devices to not take unnecessary risks. And there, Apple logs everything on the iPhone? Why?
- saagarjha 5y agoIsn't it better to persist medical data on the device rather than putting it on Apple's servers?
- jonathanstrange 5y agoWhat's funny about it is that apparently some of their WatchOS/device combos have FIPS 140-2 and FIPS 140-3 certifications. Pretty useless security theatre if you then shuffle the data around to other operating systems or into arbitrary servers with complex infrastructures.
- cybrox 5y agoNot if your API design is so bad that any third party can access them, apparently. Aside from that, I'm pretty sure they'll also get stored on their servers, if you have not declined all the nagging iCloud sync requests.
- evercast 5y agoI have some doubt with respect to whether what author claims is "medical data" is indeed medical. Practically speaking, the data he mentions seems like the things collected by Apple Watch and stored in the Health app. There is indeed heart rate tracking, but can we really label this data as medical? IMHO "medical" would relate more to professional diagnosis, treatment etc. which according to Apple is stored in an encrypted form [1]. Garmin devices also collect heart rate, sleep stats etc. and I have never thought of these as medical (health-related yes, but not medical). The line is thin though. Since you work in the industry, perhaps you could share your opinion how such data should be treated? [1] https://www.apple.com/healthcare/health-records/ https://www.apple.com/healthcare/health-records/
- devwastaken 5y agoOne more reason why "closed systems" are not magically superior. Closed systems still have vulnerability, and the culture that creates and maintains the closed system shuns those that find flaws in it. So much so that security researcher becomes, in their minds and practices, synonymous with black hat actors. Why would you report vulns to a company that doesn't want it? Go sell it elsewhere and use that money to get a better device. Yet researchers persist, for the good of secure technology.
- xyst 5y agoApple is going downhill. It's amazing how a trillion dollar company can't even get this right. Wouldn't be surprised if the IS&T group is running the bounty program. Probably offshored to hell at this point.
- soheil 5y agoHas anyone on HN been able to run any of these 0-days to see if they work on their device?
- ntSean 5y agoYep, here is a thread which has screenshots on the latest iOS update: https://twitter.com/keleftheriou/status/1441252412061204486 https://twitter.com/keleftheriou/status/1441252412061204486
- jacquesm 5y agoIf Apple can't handle properly disclosed vulnerabilities on their main revenue generating platform what does this say about other companies? Nothing good I'm afraid. Meanwhile the contact list on my dumbphone is perfectly safe. Time and again that's been proven to be the right decision, convenience seems to trump security in the eyes of many but I just don't want to give this up until there is a 'cloud free' smartphone.
- desertraven 5y agoWould you consider something like the PinePhone once it’s a bit more usable?
- jgilias 5y agoI realize you don't mean it that way, but this comes off as a bit 'whatabout-ish'. It doesn't say absolutely anything abut other companies. It just says that Apple doesn't take security nearly as seriously as their Marketing and Sales department would want us to believe.
- matbatt38 5y agoDumb phone might just be backdoored as well, how do you trust it? Do you have an open source dumb phone?
- ChuckNorris89 5y ago> If Apple can't handle properly disclosed vulnerabilities on their main revenue generating platform what does this say about other companies? It doesn't say anything about other companies, it just says that Apple doesn't give two shits about relationships with security researchers, despite their massive resources and wealth even when smaller or FOSS teams do much better. Apple are the king of user experience which made them insanely wealthy but that's about it. In every other respect they are anti-consumer, anti-developer, anti-reparability, anti-researcher, anti-openness, anti-standardization AF and act like major a-holes in general to anyone outside their org who isn't a customer. It's not that Apple can't be better on the other fronts if they actually wanted to, it's that they actively choose not to be, as that has no impact on their stock price or consumer experience and in consequence to their executive pay. So why do things differently if people still buy your products? At this point, I wouldn't be surprised if the "Apple is more secure and has less vulnerabilities" moniker just stems form researchers getting tired of dealing with Apple's BS of not acknowledging or paying them, so instead they just keep quiet and sell the 0-days they find on the exploit markets (hard working honest researchers still need to eat and pay rent) only for those exploits to later end up in the hands of shady companies like NSO or nation states, therefore leading to no news in the mainstream media about Apple related vulnerabilities. Win-win for Apple I guess.
- eurasiantiger 5y agoI am seriously considering throwing my $800 phone at a concrete wall.
- Ansil849 5y ago> My actions are in accordance with responsible disclosure guidelines (Google Project Zero discloses vulnerabilities in 90 days after reporting them to vendor, ZDI - in 120). I have waited much longer, up to half a year in one case. "Responsible" disclosure guidelines only benefit corporations. They do not protect consumers. Why should independent researchers - working for free, no less (and sorry, the well-below-minimum-wage pittance that is most bounties does not count as not working for free) have to cow tail to corporate guidelines? If you find a vulnerability, do everyone a favor and disclose it immediately. This places pressure on the corporation to fix it immediately, instead of ignoring it indefinitely.
- samhw 5y agoFYI, it's "kowtow", not "cow tail". Also, it's "This makes it immediately available to exploit before a fix can even _theoretically_ be developed", not "This places pressure on the corporation to fix it immediately".
- jupp0r 5y agoThanks to @illusionofchaos for sticking to responsible disclosure and putting themselves under legal risk for the benefit of Apple's users. Who knows if any of these are exploited in the wild already (Pegasus, etc) and by whom.
- lisper 5y agoAfter the disclosure of the last critical 0-day, I went to update the OS is my four iDevices. I upgraded three of them to iOS 14.8 with no trouble, but when I went to update the fourth it wouldn't let me update to 14.8 but rather only offered me the option of upgrading to 15.0. I didn't want to upgrade to 15.0, so I called Apple support and the first-line tech said, "Oh, I can definitely help you with that." I thought to myself that I'd give long odds against, but let's wait and see. Long story short, the matter has now been escalated two levels and is still not resolved. Funny side-story: at one point the first-tier tech suggested I try upgrading the phone using iTunes. iTunes has not existed in MacOS for quite a while now. The way you talk to iDevices now is through the Finder (which actually makes a lot more sense), but apparently their tech support didn't get the memo. Apple used to be the company that made devices that were secure and "just worked". Now they are as bad as Microsoft in the bad old days, and no one makes computers that "just work" any more. :-(
- Ansil849 5y ago> Apple used to be the company that made devices that were secure and "just worked". This is a complete myth. In fact, not only did Apple devices break all the time, but they were near-impossible for regular users to repair on their own. A simple proof: how many broken iPods did people used to have lying around?
- lisper 5y ago> This is a complete myth. No, it isn't. Snow Leopard was awesome. Mavericks was also pretty solid. In fact, I'm still running that on my machines today.
- Ansil849 5y agoYes, it is. Snow Leopard and Mavericks are not devices. The quote I am responding to is: > Apple used to be the company that made devices that were secure and "just worked". Unless your first generation iPod still works wonders.
- PostThisTooFast 5y ago"O-day?"
- chewyfruitloop 5y ago0-day ... what they mean is .... I found an issue. Its hardly a 0-day, they've not posted any evidence of it actually being used in the wild, just that "it can be used". Why is a normal "ooh look a bug or two" all of a sudden hair on fire world is burning news.... oh yeh ... I get more attention this way by exaggerating Apple may have a terrible bug bounty and response process ... but call a spade a spade ... I saw a bird this morning ... help theres dinosaurs on the loose!!!!
- breakingcups 5y agoWhat is your definition of 0-day? Because they are exactly right, this is a 0-day. Whether it's already actively being exploited or not has no bearing on the definition. I'll refer you to https://en.wikipedia.org/wiki/Zero-day_(computing) https://en.wikipedia.org/wiki/Zero-day_(computing) to make up your own mind.
- chewyfruitloop 5y agonormally I'd define it as something found in the wild being exploited already ... not a bug thats been found, reported and "ignored" this seems to be a zero day just because Apple haven't seen fit to respond the the reporter
- samhw 5y ago> normally I'd define it as something found in the wild being exploited already Yeah, but ... that's not what it means. You can choose to define "spoon" as "fork" too, but I don't see how it's useful to go around complaining about other people using the actual definition of the word.
- ksml 5y agoA zero day is a zero day, regardless of whether it's been exploited in the wild. There's a decent chance that well-funded bad actors have already found these, and you have no idea whether they've been used or not.
- xvector 5y agoI suspect when Apple doesn't want to pay the bug bounty, they just ignore it.
- xvector 5y agoWith such a successful privacy marketing campaign, Apple doesn't really need to care about security anymore to make boatloads of money. The public is mislead into thinking iPhones are secure and news outlets won't report on these minutiae.
- ThePhysicist 5y agoCan Apple retroactively identify apps that might have exploited these vulnerabilities to exfiltrate personal data? In my understanding they receive the full source code of an app for review, so they probably have an archive with all revisions that they could go through using automated tools to identify exploit code? Would be good to know if these exploits have been used in the wild, being able to exfiltrate the entire address book without any user involvement whatsoever is quite scary.
- brigandish 5y agoIt would probably take the exploitation of a security hole in Apple's systems to find out, as they clearly have no desire nor incentive to do this. Is it odd that I'm now hoping this might happen while also hoping for them to start patching up security holes? Edit: typo
- sumedh 5y ago> In my understanding they receive the full source code of an app for review I did not know that, is that even legal that Apple gets to look at your IP.
- saagarjha 5y agoApple doesn't get your app's source code when reviewing it, they just receive the binary.
- 0x0 5y agoThere is no way they could prove that an app HASN'T exploited this. They don't get source code, only compiled binaries, and with objective-c's extremely dynamic nature, any app could technically receive a HTTP response containing strings containing class and method names to dynamically look up and invoke, maybe even based on the app's IP address or only on specific dates. So calls to these exploitable APIs could have happened and there would be no way to prove otherwise.
- illusionofchaos 5y agoFurthermore, no one stops you from developing an app and planting RCE vulnerability inside the binary. Then you can exploit it remotely when necessary and execute the code that exploits any iOS vulnerabilities known to you.
- xpuente 5y agoSecurity through obscurity is a very bad idea. This is the main Achilles heel of Apple.
- ls65536 5y agoObscurity and secrecy seem to be so ingrained in the Apple culture that I don't see this changing anytime soon short of some kind of existential crisis or a major threat to a substantial amount of their revenue. And even then it isn't likely to be easy to turn the tide. Right now we see these negative externalities of security vulnerabilities being "paid for" by their customers, in the vast majority of cases seemingly unwittingly, but that can only go on for so long before it backfires (even if it's a long time).
- aguasfrias 5y agoThat contact and messages access exploit is quite neat. Some might say it even looks straightforward. I can only assume this is the "private API" that darkly patterned apps use, because it looks that obvious.
- omnicognate 5y ago> medical information (heart rate, count of detected atrial fibrillation and irregular heart rythm events) > menstrual cycle length, biological sex and age, whether user is logging sexual activity, cervical mucus quality, etc. Wat? How, and under what circumstances is it collecting stuff like cervical mucus quality?? Edit: ah, maybe I misread - it's "whether the user is logging cervical mucus quality" I think. Still, wtf?
- GoToRO 5y agoYou need to select female under health.
- omnicognate 5y agoI don't have an iDevice. Is this a built in health app or an API for apps to record stuff?
- saagarjha 5y agoThe Health app stores all this data and third party apps can ask to record to this database.
- kybernetyk 5y agoAt least the Game Center one is something an app developer could easily stumble upon. I don’t want to know how many apps are already exploiting this.
- illusionofchaos 5y agoThat's exactly how it happened for me. I noticed that when an app logs into Game Center, the notification is shown inside the app, and not in a remote process like when you choose contacts of compose an email. That led to easily discovering everything else.
- WA 5y agoI'm wondering how the health-data incident works with respect to the GDPR. Apple says it stores Health data in a protected way on the device. In reality, health data is leaked through logs and can be accessed by any other app. It is impossible to tell whether or not this data has been accessed in the wild. Since Apple failed to implement their claimed security features properly and you need to assume exploitation by apps in the wild in the worst case, this would require a disclosure to GDPR authorities. Did they do it? Were they fined yet?
- evercast 5y agoAccording to my understanding of GDPR, the data would need to contain personal information i.e. something that allows you to link it to an identifiable person. Quick search on google gives the following definition of personal data [1]: "Personal data are any information which are related to an identified or identifiable natural person." So if there is no personal data in the logs, it should not be a GDPR breach. [1] https://gdpr-info.eu/issues/personal-data/ https://gdpr-info.eu/issues/personal-data/
- cybrox 5y agoNot sure how far fetched an accusation can be in this case. If the data is accessible in plain text on a device that is clearly linked to an identifiable natural person, which is data that an attacker can easily access, the point of "just this one log file not containing the data" is pretty much mute. Would be an interesting case.
- WA 5y agoIt really is interesting. Apple could potentially claim that they didn't connect Personally Identifiable Information with the leaked health data, but a third party app, which gathered that data, did. Depends on what exactly was in the logs. Did it contain my emergency contact from Apple Health? Or my own contact data? That would be bad.
- illusionofchaos 5y ago
- solarkraft 5y agoI get happy about iOS security vulnerabilities, because they allow users to mess with the software of the device they own through jailbreaking. Hopefully one of these will end up in a jailbreak.
- raman162 5y agoUnfortunate that this researcher, shame on apple for not handling these vulnerabilities quickly. I used to believe that iphones were more secure than android and was considering making the switch. After reading this article and with some other recent news (CSAM[1], spam on the app store[2]) I don't think I'll be hopping on the iOS train anytime soon. [1]:https://www.apple.com/child-safety/ https://www.apple.com/child-safety/ [2]:
- tonmoy 5y agoWhile Apple's recent behavior does seem bad, I'm personally wondering if there is some quantitate measure comparing iOS/Android before I make the opposite switch. I wonder if iOS still may be more privacy friendly compared to alternatives regardless of the recent issue (I genuinely have no clue)
- raman162 5y agoIMO, that seems like apple but the lines are getting closer than ever
- jgimenez 5y agoI think they're at least trying! All the vulnerabilities mentioned can be found with static analysis, which Apple is doing before accepting an app into the store. I'm pretty sure if you pack one of these 0-days in your app, it will get rejected. So as for now, this is a theoretical exercise, unless proven that this code has actually been shipped to the store.
- illusionofchaos 5y agoIt can be shipped, static analysis is easily bypassed, you can check it yourself on gamed exploit
- raspasov 5y agoI am not able to compile the first two of these (after the first two I stopped trying) with the newest Xcode on iOS 15.0. I haven't tried the other two or older tools. The source code as given also had syntax errors in it.
- tonmoy 5y agoJust curious, what kind of compilation error are you getting?
- raspasov 5y ago'init(machServiceName:options:)' is unavailable in iOS
- illusionofchaos 5y agoThis is just a check built into Xcode to try to keep you from accessing XPC in iOS. The code on GitHub bypasses this by calling this method dynamically through Objective-C runtime
- larsnystrom 5y agoThis makes one question whether there really are any security vulnerabilities at all. Perhaps Apple isn’t fixing these because there’s nothing to fix? I don’t know enough to say whether these vulnerabilities are real or not.
- meibo 5y agoInteresting to note: these exploits aren't caused by memory safety, like a lot of other Apple exploits, but by plain API abuse and bad design.
- jareklupinski 5y agothat's why these were "Wontfix: Working Poorly as Designed" :^)
- gargs 5y agoUnfortunately, the fact of the matter is that the only way for Apple to recognize a problem is to have a lot of news and influential tech media cover it.
- frankfrankfrank 5y agoUntil we understand and push through a system (whether law or practice) that makes harming others, especially against their will and intentionally, far more costly than the massive returns and profits they today produce, NONE of these kinds of behaviors will ever cease. The examples are numerous; * Violation of human right to privacy and property * Violation of human right to not being tracked * Illegitimate wars * Pollution * Drugs (legal and illegal * Government incompetence * Siphoning off potential and sabotaging developing countries through human resource poaching called "immigration" * The fed fraud * Government theft and fractional enslavement through taxation * More fraud through inflation * Yet more fraud trough money "printing" * And for emphasis; being "secure in their persons, houses, papers, and effects, against unreasonable searches and seizures" (and no, that does not only apply to the government) ...and probably many more that I am forgetting are all immensely profitable activities that damage and destroy and defraud large numbers of people while providing immense profits and benefits to a very small set of people who are also the most powerful. You may disagree with what I have to say, but fundamentally regardless of which set of things you do and don't support all have an underlying mechanic that they defraud everyone while immensely profiting a parasitic ruling class, and that applies to both the things you think are good (e.g., immigration) or bad (e.g., wars). The parasitic ruling class has us squabbling over meaningless crumbs while they are bursting from picking our pockets and exploiting us as they always have, even if their con and lies have changed over time.
- sul_tasto 5y agoI’m convinced that the modern role of US political parties is to simply keep the masses squabbling. I wish we could get rid of gerrymandering and the two party dominance.
- wslack 5y agoUnfortunately, the Supreme Court decided 5-4 that the courts should have no power here, so its up to state legislatures. (https://www.npr.org/2019/06/27/731847977/supreme-court-rules-partisan-gerrymandering-is-beyond-the-reach-of-federal-court https://www.npr.org/2019/06/27/731847977/supreme-court-rules...)
- 1vuio0pswjnm7 5y agoWith these Apple-related vulnerability annoucements on HN, usually we see response from a satisified Apple owner along the lines of "This is fixed in [some new version number]". The thing is, the problem isnt whether something is fixed, its that it was broken to begin with. It passed "QA" at a trillion dollar company and its a pre-installed fixture^1 on some relatively expensive hardware item. If there is such an "it's fixed" response, it usually rises to the top comment. The underlying message seems to be, "No worries. You can safely forget about this and keep loving Apple hardware running the crappy but user-friendly, irremovable (work-in-progress) software that comes pre-installed on it." How long till this "It's fixed" comment appears. Might come in a different submission. For some folks, Apple can do no wrong. No amount of truth can change their views. The only issue to these folks is "fixing"; they are content to use software that is a WIP but marketed as ready for primetime and to dismiss any ideas about using software that is considered finished. The best place for important data is external media not a "smart" phone running an OS and software that the user does not have control over. "Everyone else is doing it" doesnt transform a stupid practice into a smart one, it just means no one will criticise the choice. That of course also opens the door for those following the herd to attack anyone who dares to suggest deviating from the mainstream because "how can the majority of people be wrong". 1 The purchaser cannot remove it and install their own replacement.
- Mindwipe 5y agoThat would be a nice problem to have. No, the issue is despite disclosure two of them still aren't fixed.
- zibzab 5y agoConsider also time of introduction (of the vulnerability) to time of patch. We have now seen bugs that have been around for 4-5 years before being discovered by ethical hackers and subsequently patched.
- azinman2 5y agoNo os/mobile platform is free of security bugs. No amount of “QA” will be enough. Just look at the number of vulnerabilities literally any OS has, or even any component such as Chrome or Safari. It is a shame that the author didn’t get replies in time and felt the need to disclose. I’m sure it’ll at least get quickly patched now.
- jimmont 5y agoTechnology today on the software side is broadly at the place medicine was with elixirs and potions. Given the variability in medical practice across the US maybe it's still a prevalent pattern in different form.
- raspasov 5y ago100%. Perhaps medicine is not that far ahead either. There's a a number of drugs (esp. the ones that deal with the brain) where we observe the effects but the mechanism of action is not well understood.
- davewritescode 5y agoI'm not defending Apple but looking at the code published here, it's clear that most, if not all, of these bugs could be caught via static analysis which Apple obviously uses as part of its approval process. Frankly, I'm a lot more concerned with bugs that have to deal with input handling than SDK bugs that developers can use to do bad things. This is likely a non-issue for those of us who haven't jailbroken our devices.
- quotemstr 5y ago> of these bugs could be caught via static analysis which Apple obviously uses as part of its approval process. What? Are you suggesting that OS security bugs are in fact non-issues because static analysis can detect programs that exploit these bugs? No, it doesn't work that way. You can always encode program logic in a way that will defeat static analysis. All you have to do is write a little interpreter with PEEK, POKE, and JUMP opcodes, then encode your actual exploit logic using the little instruction set you've just created. You can make this sort of indirection as elaborate as you want, and there's no way for static analysis to see through it all. When this kind of technique is used for DRM, it takes months of expert human analysis to figure out what's going on. No way some scanner is going to do that, especially if (unlike in the DRM cracking case) there's no clear indication that there's something to discover and decode in the first place.
- kif 5y agoIf Apple allowed a jailbreaking application make it to the App Store, then I do not trust their processes to not fail again.
- illusionofchaos 5y ago> static analysis which Apple obviously uses as part of its approval process This analysis is a joke, it just scans strings inside binaries against the list of symbols corresponding to what Apple considers to be Private API. Gamed exploit can be uploaded to the App Store and binary will pass their analysis with flying colors
- annoyingnoob 5y agoIf Apple will not do the ethical thing then why should people try to help them? I say give Apple 30 days and then sell it to someone else. Let Apple live their own reality.
- Amin699 5y agoThe vulnerably allows any user-installed app to determine whether any app is installed on the device given its bundle ID. XPC endpoint com.apple.nehelper has a method accessible to any app that accepts a bundle ID as a parameter and returns an array containing some cache UUIDs if the app with matching bundle ID is installed on the device or an empty array otherwise.
- zibzab 5y ago> ... one was fixed in 14.7, but Apple decided to cover it up and not list it on the security content page. When I confronted them, they apologized, assured me it happened due to a processing issue and promised to list it on the security content page of the next update. There were three releases since then and they broke their promise each time. I think this is 100% intentional.
- resist_futility 5y agoJust looking at the readme sample code it appears to be using APIs unavailable in iOS, so where is the vulnerability?
- illusionofchaos 5y agoIt's just marked as unavailable. Apple does that to try keeping people from using XPC on iOS. Use the full code from GitHub, it has a bypass for that Xcode check
- resist_futility 5y agoUnless they have evidence of it getting past Apple and into the App Store, just doing it dynamically doesn’t change anything
- illusionofchaos 5y agoIf you have a developer account that you are willing to sacrifice and don't mind the possibility of legal action, you can try that. I've managed to upload the binary built from the source code from gamed exploit repository on GitHub to App Store Connect and installed it onto my own device via TestFlight. I didn't submit it for review, but if the functionality would have been concealed, it would easily pass. As far as I know, how the review happens is that reviewers just install apps onto their iPads, tap through all the screens they can find and make their decisions based purely on that. So if an app connects to server and asks what it should do, it's possible to make an app behave differently for reviewers and all other users.
- exabrial 5y agoBug Bounty programs represent everything Silicon Valley hates: Interaction with customers and relationship management. They are _forced_ to actually communicate and respond to people and can't get away with just treating them like cattle.
- mensetmanusman 5y agoImagine an iMessage 0-day 0-click worm that disabled every iPhone for a month…
- Areso 5y agoThe story continues: https://news.ycombinator.com/item?id=28672680 https://news.ycombinator.com/item?id=28672680 https://habr.com/ru/post/580272/ https://habr.com/ru/post/580272/ (TL,DR: Apple says 'thank you' and did nothing once again)