3 ms·
Is there a timetable when Apple plans to stop using memory-unsafe languages to avoid memory-bugs? If not, how can the amount of zero-days stop with constant dev
by DelightOne 5y ago
Is there a timetable when Apple plans to stop using memory-unsafe languages to avoid memory-bugs? If not, how can the amount of zero-days stop with constant development?
- DyslexicAtheist 5y agobiggest issue here isn't memory safety but the dumpster fire of imessage format that calls out to privileged parts of the system
- vlovich123 5y agoWhich is exploitable primarily it by memory safety exploits. Will it make attacks impossible? Probably not totally. But it might raise the cost of the attack by an order of magnitude or more and certain classes of vulnerabilities might disappear completely.
- walrus01 5y agoI'm suspicious of any messaging system that has ties into rich media / embedded-in-chat content. I even wish I could disable URL previews, gifs, and inline images in Signal.
- elliekelly 5y agoI didn't know it was possible to disable URL previews in iMessage[1] until I read this comment. Does toggling this setting only prevent the preview from displaying or does it prevent the fetch altogether? I wish there were a way to white list the URL previews for certain contacts rather than turning it off all or nothing. [1]https://discussions.apple.com/thread/7677834 https://discussions.apple.com/thread/7677834
- kingcharles 5y agoIt can be your "trusted" contacts that infect you though. "Jeff Bezos was hacked by a file sent from the WhatsApp account of the crown prince of Saudi Arabia, Mohammed bin Salman" https://en.wikipedia.org/wiki/Jeff_Bezos_phone_hacking https://en.wikipedia.org/wiki/Jeff_Bezos_phone_hacking
- spear 5y agoI didn't see a way to disable URL previews in that thread. The given "solution" is wrong -- it just disables message previews in the lock screen.
- 2OEH8eoCRo0 5y agoIt's an extremely common attack vector. PDFs, media message, etc. Would it be viable to create a dedicated processor specifically for parsing these things?
- fmajid 5y agoAnd Apple's terrible software and QA processes, like lack of CI or fuzzing, which is why Google Project Zero is discovering flaws for them.
- uniformlyrandom 5y agoYou do know that memory-safe languages are developed using memory-unsafe languages, and eventually execute the binary code on the actual CPU?
- FpUser 5y agoI think it comes from that rewrite everything in Rust camp.
- shrimpx 5y agoA memory safe language can be written in itself.
- kevingadd 5y agoMost memory-safe languages I've used self-host their compiler and standard library (i.e. they're written in the language itself).
- webmaven 5y ago> Most memory-safe languages I've used self-host their compiler and standard library (i.e. they're written in the language itself). Well, yes, but there is also (usually) a bootstrapping phase before a language is self-hosting, and if you're sufficiently paranoid the 'Trusting Trust' meta-vulnerability comes into play and isn't easily dismissed.
- whoknowswhat11 5y agono question that imessage, email parsers, etc that do third party untrusted network type interactions SHOULD be memory safe. But of course they are not, and apple in particular LARDS these formats down with a million features.
- DelightOne 5y agoLooking at the answers, seems like a NO.