6 ms·
It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab
by jjguy 15y ago
It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate.
Over the last several years, Microsoft's MSRC has balanced this very well. Google has done well recently, too. Lots of clued-in people in both places.
- Xuzz 15y agoI'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.
- mikeash 15y agoThis hardly qualifies as an exploit. While it allows the app to do something it's not supposed to do, the ability to download and execute additional executable code doesn't actually violate security. The new code is still restricted to the app's sandbox and can't do anything that the original app couldn't potentially have done directly.
- humbledrone 15y agoIt easily qualifies as an exploit, given that Apple's app store model is based on the fact that each app is reviewed beforehand to ensure various properties, including the property that the app does not contain spyware, etc. If Apple approved a harmless app, and then said app downloaded code that snooped on the user's calls or asked for their credit card number, that's an exploit.
- ghshephard 15y agoFirst - I think just general manners, as well as established protocol, would have the security researcher let Apple know ahead of time what he would be doing. A simple email sent prior to uploading this code would have been sufficient to cover his bases - I'm surprised he didn't do that. Second - Unless I'm mistaken - his proof of concept was more a violation of Apples TOU, it didn't really attempt to copy credit card numbers, or snoop on users calls - so, in that sense, it wasn't an exploit. Net-Net - nobody comes out of this looking good, but Apple makes it clear that they are prepared to back up the language of their Developer TOU with actions.
- JoachimSchipper 15y agoPart of the security of the app store is the review process. "It's possible to download and execute code" is neat, "it's possible to download and execute code and the app store reviewers don't catch that" is much more impressive.
- ghshephard 15y agoNothing in the App Store review process will allow them to catch a zero-day exploit. Coming up with a zero-day exploit in IOS is very impressive - but, by definition, once you have it, the App Store review process isn't going to catch it.
- mikeash 15y agoApp review ensures no such thing. Put in your spyware with a timer so it doesnt activate for a week. Boom, reviewers don't see it, and users do.
- freemarketteddy 15y agolol...timer!!....really?
- mikeash 15y ago
- nookiemonster 15y agoRunning unsigned code is an exploit, my friend.
- mikeash 15y agoWhy? What can you accomplish by running unsigned code that you can't accomplish by embedding a (e.g.) Python interpreter?
- nookiemonster 15y agoCode signining is a control that is intended to restrict the software that can run to only those apps which have been granted the right to run. Your second question is a good one, but given is context, it is unrelated. If apple signs a python interpreter, they do so at their peril, for obvious reasons.
- mikeash 15y agoYes, and it's still only running an app which was granted the right to run, it's just that this app now has some extra code in it. Since Apple doesn't really inspect the contents of the apps it signs anyway, this grants no extra capabilities.
- st3fan 15y agoI think it qualifies as a great exploit. You totally go around the Private API checks that Apple does. And there is a lot you can do with those APIs that is potentially evil. Even in the sandbox.
- mikeash 15y agoIt's trivial to bypass those checks anyway.
- nodata 15y agoSo how do you prove that it's possible to get this kind of exploit into the store unless you submit it to the store?
- Confusion 15y ago^^This. And he [1] probably told them immediately afterwards, since otherwise they still wouldn't have known. As he says: he regularly submits bugs. [1] Or perhaps someone beat him to it: he may not have seen the acceptance mail before someone already noticed the app? I'm not familiar with the exact process: do you need to give final approval or can the app be in the store for a while without you knowing it?
- ubernostrum 15y agoSo how do you prove the DDoS vector exists unless you DDoS someone's site? How do you prove the SQL injection vector exists unless you take over someone's site? etc., etc. This was far from a harmless proof-of-concept app, and "I just wanted to prove I could" isn't sufficient justification for it.
- redthrowaway 15y agoYou prove DDoS vectors exist by DDoSing your own site, or one you have permission to work on. Same with SQLi vulnerabilities. If you want to report a vulnerability you've found to a company, include a working exploit in your report, but don't run it. If the company ignores you or tries to brush the vulnerability off, that's where it gets hairy and responsible disclosure comes into play. We don't know what his level of communication was with Apple, but it doesn't appear that he notified them before testing this exploit. Had they refused to address the issue or otherwise brushed him off, this would be a reasonable escalation. The same story on r/netsec [1] is being linked to a Forbes article [2], which claims he notified Apple three weeks ago. That's not a ton of time. Ultimately, he very much violated their ToS and Apple is well within their rights to give him the boot. Whether that was a smart decision on their part remains to be seen. [1] http://www.reddit.com/r/netsec/comments/m48gx/charlie_miller_gets_kicked_out_of_apples/ http://www.reddit.com/r/netsec/comments/m48gx/charlie_miller... , http://www.reddit.com/r/netsec/comments/m3uwo/mac_hacker_charlie_miller_finds_a_bug_in_ios_that/ http://www.reddit.com/r/netsec/comments/m3uwo/mac_hacker_cha... [2] http://www.forbes.com/sites/andygreenberg/2011/11/07/apple-exiles-a-security-researcher-from-its-developer-program-for-proof-of-concept-exploit-app/ http://www.forbes.com/sites/andygreenberg/2011/11/07/apple-e...
- 16s 15y agoPerhaps he's not the first one to do it? Only the first to tell Apple that he did it.
- jjguy 15y agoFrom Miller's twitter stream last night: For the record, without a real app in the AppStore, people would say Apple wouldn't approve an app that took advantage of this flaw. https://twitter.com/#!/0xcharlie/status/133739410662494208 https://twitter.com/#!/0xcharlie/status/133739410662494208
- Bud 15y agoA few points: 1. This "guy" apparently didn't try very hard, at all, to cooperate, as evidenced by him putting the exploit itself in the App Store before notifying Apple about it, in direct violation of the dev guidelines. What good is it to have such guidelines at all if you display in public that you won't enforce them? 2. Microsoft is doing a great job at this? So are we to assume that their security is therefore superior? 3. There are a few clued-in people at Apple, too.
- swixmix 15y agoHe is foolish if he did not expect this. My guess is he's doing it for the notoriety and succeeded. A job well done. Next time he either should submit a bug report to Apple or avoid using their products.
- zobzu 15y agowhen you submit a security related bug report to apple - granted my experience dates from 99-2005 - you get: A/ ignored (mail auto reply "we might fix it, don't tell anyone or we'll go after you" B/ bug don't get fixed for 2 or 3 years C/ bug get fixed, you get no credits
- daeken 15y agoI don't know why this is being downvoted. Apple is notoriously horrible at fixing vulnerabilities reported by the general public, unless they're downright critical.
- ootachi 15y ago"Unless they're downright critical or enable jailbreaking", you mean.
- JoshTriplett 15y agoIn fairness, many of the bugs which enable jailbreaking also represent serious security problems. For instance, the various iterations of web-based exploits fundamentally do represent remote code execution, a serious bug in any browser environment. On any other platform, we'd classify them exclusively as security vulnerabilities; however, on iOS, the user has to take advantage of security vulnerabilities to break into their own system.
- eridius 15y agos/many/all/
- angelbob 15y agoUnfortunately, if he submitted an exploit and didn't get banned, we'd see more criticizing Apple for favoritism in enforcing the rules. They deserve that criticism and it's true, but I can see where they would prioritize actually enforcing those rules, especially in a big publicly-visible incident. Obviously the best choice from HN's moral point of view is to be more open, more even-handed and less draconian about rules in the first place. But failing that, I can see why they try for "even-handed" over "less draconian," given their own priorities.
- brisance 15y agoHold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.
- mikeash 15y agoHe did not put users at risk. This vulnerability allows apps to download and execute new code, but that new code is still subject to the app's sandbox. This vulnerability is interesting from a research standpoint, but has zero actual consequences to the security of iOS.
- brisance 15y agoThat's not how it's being explained in the popular press. http://www.forbes.com/sites/andygreenberg/2011/11/07/iphone-security-bug-lets-innocent-looking-apps-go-bad/ http://www.forbes.com/sites/andygreenberg/2011/11/07/iphone-...
- nookiemonster 15y agoshocking that the popular press missstates anything tech. Charlie is extremely well known in the security community. They know who he is. This isnt their first trip to the rodeo with Charlie.
- mikeash 15y agoNowhere in that article do I see them state that the downloaded code is able to escape the sandbox. They certainly imply it pretty heavily, but I can only assume that's due to general cluelessness, or less charitably a desire to sensationalize the story.
- the-cakeboss 15y agoSurely you don't think that having arbitrary code placed within the IOS AppStore isn't a security risk do you? Once malicious code has been approved in the store an attacker need only find a way to break out of the sandbox, which I am sure is possible.
- kahawe 15y agoIsn't it considered good security-research practice and just "good manners" to notify the company beforehand and give them a chance to fix the problem before going public and pulling stunts like publicly abusing it, making sure they are publicly humiliated with their pants down? Judging from the article, he did neither - so don't run crying about "that's so rude".