7 ms·
I don’t know if I 100% follow or agree with the comparison of iMessage and GitHub actions. But iMessage has had a number of interesting security vulnerabilities
by MarkSweep 3y ago
I don’t know if I 100% follow or agree with the comparison of iMessage and GitHub actions. But iMessage has had a number of interesting security vulnerabilities over the years in image parsing and deserialization. One example:
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Or a story from today:
https://news.ycombinator.com/item?id=37425007 https://news.ycombinator.com/item?id=37425007
So perhaps the similarity between iMessage and GutHub actions is there are a lot of things that could go wrong. In iMessage it’s a pile of memory unsafe code that was not originally designed to withstand attack. In GutHub actions there is a lot of trust in their parties that could potentially be exploited.
- SigmundA 3y agoAnd yet Android had multiple high and critical CVE's reported in the last few days with little coverage: https://source.android.com/docs/security/bulletin/2023-09-01 https://source.android.com/docs/security/bulletin/2023-09-01
- Obscurity4340 3y agoWhere do CVEs tend to show up app-wise in Android? Is it also messaging or some other system service? With iOS its almost always either iMessage, WebKit, and iCloud Calendar
- teddyh 3y ago«А у вас негров линчуют»
- jacquesm 3y agoThis isn't an Android vs Apple article.
- SigmundA 3y agoIts not an iOS / iMessage article either but it was brought up here and is the point if this current thread.
- bdangubic 3y agoCoverage is proportional to the number of users :)