7 ms·
Lina received a $150k bounty for this exploit.
by fh9302 3y ago
Lina received a $150k bounty for this exploit.
- jamesmunns 3y agoHell yeah, good for her!
- Razengan 3y agoHow does this work anyway? I reported a password bug that went unfixed for months and didn't hear back from Apple. Do you need to be the first/only person to have reported something, or what?
- dagmx 3y agoMost bug bounty payouts go to the first person or group that report it, and only if the bug in question is novel to the company in question. I.e if you report after someone else or report after it’s already been identified internally , you’re not likely to get a payout unless you have novel details
- sirodoht 3y agoSounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.
- arghwhat 3y agoOn the other hand, that's a years salary for many people. Seems like a quite fair payment, and a payout to envy. Lower, easier to get payouts are arguably better than rare jackpot payouts you have to fight over...
- nicoburns 3y ago> On the other hand, that's a years salary for many people. It's several years salary for many people.
- brokenmachine 3y agoBut not for people with this level of applied skills. How many people do you think could pull this off? I certainly couldn't. Could you?
- nicoburns 3y ago> But not for people with this level of applied skills. Perhaps not for people with this level of applied skills who live in the US. But salaries vary drastically around the world, and remote jobs are not feasible for everyone.
- simpleuser27 3y agoHow would you value this exploit, or any exploit?
- sirodoht 3y agoI understand this is arbitrary code execution with root access. I'm imagining the potential of infecting a high status individual and I think a bad actor would pay millions for such an exploit.
- fh9302 3y agoApple pays up to $2M for such zero click exploits.
- simpleuser27 3y agoSure, so how would you arrive at a dollar amount? What would it be?
- rs_rs_rs_rs_rs 3y ago>Sounds extremely low for this kind of vulnerability How do you know that?
- thfuran 3y agoI’m not sure I follow. You’re asking them how they know their own impression of something?
- zamadatix 3y agoThat would be a fair question, we generally don't come to our impressions by random choice alone. My guess is the value of the vulnerability on the black market would be significantly higher and Apple could afford to compete with that better if they wanted. Only the GP could tell us the reasoning for their impression though.
- sirodoht 3y agoWhich part? I feel that arbitrary code execution with root access is a pretty extreme thing to accomplish. But I might be mistaken!
- Veserv 3y agoI mean, this is the company where the only security certification advertised on their website for macOS [1][2] only achieved the lowest possible level of security, EAL1. A level only fit for products where [3]: "some confidence in correct operation is required, but the threats to security are not viewed as serious" which is one level lower than "demonstrating resistance to penetration attackers with a basic attack potential" [4]. Which is four full levels below "demonstrating resistance to penetration attackers with a moderate attack potential" [5]. Apple has never once, over multiple decades of failed attempts, demonstrated "resistance to penetration attackers with a moderate attack potential" for any product. It should be no surprise that the systems, processes, and people who lack the knowledge, ability, technology, and experience to make a system resistant to moderate attackers, despite nearly unlimited resources, have the security of their systems completely defeated by moderate attacks like small groups of skilled researchers. Apple positively, absolutely, 100%, certifies they can not. Though, it would be nice if their marketing were restricted to what their engineering can prove. [1] https://support.apple.com/guide/certifications/macos-security-certifications-apc35eb3dc4fa/web https://support.apple.com/guide/certifications/macos-securit... [2] https://support.apple.com/library/APPLE/APPLECARE_ALLGEOS/CERTS/st_vid11078-ci.pdf https://support.apple.com/library/APPLE/APPLECARE_ALLGEOS/CE... [3] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PART5R1.pdf#page14 https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 14 [4] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PART5R1.pdf#page16 https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 16 [5] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PART5R1.pdf#page20 https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 20
- irundebian 3y agoEAL is not a measure of security but a measure of the depth of analysis. Looking at the complexity of monolithic-kernel-based operating systems, I don't much can be derived from certifications with an EAL < 5.
- Veserv 3y agoEvaluated assurance levels (EAL) are a bundle of security assurance requirements (SAR) that reasonably trace to varying levels of assurance that the target of evaluation (TOE) enforces the Security Functional Requirements (SFR) of the product. One of the core SARs being AVA (vulnerability assessment) which evaluates resistance to penetration attackers and the presence of vulnerabilities. It is only at EAL5 that you are required to demonstrate AVA_VAN.4 which is resistance to penetration attackers with a moderate attack potential. What we derive from companies only able to achieve EAL < 5 is that their systems are not designed, nor capable of protecting against moderate attackers. This has been borne out by decades of experience where the security properties of these systems have been routinely defeated by attackers with moderate or lower attack potential. The certification process is both effective and accurate at identifying that these consumer operating systems are inadequate against attackers of moderate ability as an upper bound. We further know from decades of experience that any system that attempts EAL5 certification and then fails has structural deficiencies that make it practically impossible for any configuration to ever be certified without a total redesign. As far as I know, nobody has ever achieved that despite decades of attempts and billions of dollars spent attempting to retrofit inherently insecure designs such as Windows, Linux, or macOS. So, what we know is that macOS, iOS, Linux, Windows, BSDs, etc. are structurally insecure against moderate attacks such as those employed by commercial hackers and organized crime, let alone state-level actors, and that it is hopeless for them to ever be improved to reach such a level. Anything less than EAL5 is inadequate for the modern threat landscape of established commercial hackers and state actors as experienced by consumers, businesses, and governments. Therefore, the systems currently deployed are universally unfit for their usage in these connected systems and we have the certifications and continuous examples to prove it.
- paddim8 3y agoWhat? That's an insane amount of money
- sirodoht 3y agoI'm comparing it with Apple's market cap of $10^12. Such a vulnerability seems pretty serious. But maybe I'm mistaken and it's not that bad.
- devnullbrain 3y agoLess than the salary of their software engineers.
- 29athrowaway 3y agoWell deserved. By reading the code you can tell there is a lot of analysis and knowledge required to make that exploit happen. OS development, security, shader programming, computer architecture, etc. The code is clean and has plenty of comments explaining what is happening at each step. And for the ones do not know, Asahi Lina is the same person who made it possible to run GPU-enabled Linux on Apple Silicon, among with other contributors.
- tourmalinetaco 3y ago[flagged]
- ayewo 3y agoApple pays out a range of $5k to $150k for this type of attack. See: https://security.apple.com/bounty/categories/ https://security.apple.com/bounty/categories/
- sebzim4500 3y ago> Lina is a pseudonym for Marcan Is there any evidence for this? I've seen a bunch of people say it on HN.
- tourmalinetaco 3y agoHe hasn’t admitted it directly, but there is a large amount of circumstantial evidence. Asahi exclusively uses Marcan’s private infrastructure. They both name their systems after little girls from the anime “PreCure”. They are NEVER talking/streaming at the same moment, even when they appear together. In fact Marcan used to stream quite a bit on his personal channel, but once Asahi appeared he stopped almost entirely. They even have similar typing styles once you start comparing their long-form writings. Not to mention the fact that Asahi’s specialities just so happen to align with Hector’s to the point where they can interchangeably work on reverse engineering Apple Silicon. How many people in the world exist that can do that? And how many would share the exact same interests and peculiarities as Hector? Finally, and my personal favorite: Asahi’s VTuber reveal was by “hacking” and hijacking one of Marcan’s streams. The introduction was literally replacing Hector.
- globular-toast 3y agoThe fact that the comment you replied to is buried shows that it's probably too close to be true and makes people uncomfortable. Are we supposed to believe the character is literally an animated humanoid with animal ears? Is it not ok to question who the human entity behind it is? In any case, it's super easy to spot when it's a man pretending to be a woman, in case that's the source of the controversy.
- deleted 3y ago[deleted]