3 ms·
Interesting that the researchers have gone public before a mitigation is in place from Apple. Seems in pretty stark contrast to the industry-wide coordination t
by remus 2y ago
Interesting that the researchers have gone public before a mitigation is in place from Apple. Seems in pretty stark contrast to the industry-wide coordination that went into patching and mitigating spectre.
- dartos 2y agoDoes Apple pay bug bounties?
- InTheArena 2y agoYes, they do.
- saurik 2y agoThey claim to, but they drag their feet, demand terms most researchers find so unacceptable as to be a bit immoral (the point of "responsible disclosure" isn't, in fact, to hold secrets from the public arbitrarily long), and often end up paying only a fraction of what was expected, if anything. https://pxlnv.com/linklog/apple-bug-bounty-troubles/ https://pxlnv.com/linklog/apple-bug-bounty-troubles/ https://www.marketplace.org/shows/marketplace-tech/looking-for-worms-in-apple-leaves-a-bad-taste-in-ethical-hackers-mouths/ https://www.marketplace.org/shows/marketplace-tech/looking-f... https://mjtsai.com/blog/2021/07/13/more-trouble-with-the-apple-security-bounty/ https://mjtsai.com/blog/2021/07/13/more-trouble-with-the-app...
- tptacek 2y agoThe vibe I got talking to people like Mark Dowd about this is that they're running something closer to an exploit bounty program, and it's pretty focused on patterns of vulnerabilities common to some pretty specific threat actors.
- threeseed 2y agoYour links are all from 2021. I remember there was a lot of criticism at the time and so they updated their bug bounty program which quite a number of changes: https://security.apple.com/blog/apple-security-bounty-upgraded/ https://security.apple.com/blog/apple-security-bounty-upgrad... Would be interesting to see if it made a difference.
- phoe-krk 2y ago> We disclosed our results to Apple on May 24, 2024. Apple’s Product Security Team have acknowledged our report and proof-of-concept code, requesting an extended embargo beyond the 90-day window. At the time of writing, Apple did not share any schedule regarding mitigation plans concerning the results presented in this paper. The vulnerability is over half a year old and over a quarter over the embargo window.
- sofixa 2y agoI wonder if Apple are being slow due to the complexity of the potential fix, or because they're dragging their feet.
- kllrnohj 2y agoOr it's a hardware issue and they don't have any way to do a microcode fix for this
- sebzim4500 2y agoIt's could be unfixable without a significant performance penalty, but at minimum they could make safari do proper process isolation like every other browser does.
- School-Cotton 2y agoI could easily imagine such a refactor of Safari taking more than 90 days even if Apple made it the highest possible priority.
- goldsteinq 2y agoThe bug is open since 2018, so clearly they don’t actually care about that. https://bugs.webkit.org/show_bug.cgi?id=184466 https://bugs.webkit.org/show_bug.cgi?id=184466
- nerflad 2y ago> We disclosed SLAP to Apple on May 24, 2024, and FLOP on September 3, 2024
- IshKebab 2y agoI think also this isn't fundamentally different to Spectre. Spectre introduced a whole new class of vulnerabilities (hence the name) and this is one of them. An impressive one, but still, it definitely doesn't deserve the coordination & secrecy that Spectre had. Most browsers have already switched to process-per-site because of Spectre.