Apple AirPort Firmware Data Deletion Vulnerability
jcs.org
jcs.org
IMHO this is really the only concerning part because it sounds like something that can be remotely exploited; knowing the wireless network name and key is only worth anything if you know where that network is, and can actually go there and do something.
a "factory-default" reset just moves the configuration file to a new location on the device, and the old file and up to two additional previous configurations remain accessible on the device.
When doing a factory reset, repeat the process at least three additional times to cycle the data out of ACPData.bin.3.
That sounds like a "last known good configuration(s)" feature to handle the inevitable "I thought I'd reset it because it wasn't working, and now nothing works anymore!" but perhaps the feature was never fully implemented due to other factors.
The AP's MAC address would be the same, which you can just plug into https://find-wifi.mylnikov.org/
Before updating, I questioned whether I should even bother applying the update, but figured better safe than sorry in case it contained some important security patches. Glad I did!
That sounds like an interesting behavior to debug.
A company with as much resources as Apple should not be given this much time before publication. A Project Zero-like 90 days grace period should be fine, especially as you need either physical or SSH access to such a device.
I know Apple tries to make people who report bugs stick to their procedures and agenda but taking over 300 days to roll out a patch for a product that was not seeing any active development regardless? That's quite a lot of patience to keep.
I wonder how many other consumer companies would've bothered with a patch at all?
Microsoft would have.
For example:
Microsoft is planning to end support for Windows 10 Mobile devices in December. While Microsoft revealed back in 2017 that the company was no longer developing new features or hardware for Windows 10 Mobile, security and software updates have continued. These security updates will now cease on December 10th 2019...
https://www.theverge.com/2019/1/18/18188054/microsoft-window...
I was thinking more along the lines of e.g. Sony. There are tons of consumer devices that no longer get updates after they’ve been withdrawn from the market.