Google reveals fistful of flaws in Apple's iMessage app
bbc.co.uk
bbc.co.uk
Of all places, I thought Hacker News would have a community which understands the critical importance of security research and the fact that fixing software security bugs is a net benefit to everyone, every time, all the time.
Personally, I've observed (via the voting mechanism and commentary) several different cohorts of people visit HN throughout the day. You get a real sense that opinions are regional and tribal. Europeans in the early morning, then east coast and flyover states, and then brace for impact when SV (in particular Googlers and/or pro-Googlers) pile on. It's fascinating.
No science here, absolutely, but I have had great success so far predicting in advance what the voting pattern is going to be on a comment I make. I treat it a bit like a sport.
I installed innocent piece of Google SW on my Mac, Android File Transfer [0]. Immediately it tried to install several launch agents, driving BlockBlock [1] crazy. Uninstalled right away without opening the app.
People tend to subconsciously forget that Google is an Ad company by 85% of revenue.
[0] https://www.android.com/filetransfer/ [1] https://objective-see.com/products/blockblock.html
That's not magic mate, something needs to monitor for your Android device being connected otherwise you'd complain that it's not as user friendly as other Mac apps.
I suppose once you hate something, it becomes impossible to acknowledge that any good can come from that thing. Which is unfortunate.
There is a plethora of things I really don't like about Google, but I make a conscious effort (and it's hard sometimes!) to acknowledge the good they do, when they do it.
P0 is one of the things in the "good" column of Google.
They didn't say they were appalled at people disagreeing with them. They said they were appalled at the lambasting. There is valid criticism raised here, but the majority of the criticism is based solely on the fact that its P0. Not for any technical reason. Not for any security related reason. Just because it's Google. If you think "Google is worse than China and Russia" is a worthy criticism... So be it.
>I tend to find it appalling to when hacker news argues against for example a free press
Huh. Can you expand on this, in the context of this thread?
>Arguing against arguably the most powerful software company in the world because you disagree with their practices?
Very few of the legitimate criticism I have seen here has been about P0's practices - and the ones that have brought up P0's practices have brought it up in the context of the security industry as a whole (i.e. what responsible disclosure should be).
Whether you think something is legitimate criticism or not is subjective and I don't see an argument why it is. Anyone is certainly free to argue, or not argue, with those comment and they have.
> Huh. Can you expand on this, in the context of this thread?
I was calling out the line "I thought Hacker News would have a community which understands the critical importance of security research". People argue against important things here all the time.
> Very few of the legitimate criticism I have seen here has been about P0's practices [...]
Again, subjective. Here is the first comment hidden by downvotes:
'Why should end-users "have nothing but gratitude" when vulnerabilities are disclosed and they are immediately placed at risk until they get a chance to update, even when the vendor has promptly provided a correct patch? I know I certainly don't appreciate that and can't reasonably expect any normal person to appreciate it either.'
Seems like a legitimate opinion to me. (The same users had almost all their comments downvoted as well, most of which seem perfectly fine). There are a number of others saying that Google has a conflict of interest, which also seems legitimate.
What I see is people doing everything they can to not address those arguments. It is one thing to call out people when they are the majority, another when mostly normal comments are being suppressed. That is not legitimate if anything. I can't see how the people creating that environment expect to get anything out of it, but I guess that isn't the point. Very few smart people you meet in real life spend any time on hacker news.
There's a trove of clever people on HN, I never lookup usernames or track who posts what. It's enlightening in a way to remember even smart people are still people.
I think there is trove of people who think they are clever on HN. Most likely includes me, but I don't comment much because of that reason.
Disc: Googler.
Many Googlers use iOS. I am not a Google fanboy (I prefer DuckDuckGo) but I don't think it's accurate to paint this as an attack on Apple. Not everything Google does is good, but Project Zero is a good thing IMHO.
Reading through the comments is disorientating - people are angry that researchers are.. gasp... researching vulnerabilities. It's not some faceless Google Incarnate monstrosity, they are paid researchers (humans, too!). If it was Cure53 that did this, for free, and made the exact same announcement no one would bat an eye.
Good on whatever company does vulnerability research, follows established protocols in disclosure, and makes the world a safer place.
Why the hell suddenly put everyone's devices at immediate risk until they get a chance to update? That's "responsible"?
Disclosing the flaw even if patched helps everyone, including you and me.
If companies like Apple or Microsoft are alarmed by the optics of Project Zero, they are free to stand up their own vulnerability research labs; they have the resources and they would immediately find takers in the research community.
End-users, meanwhile, should have nothing but gratitude for P0, since that project essentially represents Google donating fairly expensive and scarce specialized resources to public interest work. Vulnerabilities that P0 finds are vulnerabilities that aren't being sold through brokers to the global intelligence community. Message board talk about the "black market" alternative to bug bounties is almost always overblown, but P0 traffics in exactly the small subset of vulnerabilities that do have substantial, liquid markets.
Why should end-users "have nothing but gratitude" when vulnerabilities are disclosed and they are immediately placed at risk until they get a chance to update, even when the vendor has promptly provided a correct patch? I know I certainly don't appreciate that and can't reasonably expect any normal person to appreciate it either.
If you want to get angry about this, get angry at the vendor that took your money and time and attention and gave you a product with an exploitable security vulnerability in it. I think the issues involved here are a bit subtle to warrant knee-jerk anger, but if you've got to get angry, at least get angry in the right direction.
1. because the policy is "mandatory disclosure", it's way harder to criticise it if it's a blanket, universal policy
2. disclosure is important for users (in general though mostly corporate) because if the issue is not publicly disclosed they might not update their systems (assuming issues are minor or irrelevant)
"It's harder to criticize"? So the reason to put users at risk is to... solve a PR problem?
> 2. disclosure is important for users because if the issue is not publicly disclosed they might not update their systems
Hold on. You're actively injecting a threat and guaranteeing that everyone knows the exploit immediately and that it can be deployed by lots of people on a wide scale because someone might discover it someday?
Can't you just at least easily address this by at least putting a reasonably long time gap between the patch and the disclosure? People will still have to update their systems in the interim due to previous patches' deadlines expiring...
Others have stated that almost immediately after patches are released they are reverse engineered to discover the exploits. So at that time, motivating people to upgrade to the patch is all benefit no?
If they're wrong about their assumptions, you might have a point. If you're wrong, what's the dispute?
There should be an easy way to settle this, which is with data, which I have not yet seen anyone point to. I would be shocked if data showed that the number of actual customer systems hacked actually decreases when a PoC is provided quickly after a patch, vs. when this is not the case.
because many people will discover it immediately by looking at the patch.
This happens to 100% of MS Windows Patch Tuesday patches, and happens to less well known products as well. These examinations happen even on changes that aren't known to be security problems when they are fixed: the recent EXIM worm problem was actually fixed by the EXIM team as a minor bugfix, and they didn't categorize it as a security flaw. It was only when outsiders at Qualys [1] saw the change that they realized it was possible to do a remote command execution.
In essence, the bad guys are patient, smart, and observant. They will notice all of these code changes. So disclosing the problem after it is patched serves to encourage users to patch, because it boosts and amplifies the "get updated" signal for the good guys, and the bad guys already are paying attention.
[1]: https://www.qualys.com/2019/06/05/cve-2019-10149/return-wiza...
The P0 disclosure is the disclosure to the good guys and users.
You're assuming that the bad guys are learning about the problem from P0's disclosures, but without P0's disclosures, the bad guys would still learn about the old bugs from the patch itself.
So which is a better situation: a world in which only the bad guys get the information about broken old versions, or a world in which everyone gets the information?
The way I'm suggesting you measure "better" by measuring actual hacks, and how the number of actual hacks is changing based on whether you insert a delay or not.
So we go back to my question above, which you didn't address. I'm saying the fact that patches come out on a regular basis means that people would still have to update regularly, even if each individual patch comes with a delay before a PoC etc. is disclosed. So I repeat the question: would customers really update regularly but actively filtering out patches whose disclosure deadlines haven't passed? If not, why wouldn't the delay that still achieve the outcome everyone is asking for here?
And wouldn't a vulnerability still be there even if there wasn't e.g. a PoC disclosed? I'm not really sure how that affects what I'm saying.
Of course not, that's a straw man that only you are suggesting and often isn't even possible on most systems. People by-and-large will apply all pending updates at once.
Responsible disclosure pushes folks to update. Well, that and new emojis that they're feeling FOMO from. It's a carrot and stick sort of operation.
As noted elsewhere, patches are effectively disclosures, with some small delay (best described as an obscurity delay) baked in.
It's in the interest of the developer to downplay security problems they they think aren't a problem. It's in the interest of the security researcher to make sure they get the information about how problematic the exploit is. The user can only make an informed decision about whether an update is important when they have the information.
Once the patch is released, all announcing the exploit does is possibly bring more exposure to it for people that might have delayed or foregone patching, possibly causing them to patch manually or request their automatic patch process run immediately instead at some future date.
This is a net gain for the security of individuals, in that it likely causes some number of people to patch earlier than they would have, and adversaries are already actively tracking patches so it's unlikely you've given away much info they couldn't get fairly easily (and they are incentivized to find it no matter what).
On the other hand, I'm pretty sure I've repeatedly seen patches on closed-source products (from Microsoft, Apple, etc.) make it to the broader news without a PoC, so to me it seems like it's really a function of how severe the vulnerability is (although every vulnerability becomes more severe when it comes with an exploit and an instruction manual).
There's an easy way to settle this with data though. Is there data to indicate fewer machines are actually hacked at the end of the day when a PoC is provided after a patch, compared to when it is not provided unless the vendor doesn't issue a patch? That's what ultimately matters at the end of the day, and I'd readily buy that, but I have yet to be made aware of any.
Based on evidence like that, I don't think that a PoC matters that much to the most dangerous bad guys. The script kiddies, maybe it does matter, but there are enough NotScriptKiddies out there that'll own you just as hard with Shodan and their own code that the marginal effect of releasing a PoC is probably pretty minor.
Because as far as I can tell, Qualys did include precise exploit details [1], and the attacks happened 8 days after they did that, meaning in fact the inclusion of source code details would have caused the exploitations in the wild!
Here's the timeline I can find:
CISA reported this vulnerability as being exploited in the wild on June 13 [2]. According to a June 14 article [3], this came one week after Qualys disclosed the bug, which means they must've been referring to the the announcement Qualys made on June 5 [1]. When you look at that announcement, it in fact included full details on how to exploit the vulnerability ("a local attacker can simply send a mail to [...] and execute arbitrary commands") on top of explaining in precise detail the vulnerable piece of code in the (open-source!) source code.
More info on the timeline is in [4]. They refer to a May 27 report, which I cannot find online. I assume it must've been a private disclosure. In any case, it doesn't seem to be what SCMagazine was referring to, given CISA only reported this on June 13 and SCMagazine referred to that on June 14.
So... if I'm reading this right, it seems in fact it almost certainly was the precise exploit details that made the bad guys move quickly. Right?
[1] https://www.qualys.com/2019/06/05/cve-2019-10149/return-wiza...
[2] https://www.us-cert.gov/ncas/current-activity/2019/06/13/Exi...
[3] https://www.scmagazine.com/home/email-security/exim-vulnerab...
[3] https://www.exim.org/static/doc/security/CVE-2019-10149.txt
You judge the persuasiveness of an argument by... the "pallor" from other users' votes? In a discussion about computer security... which is an area in which you yourself are the expert? Shouldn't you be the one whose thoughts and votes other people would look at (and frankly, quite possibly, did look at and become immediately biased by), rather than the other way around?
> Why would I do that? If it was just one or two comments, sure, who cares, but you've written a multitude of them
Why would you do that? Yes, good question! Why did you ignore my 3rd comment in that thread (I suppose 3 is "a multitude") where I pointed out you had not been actually addressing my argument at all in the previous 2 comments, yet still proceed to interject into this discussion instead, and after waiting for hours for the discussions with other people to finish, again waste time replying to me here with a comment devoid of any substance? I wouldn't know; that's a question only you can answer to yourself.
You can "place the burden of proof on me" if you want, but the fact that you misrepresented my argument twice, refused to ever address it, moved told another thread just to tell me I'm being backwards, and now replied hours later to judge the merits of my comments by other people's downvotes in the very area you're an expert in... answers my question more fully than I could have ever hoped it would. Thanks.
> and none of them appear to be surviving.
You're wrong here too. At least one of them is still quite productively moving forward, with a kind user who left genuinely good replies that have actually directly addressed my arguments, and I look forward to that user's next reply.
I'm totally baffled by your stance would you rather only the people on the black market and their buddies have access to this knowledge?
I think you're complaining that P0 don't give users enough time to patch - e.g. disclosing one day after the patch was released. If so, that is fair and I think they could wait longer, but for things like Microsoft, Apple, Android, Chrome, etc. security patches - those are disassembled and diffed within hours of release, and for some vulnerabilities an exploit is ready within 24h, so P0 disclosing everything so defenders can for example prioritize installing the patches, turn off features/services, etc. is generally a good thing.
Or they might not have, in which case you just gave them a pretty powerful weapon, and it's pretty unfair to customers??
> It's disclosed so that the customers know what the vulnerability is. Sometimes patching is not the best thing to do for a given situation. Other mitigations might be possible, or it might not even be an issue depending on how the software is used.
Are you sure "because maybe you shouldn't the patch" is their logic here? (Which doesn't even necessitate this either, but everything I've seen indicates they want you to patch immediately.)
AFAIK the compelling reason is that history shows us that vendors won’t take vulnerabilities seriously enough until they get threatened.
https://appleinsider.com/articles/19/07/22/apple-issues-ios-...
Given that before the patch the value of non-disclosing is certainly higher, and after five years the value of disclosing is certainly higher, there must be some point in time from where on disclosing is the right choice. Therefore, the only question is when to disclose, not if to disclose.
Second: P0 never “immediately places people at risk” because they always follow responsible disclosure.
P0 has a well documented and frankly fairly conservative policy before anything is publicly disclosed. Do vendors want more time to fix things? Sure, they always will. Do P0 disclosures sometimes happen publicly before the vendor has things fixed? Yes, Occasionally. However, looking at the net, P0 has provided far more value than they detract with public disclosure of flaws
You don't see how the risk might increase when more people learn about the vulnerability?
> Second: P0 never “immediately places people at risk” because they always follow responsible disclosure.
What? They provided proof-of-concept exploits just one week after the patch was provided. That's apparently not "immediate" in the eyes of security researchers, but try asking the average user if that's enough time to expect them to update.
> P0 has a well documented and frankly fairly conservative policy before anything is publicly disclosed.
Yes, and it could be worse, but it's also not great and could also be better.
> Do vendors want more time to fix things? Sure, they always will.
That was never my argument. I never said they should get more time to fix things.
> Do P0 disclosures sometimes happen publicly before the vendor has things fixed? Yes, Occasionally.
Again, I was specifically NOT arguing about disclosing before the patch is provided.
> However, looking at the net, P0 has provided far more value than they detract with public disclosure of flaws
And I never singled out P0 or claimed otherwise. I'm disputing the entire practice by whomever is practicing it.
Do you see the risk of having a vuln that is completely unknown still exploitable in your stack?
> What? They provided proof-of-concept exploits just one week after the patch was provided. That's apparently not "immediate" in the eyes of security researchers, but try asking the average user if that's enough time to expect them to update.
Why are critical issues not being patched within 48 hours? The disclosure of the issue can only mitigate so many things, and patch schedules by vendors is not one of them. If your vendor takes 3 months to patch the system, is that the requisite amount of time the researcher should be expected to wait before disclosure? That seems preposterous.
> > Do vendors want more time to fix things? Sure, they always will.
> That was never my argument. I never said they should get more time to fix things.
So then that is your argument. What is a reasonable amount of time, and why is your arbitrary value not arbitrary? A day, a week, a month, a year; when can you ever be sure you've reached the critical threshold of patched systems using a rule of thumb?
I don't think we should wait for the carrier though. That's just months and honestly the carriers need pressure put on them or else they'll keep playing this lazy game and keep customers at risk. Because that's the truth. While a vulnerability exists users are still vulnerable. The difference of disclosure is that users know how they are vulnerable and they can hold carriers responsible.
"immediate" has a pretty clear meaning. You might argue that a week delay is not long enough, but it clearly isn't immediate.
> try asking the average user if that's enough time to expect them to update.
I would expect that yes, the average Apple user was updated within a week. You can also argue that if the rollout took too long, that is Apple's fault, not P0
Why is disclosure good?
Companies:
Disclosure in specific instances is often not popular with companies and they try to avoid it because of the bad PR is brings. However, companies benefit from the broad convention of disclosure because disclosures spread knowledge about how to write secure software and how to test for insecurities.
Researchers:
It seems pretty obvious that disclosure is good for security researchers. They get good PR and exposure, without a bug bounty program, that is all they get. (With a bug bounty program, disclosure is often restricted)
Users:
The risk profiles begin to change when a vulnerability is disclosed. After a patch, risks for unpatched users are always going to rise because the patch itself serves as a disclosure of sorts. After the disclosure, this risk does start to rise faster as the pool of people who can exploit the bug expands.
On the flip side, disclosure is important because users need to know when they have been exposed to risk so they can take steps to mitigate that exposure. If a vulnerability allows remote code execution, installing a patch may not be enough if your system is already compromised. If a vulernability exposed communications you thought were secure, any credentials passed using that method need to be rotated.
Finally, not all users' security is equally important. A grandma sending pictures of puppies to her grandchildren does not have the same security considerations as a human rights activist in China. You see this explicitly in embargoed disclosures where a limited set of organizations are informed in advance of the public disclosure.
The length of time between patch and disclosure is thus a trade off between reducing security for high-security users and low-security users. The longer you wait, the more low-security users are patched, but the worse the risks become for the high-security users.
You can't pick an optimum period on a case by case basis, because there are too many unknowns, so the best bet is to use a standard disclosure delay.
I see you've included the old, tired but still favorite excuses of security community that the exploits were probably already known by those other bad actors and if not we should anyway be grateful that those bug hunters aren't selling exploits to the global intelligence community...
Except the security community and Google inclusive have no freaking clue who or what has discovered those exploits. And now they're available to everyone.
Why exactly should anyone using iOS be grateful towards Apple or Google here? We're pawns in a stupid game between these companies. In this day and age all software companies should be forbidden by law to release any software that they can't prove secure. And if that means no releases for the next 10 years, too bad.
They were already available to everyone. You just didn't know about it, and now you do and can take protective measures.
Were there?
In any case, the software industry has a nice racket going:
1. Get paid lots of money to develop broken software.
2. Get paid lots of money to find security holes.
3. Expect praise from us customers that version X+1 is still broken, but now in different ways.
No thanks Google, no thanks Apple. The game's over anyway, several unsavory companies have access to iOS zero days, see the Bezos case.
To be fair it also deprives other companies (and governents) of talented security engineers with a rare set of skills
They have way too much skin in the game.
You're just going out of your way, trying to find things to dislike, and it shows.
Project Zero is a great marketing effort that produces a genuine public good. But when you are the brains around the security dumpster fire that is Android, it's understandable to eyeroll the big PR splashes (ie. distractions) that that project generates.
But hey, that's that market -- it is a valid strategy, and at the end of the day the world gets to learn and fix problems that they didn't know existed.
Wonder how this happened? rushed patch or perhaps they only tested against a submitted PoC? Only a week left until the defcon talk. Still listed as "fixed" in Apple's release here: https://support.apple.com/en-us/HT210346
[0]: https://eclecticlight.co/2019/07/24/dont-apply-high-sierra-s...
It has never been. Been using Apple devices since Tiger if not Panther, their software has always had more teething issues than their hardware, and 10 years back you didn't buy hardware rev1 unless you got every device. Major OS updates usually took a few point release to get solid, and some were just terrible to and through (Lion stands to mind, lots of shiny new stuff, lots of shitty new stuff).
Quality is a moving target: I know something about the quality of Safari, and the quality has been getting better over the years (that said, I admit the recent Mobile Safari Betas have been really shit, hopefully the release will be good).
Maybe it is comparitive: for example Safari's quality it is nowhere near as good as the Chrome team's quality (which is unbelievably good: regular updates across thousands of different Android device types, across thousands of versions of Android, with immensely complex software).
Also social media now means that we hear about quality issues - we raise the bar on what we think is acceptable.
Do you think Apple's software quality has not improved over the years?
I think quality has actively declined.
As you know something of the quality of Safari, I'll limit myself to that. Safari over the past several years has made myriad design changes that I heavily disagree with (killing extensions, removing user control over website data, baffling UI decisions), but even though those changes have made my browsing experience worse they may not be objectively considered "software quality." Instead, I'll focus on stability and bugs.
When macOS Sierra launched, I had to deal with weekly lockups and reboots of the OS that I mentioned here: https://news.ycombinator.com/item?id=13159008. I tracked the issue down to Safari 10, which introduced new resource leaks that eventually brought the entire system down after being left open. Even after major releases of the browser eventually stopped forcing restarts, leaving Safari open for extended lengths of time will still cause not just instability and misbehavior in itself (e.g., popover arrows eventually disappearing), but also knock-on problems in completely separate applications, including greyed-out standard menu actions that return immediately once Safari is quit. This resource exhaustion is independent of the number of tabs, but handling of large numbers of tabs has also regressed: tabs now crash or unload regularly, and there is no easy built-in way to see which; this causes data loss and erroneous cookie manipulation when the tabs are reloaded when navigating back to them. Pages often do not add correctly to History, particularly from clicked or OpenSearch search results, with mismatched titles/URLs or entirely missing entries: to this day, searching Wikipedia with Quick Website Search gives a tab title that does not match the page or the history item, and interaction with the back/forward cache is likely to exacerbate this. Worse, pages often disappear entirely from autocompletion, causing mistaken page loads and spurious searches when expected results are missing. A couple of years ago, Safari stopped preventing the Mac from sleeping while a download was in progress, forcing me to copy URLs into Terminal to download with a caffeinated curl command instead to avoid truncated files. A recent release of Safari marked random unvisited links as visited, likely due to some newly introduced hash collision, and was not fixed for many months.
This is just what I can recall off the top of my head, in one limited aspect of a single application. All of these were newly introduced errors; some major, many persistent. I sometimes have call to use older versions of Safari, and while definitely slower and less compliant, in many respects they are remarkably better in terms of feature stability and experience.
[0] https://lists.apple.com/mailman/listinfo/security-announce/
Apple's runs out in November 2019 instead of April.
ZDNet seems to be the better / primary source on most other articles: https://www.zdnet.com/article/google-researchers-disclose-vu...
Edit: and explains how to set up tooling to test these components. I'll wait for the BlackHat slides.
This is very easy to do using tools such as class-dump if you can get access to the binary (either from the IPSW, or sometimes directly from the shared cache).
Think if Google instead of disclosing these responsibly would leak one bug to hackers every month or so. How many would stay on iMessage efter getting owned for the tenth time??
Google is spending millions of their own dollars to freely help other companies (and themselves!) enhance their security and close holes malicious actors can exploit.
Now replace "Google" with any other company or independent researcher of your choice. If you're no longer angry, you're being biased solely because its Google and not someone you like.
Really, I don't get peoples hatred for Project Zero. Sure, hate the companies, but can you seriously argue that companies spending money on security research is a bad thing? Even if gasp they might get some good publicity from that research?
And if you rule out "all companies like Google", you've basically ruled out everyone with enough capital to donate to research, depending on your definition of "like Google".
And really, it absolutely is a donation. The ROI on Project Zero is likely 50x or more less than if that money went to the marketing team.
And I am not going try to convince you in a popularity based forum, but that is generally the objection.
You are saying that this gives more power to google and someone asked if you could elaborate on why you think that. Not everyone has the same background and what may be obvious power to you may not be to others. This forum is supposed to be participated in with good faith.
But on the other hand meta isn't that interesting either. If large companies wanted to do security research that wasn't objectionable to people they could do so by consensus, standards and agreements. No one could really question that. Instead the idea is largely that "the ends justify the means". That is what people tend to disagree with. That large companies can unilaterally decide how things are done, not just for themselves but in a way that affects other companies or their users. It doesn't really matter if it is for good or best practice because it is about them, especially as large companies in the industry, having that influence.
That being said, I think the same behavior is to be expected from any company large enough to need a dedicated security research team.
Agreed, and I don't think for a second Google as a whole is any different in this regard.
But who cares? Security issues are being found, Security issues are being publicized, Security issues are being fixed.
Project Zero, as a small part of Google, is finding bugs in everyones software - including Google's - and holding them to the same standards, standards which are widely regarded as being acceptable standards for disclosure.
The rest of Google, should they discover an issue without Project Zero's help, presumably behave just as most of other companies do - so hate them all equally, that's fine - and I agree, but Project Zero is different to Google as a whole, and just is not something to hate IMO.
How does fixing vulnerabilities in your iPhone make you feel unsafe?
> apple blamed for issues
Apple is being blamed for the issues because Apple is to blame for the issues. They made the product. Who is to blame about the security issues in an Apple product, if not Apple?
As soon as a company slighted Google, it was immediately a Project Zero target, and that should tell you everything you need to know about why people are annoyed with them.
> with a constructed story about how Epic is compromising everyone's security
Did Epic compromise everyone's (or, at least their users) security? My memory of that incident is, yes - they did. If that's true, if the code was buggy and had a path to a security exploit, how is it a "constructed story"?
It's a pretty big vulnerability when you allow the malicious intent of one app to escalate to an actual malicious capability so I don't think you're accurately recalling the issue in question.
Which is to say, there's the possibility for minor problems that should be fixed, but it's far from the "Epic is terribly insecure, trust the malware-ridden Play Store instead" rhetoric we got from this particularly aggressive media campaign.
Did p0 say that anywhere?
Given that if I search fortnite on the play store, I get a special warning message that it can't be downloaded on play (which was added specifically to prevent fortnite clones), I'm less than convinced that there was a unified campaign by Google to undermine epic, as you seem to be suggesting.
So, yes is what your saying. It was vulnerable code discovered by Project Zero.
And when discovered, did Project Zero follow their published process for disclosure to both Epic and the general public?
I don't think it's all that sudden and they've talked about it:
Plenty of uncovered and disclosed vulnerabilities for Android and Chrome there.
130.
Even Microsoft released a patch recently to a security vulnerability found in Windows XP.
But that “pretty small portion” doesn’t matter if you can’t patch it.
There is a large difference. One is an automatic app update while the user continues working. The other requires the user to stop everything they're doing and reboot their device.
With the benefit that all necessary components are updated together and that Apple can push out any updates world wide without waiting on the carriers....,
This is how devices stay vulnerable.
> With the benefit that all necessary components are updated together
The whole app is already updated atomically. There is no benefit here.
> and that Apple can push out any updates world wide without waiting on the carriers
The same as a Pixel or Android One device. The only difference is that app security updates are artificially slower on iOS due to poor design, and for apps like browsers, this is a fatal flaw.
As opposed to most Android phones that never get system updates? As opposed to Apple releasing an update two weeks ago for all iOS devices back to 2011?
The whole app is already updated atomically. There is no benefit here.
The Safari app is also used as an out of process web view for other apps as is the messenger app...
The same as a Pixel or Android One device. The only difference is that app security updates are artificially slower on iOS due to poor design, and for apps like browsers, this is a fatal flaw.
It’s estimated that Google may sell 1-2 million phones a year and Android One phones are not much more ubiquitous. Even then Google only promises updates for two years.
Don't buy them. Problem solved. Do you avoid Linux entirely because there exist Linux-based routers that are never updated? No, you buy Linux-based routers that are updated.
In this case, the choice is between properly updated Android phones, poorly updated userspace iOS phones, and poorly updated base system Android phones. The obvious choice is a phone from the first group.
> The Safari app is also used as an out of process web view for other apps as is the messenger app...
As is Chrome on Android. Since Android is designed in a way that apps can gracefully recover from arbitrary processes being killed, this does not matter. Chrome gets updated, the process restarts, and the page the user was viewing in the web view reappears. If the app wasn't in the foreground, the user won't even notice.
But yet every single Windows PC sold by any vendor can still get updates directly from Microsoft.
In this case, the choice is between properly updated Android phones, poorly updated userspace iOS phones, and poorly updated base system Android phones. The obvious choice is a phone from the first group.
You are really claiming that Android has a better update strategy than iOS and is more secure? Which Android phones from 2011 are still getting updates? 2013? 2015? Heck 2017?
It's a problem, just like the routers that aren't getting updated. It's not my problem.
> You are really claiming that Android has a better update strategy than iOS and is more secure?
Yes. I've already explained why, and you haven't refuted it.
> Which Android phones from 2011 are still getting updates?
I don't use eight year old phones, so this doesn't matter to me. If you use old phones, you could argue that iOS is marginally more secure than the Android options; but that argument is irrelevant to the purchase decisions of 99% of the people here who do upgrade devices regularly for whom there are Android options that are much more secure than iOS phones.
The average replacement time for cell phones in the US is 32 months.
https://www.npd.com/wps/portal/npd/us/news/press-releases/20...
8 months longer than Google has promised updates.
https://www.digitaltrends.com/mobile/what-is-android-one/
And that’s only with Android One phones. Most Android phones never get updates or are rolled out slowly waiting on the OEM and carrier.
That is not my replacement cycle nor the replacement cycle for most of the readers of this forum. It has no bearing on my purchase decisions nor the purchase decisions of most of the readers of this forum. For people who upgrade regularly, which is a group that includes me and most of the people on this forum, Android One and Pixel devices are more secure than iOS devices, and you appear to agree.
> 8 months longer than Google has promised updates.
Android One phones get security updates at least three years after release.
Well as long as it caters to you and the rest of the people on HN (have you done a survey?), I guess that’s all that matters - not the other 2 billion people in the world....
Android One and Pixel devices are more secure than iOS devices, and you appear to agree.
Android One phones still have to wait on the manufacturer to update their phones. Yes, but they pinky promise they will. From the article I posted.
I’ve never had to wait on a manufacturer to get updates from my Windows PCs. Heck I still get updates for my Mac Mini running Windows 7 and Apple definitely had nothing to do with it. Why is the Android architecture so piss poor that they can’t figure this out? This- an OS vendor licensing to OEMs and providing update - has been a solved problem for PCs for well over 30 years.
From the earlier article I posted.
While updates do still have to go through each phone’s manufacturer, there’s much less to check and update, so updates will generally arrive much faster. It won’t be a day one patch like you’d expect on the Google Pixel range
Each Android One phone is guaranteed to get at least three years worth of security updates from its release date, and up to two years of major Android releases, too.
Android One phones get security updates at least three years after release.
The iPhone 5s (2013) received 5 years worth of OS updates.
The 4s (2011) just received a bug fix earlier this month.
The 6s (2015) is still a more performant phone than any midrange Android phone released this year and can hold its own against high end Android phones that are two years newer. It would be a pity to replace it if it were an Android phone just because Google couldn’t figure out how to update third party devices. My son is still using it.
I already explained the choices. For us, the obvious choice is a properly updating Android device. Any user who chose an iPhone or non-updating Android phone made a poor security choice. Any user who has a longer than three year upgrade cycle has no good options unless they use a community-maintained Android build.
> Android One phones still have to wait on the manufacturer to update their phones. Yes, but they pinky promise they will.
They are guaranteed monthly security updates. If you have an example of one that hasn't had monthly security updates, that would be a breach of contract with at least the user and possibly with Google who certified the device as Android One.
Windows updates aren't guaranteed to work with arbitrary device manufacturers' custom drivers.
> [Irrelevant stuff about how long iOS devices are updated]
The comment you replied to was a correction to your claim about how long Android One devices are updated. That is the maximum period a user can get a secure device for because we have already established that all alternatives have non-working security update systems.
>The 6s (2015) is still a more performant phone than any midrange Android phone released this year and can hold its own against high end Android phones that are two years newer.
You have conceded that iOS is worse for security, so now you want to argue about performance. Android has iOS beat there, too. Here is a midrange Android phone one generation older than the iPhone 6 beating it at the most common task for phone users — opening apps: https://youtu.be/hPhkPXVxISY
Here is a midrange Android phone of the same generation as the iPhone 6s beating it in the same test: https://youtu.be/B5ZT9z9Bt4M
Of course if you want to get off topic, a more interesting discussion than performance is usability, and Android is multiple generations ahead of iOS for what you can do with it and has been since at least the Verizon Droid, which came with driving navigation and voice control.
I’m not arguing performance for performance sake. I’m arguing that a four year phone is still performant compared to many newer Android phones and it is getting both* security updates and os upgrades 24 months and 12 months longer than the tiny percentage of Android phones that get either. It also doesn’t have to wait for a third party OEM to decide to push updates.
I’m also criticizing Google for not knowing how to push updates to phones running its operating system without OEM intervention - something Microsoft figured out 30 years ago with PCs.
But you don’t need to speculate how fast iOS users update their phones.
There are plenty of sites showing how many iOS users have updated operating systems compared to Android users:
https://www.forbes.com/sites/ianmorris/2018/04/13/android-is...
So do have a cite showing that a larger percentage of Android users are running an up to date OS?
You keep coming back to this irrelevant point. Many Android phones are insecure, just as all iPhones are. Don't buy them.
> I’m also criticizing Google for not knowing how to push updates to phones running its operating system without OEM intervention - something Microsoft figured out 30 years ago with PCs.
Who cares? Don't buy them. Besides, I already pointed out in my previous post that Microsoft didn't solve this problem. Do you blame Linus for all the routers that don't get updated, or do you just not buy them?
> I’m arguing that a four year phone is still performant compared to many newer Android phones and it is getting both*
So is a five year old midrange Android phone, which is also as insecure as any iPhone. Don't buy them.
Seeing that the latest iPhones you can get that hasn’t received a recent patch is the iPhone 4 from 2010, where are “all of the insecure iPhones” - especially seeing that both Google and Apple routinely publish the percentage of devices running older OS’s, there is no conjecture needed on which one is running a greater percentage of OS’s with unpatched vulnerabilities - we have numbers straight from the source.
Who cares? Don't buy them. Besides, I already pointed out in my previous post that Microsoft didn't solve this problem.
Seeing that I have a Mac Mini from 2006 running Windows 7 that is still getting security updates and a Dell from 2009 running Windows 10, I think Microsoft solved the problem a lot better than Google. The other 2.7 billion Android users probably would care if they knew any better.
you blame Linus for all the routers that don't get updated, or do you just not buy them?
Linux is free open source software that anyone can use, no one pays Linus for using it, and Linus doesn’t have much of any criteria about how it’s used. None of that is true about Android. What makes Android Android is Google Play Services that is licensed by a commercial entity.
So is a five year old midrange Android phone, which is also as insecure as any iPhone. Don't buy them
There is no five year old iPhone that isn’t supported and receiving security patches. Right now, there isn’t any 8 year iPhone that hasn’t received a security patch recently.
We already discussed this. iOS has a huge attack surface that can only be patched via system updates, which is horribly bad design and terrible for security.
> The other 2.7 billion Android users probably would care if they knew any better.
If those billions knew better, they would get an Android One or Pixel instead of an instead of an iOS or other Android device. We already established that there is only one set of devices that is good for security, and the vast majority of people, including you it seems, do not have them. It's not my problem to fix their security. I don't buy them myself.
> I have a Mac Mini from 2006 running Windows 7 that is still getting security updates and a Dell
In exactly the same way, updates work fine for those of us on properly updated Android devices, and Windows updates don't work for people with hardware that has poorly supported drivers. You didn't address my point. Also, you still haven't addressed why this matters.
> Linux is free open source software that anyone can use, no one pays Linus for using it, and Linus doesn’t have much of any criteria about how it’s used.
So exactly the same as Android.
> There is no five year old iPhone that isn’t supported and receiving security patches.
And all of them have poorly updated userspace. There is no five year old Android phone that has poorly updated userspace. All of those are insecure except for the subset of Android devices that have properly updated base system.
And your theory isn’t supported by facts on the ground - we have statistics about the percentage of iOS devices running the latest version of iOS versus the number of Android devices.
Since iOS annoying asks you to upgrade when there is one available and you are given a choice to automatically update when you’re not using, do you have a reliable citation showing the number of iOS devices without the latest version compared to the number of Android devices? Or do you just have a hunch?
> you're being biased solely because its Google and not someone you like.
We should be biased against Google, in everything.
>On the surface it appears
This implies an ulterior motive.
>expose flaws
As mentioned, "expose" is an emotionally charged word with negative connotation.
>in competitor's products.
P0 does not just focus on competitors products, by any stretch.
Your statement also fails to convey that they notified Apple with industry accepted disclosure practices in order to fix the vulnerabilities, rather than just "expose flaws".
Hopefully Apple does the same thing and obliges Google to operate with a whole lot more security. (Not that anyone should use Google in any case because of the industry leading flagrance of their privacy issues. But I digress.)
There is no reason to assume project zero is biased if one considers second order effects of this security research.
What kind of press releases get picked up by the media 9 out of 10 times? Not the ones about google finding flaws in google products. Google just makes clever use of the medias' bias for conflict.
I'm not a fan of Google at all and don't use their products unless I absolutely have to, but everything I've seen so far about P0 has been stellar technically and ethically.
It also shows that Google Project Zero is very successful in marketing their work. There are several other players reporting security bugs in iOS regularly, I see Tencent KeenLab, Pangu, Checkpoint, GaTech SSLab in the last two releases to name a few, but very few have achieved similar recognition as GPZ.
One thing I’ve always struggled with is the strategy of these white hat teams. I’m sure Google Zero spends a lot of time on Apple because Apple is an enormous company, large partner, and competitor in some spaces.
So now I wonder: does the release of vulnerabilities ever get effected by business agenda?
I assume it has to, although I’m not sure of the agenda here. In this case, iMessage is in direct competition with a Google sms protocol (although googles hasn’t gained much traction). Maybe the vuln is less impressive than saying, “there’s one more”?
¹ https://bugs.chromium.org/p/project-zero/issues/list?can=1
^1
Instead, they worked together to fix the bugs. This is exactly what we want, there is no better resolution.
All their bug reports come with a bad taste in my mouth.
Guilt by association is in fact not completely unjustifiable. But either it attenuates quickly, or every human you know must be shunned for ethical reasons.
I have no love for Google but I’m extremely happy they found vulnerabilities that could be patched on my phone before someone else did.
(these downvotes are confusing. Do you disagree that it is marketing? That their approach is brutal? That they plan this regularly?)
What made you settle on this specific one?
Remember, it's not like others would stop looking for these exploits if Google did.
Does Google harming the reputation of a competitor for it's own advantage not cause some societal harm? Or are we still pretending that some businesses are working in our best interests?
If they're harming the competitor's reputation by exposing a legitimate flaw in the competitor's product, I don't think that causes societal harm, no.
Apple could open up their own Project Zero, if they wanted to. Then you'd have two competing companies making each other better, which sounds to me like the ideal of the free market.
The act of rapid public disclosure compels the target to shift resources and focus to respond to those potential dumps. This can negatively impact the company's strategically and put them in damage control mode.
In the case of Apple, they're not the dominant platform and are trying to pivot to be seen as the the secure and private platform. Google is damaging their credibility with that pivot by investing in finding vulnerabilities in their products and rapidly disclosing them.
Short term this could improve the product but long term it could damage Apple's reputation and further diminish their market share and solidifying Google's.
If Google were funding an independent research team tasked with securing the internet and platforms for the greater good that would be fine. But that isn't Project Zero. Project Zero is a weapon wielded by a company trying to protect it's monopoly.
The fact that this is possibly two faced by google doesn't change the fact that it is a net good if Apple is sincere in their pivot, because they'd want this dealt with anyway and they get them highlighted for free. If Apple just want to be "seen" as secure and private without actually making it so then it's good that it's being exposed as hollow words.
You 'may' have a point with smaller competitors to Google but really Apple is a large enough target that there are other capable threats targeting them that will use these vulnerabilities for worse than just keeping them in line with their marketing material.
Need the right people and perhaps just as importantly the right internal politics.
Lots of businesses struggle with the idea that when the Big Boss says something false it might be OK for a lowly employee to contradict them. I expect that even if Tim Cook thinks he'd be OK with hearing from an Apple engineer that their new product is garbage, Tim's immediate reports will ensure that engineer is fired before news reaches Tim so he thinks it never happens.
What you want in a good company is the CEO takes the bullet. Something bad happened? That's my fault, the buck stops here, I will make sure we do better next time. Big loss? Cut my salary and zero all executive bonuses until we turn it around.
What you see most often is throwing employees under the bus. Something bad happened? We fired the people responsible, I'm putting somebody else on this (read: I am preparing to throw this new person under a bus too). Profits a bit less than anticipated? Fire 1000 people essentially at random to show I'm focused on the problem.
Well it’s not necessarily that simple. Exposing a flaw without adequate time to develop a fix could cause net societal harm. This is especially true if it’s a bug that would have been discovered and fixed internally without any public disclosure.
How was releasing the details 2 days early responsible or beneficial? At best it got customers worked up and made them question Microsoft's patch policies.
Do you think in the intervening 2 days anyone took any actions knowing the patch would arrive Tuesday?
Google hides behind "responsible disclosure" as an excuse for using Project Zero tactically to do PR damage to competitors.
We should all be so lucky as to have Project Zero handing us free bug reports like that. Responsible companies PAY for bug reports on their products. Google is handing them over for free.
(Disclosure: I work for Google)
Project Zero has long maintained that any serious company should be able to meet 90 day disclosure timeframe, and yet here comes Google+...
So it's not "literally no company". ;)
Disclosure: I work for Mozilla and I have reported a number of security bugs on our code, the vast majority of which are now public.
Regardless: that's a good point. I should have said, public disclosure of internal findings is not an industry norm. Mozilla is a good counterexample to the argument that everyone close-holds internal findings.
Of course, as you say, we do rate almost all security issues, and eventually make them public, so the information is only a bugzilla search away! https://bugzilla.mozilla.org/buglist.cgi?keywords=sec-critic...
How is that different?
Disclosure is one thing, remediation is another. The former is only instrumental to the latter. In the G+ leak, remediation was swift; so disclosure was not required.
(Btw, the affected accounts were 500K, reportedly, not millions.)
And it had the exact same automatic 90 day disclosure applied: https://bugs.chromium.org/p/chromium/issues/detail?id=944062
"Please note: this bug is subject to a 90 day disclosure deadline. After 90 days elapse or a patch has been made broadly available (whichever is earlier), the bug report will become visible to the public."
In fact they've reported a lot of Chrome vulnerabilities: https://bugs.chromium.org/p/project-zero/issues/list?colspec...
And Android ones: https://bugs.chromium.org/p/project-zero/issues/list?colspec...
Hey, look at that! Equal treatment for all.
And Project Zero has notified that company of their problem.
If the company fixes their problem in a reasonable amount of time, then it's a Win-Win-Win. The users, the company, and Project Zero all win.
If you blame anyone but the companies with bugs that can't fix them in a reasonable amount of time, then your priorities are dead wrong.
You should check out
https://news.ycombinator.com/newsguidelines.html
for some answers.
90 days is unbelievably conservative. It's frankly ridiculous. Imagine you found weaknesses in a bridge. 90 days to disclose would be insane.