back
246 comments
Why are people out to crucify Apple for a story that's still being resolved? The article clearly says:

"...Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day..."

"...We saw your blog post regarding this issue and your other reports. We apologize for the delay in responding to you," Apple told Tokarev 24 hours after publishing the zero-days and the exploit code on his blog...

"...We want to let you know that we are still investigating these issues and how we can address them to protect customers. Thank you again for taking the time to report these issues to us, we appreciate your assistance..."

The company hasn't denied the bounty, they're just incompetent / slow on this process.

Feels like everyone is out to paint <x> company with just confirmatory bias using whatever half-baked story is available. Even I feel for company leaders in this kind of shitty journalism environment. And the rest of the comments here are just autopilot piling on the echo fest.

You're framing this as if it's all about the bounty and Apple just hasn't gotten around to it yet. That's only a small fraction of the story and could easily be forgiven. If I wanted to make Apple look good, I'd focus on that part, but that would be rather biased to ignore the whole picture...

Tokarev discovered 4 iOS 0-days, then reported them all to Apple back in May. After months of Apple's continued refusal to fix or even publicly acknowledge all four of the issues, Tokarev made all of them public on GitHub.

Weeks passed, and now it's today. Apple has yet to fix or publicly acknowledge two of the four security vulnerabilities. That should make Apple look bad because it's some fundamentally irresponsible security practices.

Yes, I'm biased. I'm human, not a computer, and it's stuff like this that makes me biased towards Apple. They should receive negative publicity for this, then they should change how they do things. At the very least, app developers and users should be warned about the two issues that have yet to be fixed.

Devil's advocate here: I've worked the other side of managing bug bounties.

It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it.

When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't share details of a larger vulnerability with them. All we can really do is ask for more time. In the end it all works out and they get paid out/credited for the original+follow on bug.

"Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they failed to credit his analyticsd bug report."

"Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories."

They didn't give him credit in the last 5 advisories. Really no excuse for that imho. If Apple keeps this up then why would anyone report bugs to them when you can just post it online and get credit for it right away? Or sell it on some 0-day site.

> they're just incompetent / slow on this process

> I feel for company leaders in this kind of shitty journalism

You're not making sense. Plus Apple has a history of being incompetent and slow on this.

Probably because the 0days have been fixed and the public have received the benefit of the security researcher's report to Apple, but he hasn't received any recognition or compensation through the bounty program via which he reported the vulnerabilities?
>Why are people out to crucify Apple for a story that's still being resolved?

>The company hasn't denied the bounty, they're just incompetent / slow on this process.

People probably expect more from... checks notes The world's most valuable and successful modern corporation.

> The company hasn't denied the bounty, they're just incompetent / slow on this process.

With 0-day security vulnerabilities, slowness equals incompetence. Companies with unbounded resources like Apple have absolutely no excuse for not being able to move as quickly as a small startup on issues like this, unless their message to shareholders is "yes invest in us so you can see our performance literally decrease with every dollar invested".

Let me selectively quote you:

> Why are people out to crucify Apple (...), they're just incompetent / slow on this process.

That's exactly the problem when they're endangering the security of approximately one billion users.

Some security people love to hand-wave and issue prophecies of doom for attribution and attention. It’s great chum for writers — easier to run with some guys grievance than research a more substantive story.
The “Apple Hater” market is as big as the “Apple fanboy” market, maybe even bigger!
Because those emails are probably lies, they're just delaying and delaying and hoping it will just go away, and writing fake "We're sorry"'s when they're forced to.
What a slap in the face. This guy is owed a boatload of cash, and typical Apple just kicks the can down the road. Next time I hope he sells his next vuln to the highest bidder.
Who's the next highest bidder after Apple for a bug in `gamed` that allows you to access GameCenter and download contacts? It's a significant vulnerability, but there's e.g. no price list entry on Zerodium (you can take Zerodium more or less seriously, this is just a data point) for anything but code execution, which this vulnerability isn't.
Can't we hope they go for full-disclosure instead of selling to the highest bidder? Selling to the highest bidder just hurts apple users not apple.
> Next time I hope he sells his next vuln to the highest bidder

And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.

Sell it to the highest bidder then release it on the darknet for free anyways :^)
So you’re hoping for malware?
No, he's not. Those are low-priority bugs and the only thing that made them stand out was the fact that he dropped them online without a patch. RCEs get priority in patching, and his priv esc issues were not as important.
Zerodium (https://zerodium.com/program.html) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal.

Next time someone finds one of these, I wonder where they will report it to….

Zerodium doesn't list "information disclosure" for smartphones. "Information disclosure" from an email server means exfiltrating the emails. Zerodium will almost certainly not outbid Apple for the `gamed` vulnerability here (maybe for publicity).
Is it moral though? What do they do with these exploits? If it is to help advance the agendas of countries like Israel and Saudi Arabia how would you feel submitting exploits to them?
Ah, when I read

Complete file system read access to the Core Duet database (contains a list of contacts from Mail, SMS, iMessage, 3rd-party messaging apps and metadata about all user's interaction with these contacts (including timestamps and statistics), also some attachments (like URLs and texts))

I thought it included SMS and iMessage contents, which does very much sound like what Zerodium is looking for. But reading it again it’s not actually all text messages.

See my comment history for a firsthand account of Zerodium.
>iOS “information disclosure” exploit (likely what this would have fallen under)

Based on what? There's nothing to suggest that this falls into the category for an "information disclosure" according to Zerodium's eligibility guidelines.

Seems that no credit, no bount, nothing, has become the way that Apple deals with the iBugs Hunters.

And all it takes is one of those unsong heros giving up on reporting to Apple and, instead, reporting to some 0-day company, and some ransonware go brrrr

I'm surprised it hasnt happened yet. IT seems apple is possibly openly hostile and uses "red tape" as an excuse to obfuscate communication and frustrate those trying to do right by them instead of just posting it to github and calling them out on twitter.

Its one of a few reasons I have made some in-roads into moving off the platform.

This comment is just nonsense. They regularly credit security researchers:

https://support.apple.com/en-au/HT201222

Seems like this in case it's just a mistake that was made.

Could it be that maybe they try to uphold the reputation of Apple by doing so? But it doesn't make sens either way because they could have just paid those guys and then everyone is happy. That's just some ass-backwards logic. I am an Apple fan and I'm not going to defend this. It's just plain bad behavior on their side.
Here's a fun conspiracy theory proposed entirely in jest:

Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices.

So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ultimately be the largest governments with the greatest ability to regulate Apple).

The need for Linux phones, in a market dominated by two companies and one government, is more than ever!

Hope we soon get a usable Linux phone.

Apple the corporation religiously and sometimes aggressively portray themselves as virtuous, safe, and honest, but this behaviour suggests those qualities are marketing tools.
For want of a nail the kingdom was lost. Just pay the stupid bounty
My friend has just looked on Find My Mac and he can remotely format and track the whereabouts of the Macbook Pro of a guy called “Jason”. He’s never sold or had this MacBook model on his account.

The people in the Apple store provided no fixes but suggested formatting the machine which I guess would be illegal in most places.

It makes me worry that I could be Jason and someone could remotely format my computer… it’s scary that something like this is possible.

The advisory credit and bug bounty fiasco aside, when I reported a security vulnerability to Apple in 2010, they wrote, "Because of the potentially sensitive nature of security vulnerabilities, we ask that this information remain between you and Apple while we investigate it further." It seems to just be a standard inclusion in their correspondence, and not unique to this exchange.
As an apple fan myself, I agree that this type of practice renders the platform less secure rather than more secure. Everyone ends up losing.
I wonder what would happen if everyone that knows about this just starts pounding Apple's online presence (twitter, fb, etc) in protest of their actions. Would they relent and pay up?
There's an incentives problem here: If whitehat researchers are disincentivised from working on iOS, the only people researching iOS vulnerabilities will be the bad guys.
I wish Apple would do a feature freeze for iOS and macOS for a couple of years, then focus on fixing bugs, improving security and optimizing performance instead.
>Apple silently fixes iOS zero-day, asks bug reporter to keep quiet

Isn't that standard procedure for any company faced with a 0-day, prudent, and the right thing to do?

Big companies move slow and given the pervasiveness of these devices, it's fundamentally irresponsible to allow the google-apple duopoly in mobile OSes to keep their platforms closed, forming a bottleneck on all security fixes. Trust-busting in this space is long overdue
Richest company in the world.
iOS 15 from release date has had the most bugs I've ever experienced with any former versions of iOS. Siri would revert back to Dragon style text to speech randomly is one thing I noticed frequently.
so silent that the internet now knows about it..
Apple definitely needs to improve its processes in order to ensure he and others gets credit.

But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite request not a demand.