"...Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day..."
"...We saw your blog post regarding this issue and your other reports. We apologize for the delay in responding to you," Apple told Tokarev 24 hours after publishing the zero-days and the exploit code on his blog...
"...We want to let you know that we are still investigating these issues and how we can address them to protect customers. Thank you again for taking the time to report these issues to us, we appreciate your assistance..."
The company hasn't denied the bounty, they're just incompetent / slow on this process.
Feels like everyone is out to paint <x> company with just confirmatory bias using whatever half-baked story is available. Even I feel for company leaders in this kind of shitty journalism environment. And the rest of the comments here are just autopilot piling on the echo fest.
Tokarev discovered 4 iOS 0-days, then reported them all to Apple back in May. After months of Apple's continued refusal to fix or even publicly acknowledge all four of the issues, Tokarev made all of them public on GitHub.
Weeks passed, and now it's today. Apple has yet to fix or publicly acknowledge two of the four security vulnerabilities. That should make Apple look bad because it's some fundamentally irresponsible security practices.
Yes, I'm biased. I'm human, not a computer, and it's stuff like this that makes me biased towards Apple. They should receive negative publicity for this, then they should change how they do things. At the very least, app developers and users should be warned about the two issues that have yet to be fixed.
It is entirely possible the researcher found something but didn't realize how deep the problem went. Apple may have released an incremental patch and is working on fixing a larger issue they found when digging into it.
When this has happened in the past, from the researchers perspective things seem quiet/delayed because we obviously can't share details of a larger vulnerability with them. All we can really do is ask for more time. In the end it all works out and they get paid out/credited for the original+follow on bug.
"Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories."
They didn't give him credit in the last 5 advisories. Really no excuse for that imho. If Apple keeps this up then why would anyone report bugs to them when you can just post it online and get credit for it right away? Or sell it on some 0-day site.
> I feel for company leaders in this kind of shitty journalism
You're not making sense. Plus Apple has a history of being incompetent and slow on this.
>The company hasn't denied the bounty, they're just incompetent / slow on this process.
People probably expect more from... checks notes The world's most valuable and successful modern corporation.
With 0-day security vulnerabilities, slowness equals incompetence. Companies with unbounded resources like Apple have absolutely no excuse for not being able to move as quickly as a small startup on issues like this, unless their message to shareholders is "yes invest in us so you can see our performance literally decrease with every dollar invested".
> Why are people out to crucify Apple (...), they're just incompetent / slow on this process.
That's exactly the problem when they're endangering the security of approximately one billion users.
And thereby accomplishing what, exactly? There is still merit, albeit not from a material wealth standpoint, for doing the right thing for the right reasons.
Next time someone finds one of these, I wonder where they will report it to….
Complete file system read access to the Core Duet database (contains a list of contacts from Mail, SMS, iMessage, 3rd-party messaging apps and metadata about all user's interaction with these contacts (including timestamps and statistics), also some attachments (like URLs and texts))
I thought it included SMS and iMessage contents, which does very much sound like what Zerodium is looking for. But reading it again it’s not actually all text messages.
Based on what? There's nothing to suggest that this falls into the category for an "information disclosure" according to Zerodium's eligibility guidelines.
And all it takes is one of those unsong heros giving up on reporting to Apple and, instead, reporting to some 0-day company, and some ransonware go brrrr
Its one of a few reasons I have made some in-roads into moving off the platform.
https://support.apple.com/en-au/HT201222
Seems like this in case it's just a mistake that was made.
Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices.
So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ultimately be the largest governments with the greatest ability to regulate Apple).
Hope we soon get a usable Linux phone.
The people in the Apple store provided no fixes but suggested formatting the machine which I guess would be illegal in most places.
It makes me worry that I could be Jason and someone could remotely format my computer… it’s scary that something like this is possible.
Isn't that standard procedure for any company faced with a 0-day, prudent, and the right thing to do?
But he is over-reacting about the confidential line. When I worked at Apple years ago I added a similar line when dealing with external people. And in every email I have sent whilst working for telcos, banks etc over the last decade a similar line has been included automatically at the footer. It's more a boilerplate polite request not a demand.