• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.

Syriel

Banned
Dec 13, 2017
11,088
Confirmed 0-day exploit called KeySteal on MacOS that allows anyone with machine access to dump all Keychain info.



No information has been provided to Apple on how the exploit works, but it's pretty much guaranteed to be in the wild.

 

captive

Member
Oct 25, 2017
16,999
Houston
Ya damn him for doing Apple's job and wanting money for it!
so people should only look bugs if there is a reward? No one asked him to do it.

Apple is dick?
of course it's on Apple. But again no one asked this guy to look for bugs.

But it's a dick move to put it out there and say I'm not gonna tell Apple cause there's no bug bounty.
 
OP
OP
Syriel

Syriel

Banned
Dec 13, 2017
11,088
But it's a dick move to put it out there and say I'm not gonna tell Apple cause there's no bug bounty.

Why?

He's not selling the exploit. Nor is he sharing a public PoC. He simply had it verified by another security researcher.

If he found it, so have others.

He is making the existence of the 0day public so that the public can be aware, and take steps to protect themselves.

Meanwhile, Apple now has constructive knowledge of the issue, and can spend engineering time fixing it.
 

Ferrio

Member
Oct 25, 2017
18,072
so people should only look bugs if there is a reward? No one asked him to do it.

People can do it for whatever reason they want, but wanting compensation for important work shouldn't be vilified. You're right no one asked him to do it but Apple can ignore him if they want to find it themselves. Their choice.
 
Nov 30, 2018
2,078
User Warned: Thread whining
Another hate on Apple for no reason thread

Meanwhile there's millions of exploits on windows probably
 

Hippo_PRIME

Banned
Oct 25, 2017
171
so people should only look bugs if there is a reward? No one asked him to do it.


Apple is dick?
of course it's on Apple. But again no one asked this guy to look for bugs.

But it's a dick move to put it out there and say I'm not gonna tell Apple cause there's no bug bounty.
This is how these things in software work. People interested in software poke around. Typically, if something wrong is discovered, a bug bounty incentives sharing that information. That's why so many other companies have them.

It's telling that Apple doesn't have a bug bounty program. For them to not is arrogance, plain and simple. It's that elitism that Apple is known for. This guy is not at all a dick, Apple fully is.
 

captive

Member
Oct 25, 2017
16,999
Houston
Apple is not entitled to his labor.
This would be like me coming to your house and writing a report all the ways I can get in your house then sending you an invoice for my assessment. You didn't ASK me to do it.

Neither did Apple, in this case.

Don't want to work for free? Don't do shit without an agreement in place. This isn't hard.
 

Deleted member 23212

User requested account closure
Banned
Oct 28, 2017
11,225
This would be like me coming to your house and writing a report all the ways I can get in your house then sending you an invoice for my assessment. You didn't ASK me to do it.

Neither did Apple, in this case.

Don't want to work for free? Don't do shit without an agreement in place. This isn't hard.
He's not forcing them to pay.
 

kadotsu

Member
Oct 25, 2017
3,505
This would be like me coming to your house and writing a report all the ways I can get in your house then sending you an invoice for my assessment. You didn't ASK me to do it.

Neither did Apple, in this case.

Don't want to work for free? Don't do shit without an agreement in place. This isn't hard.
I agree that apple should just give contracts to every coder on the planet. I would personally take that deal. The text of the contract would sound like:

Yo, find some unknown bugs.

Peace, yo boy Tim!
 

Deleted member 1476

User requested account closure
Banned
Oct 25, 2017
10,449
Lmao at calling this guy a dick. People here are so up these companies nuts they can't even see the dick anymore.
 

DBT85

Resident Thread Mechanic
Member
Oct 26, 2017
16,281
This would be like me coming to your house and writing a report all the ways I can get in your house then sending you an invoice for my assessment. You didn't ASK me to do it.

Neither did Apple, in this case.

Don't want to work for free? Don't do shit without an agreement in place. This isn't hard.

He's not forcing them to pay, and he knows that its valuable information they don't have.

If apple can't find it themselves maybe they can rummage around in the sofa and dig out some money for the info.
 

Deleted member 8901

Account closed at user request
Banned
Oct 26, 2017
2,522
This would be like me coming to your house and writing a report all the ways I can get in your house then sending you an invoice for my assessment. You didn't ASK me to do it.

Neither did Apple, in this case.

Don't want to work for free? Don't do shit without an agreement in place. This isn't hard.

It's not like that at all.
 
Oct 25, 2017
26,560
This would be like me coming to your house and writing a report all the ways I can get in your house then sending you an invoice for my assessment. You didn't ASK me to do it.

Neither did Apple, in this case.

Don't want to work for free? Don't do shit without an agreement in place. This isn't hard.
Difference is I don't have millions of people coming in my house leaving their valuable shit.
 

LCGeek

Member
Oct 28, 2017
5,857
But it's a dick move to put it out there and say I'm not gonna tell Apple cause there's no bug bounty.

Apple put themselves in that position and people shouldn't be doing their work for free. The company with billions of dollars can pay the guy for his labor and insights.

The public has a right to know that a kernel they use has security flaws.
 

lint2015

Member
Oct 27, 2017
2,811
so people should only look bugs if there is a reward? No one asked him to do it.


Apple is dick?
of course it's on Apple. But again no one asked this guy to look for bugs.

But it's a dick move to put it out there and say I'm not gonna tell Apple cause there's no bug bounty.
Apple sucks at cooperating with the security community when it comes to bugs, not having a bounty for critical macOS bugs is part of that. Just like that Facetime bug, too often they completely ignore the issue when it's reported to them, bounty or not, until there's press coverage. Only then do they make haste and contact those who discovered it.

That culture needs to change for their customers' sakes, because at the end of the day, these exploits are used against their customers.

So yes, Apple is the dick.
 

Moosichu

Member
Oct 25, 2017
898
This would be like me coming to your house and writing a report all the ways I can get in your house then sending you an invoice for my assessment. You didn't ASK me to do it.

Neither did Apple, in this case.

Don't want to work for free? Don't do shit without an agreement in place. This isn't hard.

It's more like a company sold you a house and you found out that none of the locks work. Meanwhile everyone else's home is just as unsafe because they have the same locks, which criminals can exploit. Meanwhile Apple aren't providing people incentives to report these flaws back to them so that they can be fixed. It's entirely on them.
 

Arthands

Banned
Oct 26, 2017
8,039
Why?

He's not selling the exploit. Nor is he sharing a public PoC. He simply had it verified by another security researcher.

If he found it, so have others.

He is making the existence of the 0day public so that the public can be aware, and take steps to protect themselves.

Meanwhile, Apple now has constructive knowledge of the issue, and can spend engineering time fixing it.

More like informing people that they can exploit it before giving Apple can fix it.
 
Oct 26, 2017
10,499
UK
More like the users whose passwords will get compromised cause some kid is greedy.

But that's OK cause Apple is getting owned!

Apple released the software with the flaw, the kid just want a buck for doing their job better than them. Corporate apologists are the worst boot lickers; don't even care about labours getting their worth within the capitalist system they support.
 

asmith906

Member
Oct 27, 2017
27,398
More like the users whose passwords will get compromised cause some kid is greedy.

But that's OK cause Apple is getting owned!
If he found it then other people have probably found it. But unlike him putting it out in public they are trying to cause harm. People like him that find critical flaws in software that millions of people use is not the villain in this scenario.
 

Mammoth Jones

Member
Oct 25, 2017
12,309
New York
>Kid is greedy
>Apple has 250+ billion in the bank but can't spend resources on a bounty program

Don't hold an exploit hostage for a payday cause you don't agree with their policy? This ain't hard.

I agree that apple should rethink a bounty program but that to me has fuck all to do with this kid trying to leverage it for a check.

Apple released the software with the flaw, the kid just want a buck for doing their job better than them. Corporate apologists are the worst boot lickers; don't even care about labours getting their worth within the capitalist system they support.

Oh give me a break with the bootlicker bullshit lmao. This isn't about apple. This is about some greedy kid would rather see passwords compromised than not get paid. But I get it. Anything to justify whining about apple lmao.

We have all reported bugs before for software in production. How many of us got a check? FOH.
 

The Adder

Member
Oct 25, 2017
18,112
Don't hold an exploit hostage for a payday cause you don't agree with their policy? This ain't hard.
Don't be a software manufacturer and refuse to participate in basic infosec community protocol? This ain't hard.

You ain't entitled to the fruits of his labor anymore than apple is. He told people the exploit exists, they cam now take the steps necessary to protect themselves.
 

SJurgenson

Banned
Oct 28, 2017
1,239
What happens when Apple fanboys and Apple's lack of an industry standard bug bounty collide?

Mostly just lots of ill-informed discussion.
 

lint2015

Member
Oct 27, 2017
2,811
More like the users whose passwords will get compromised cause some kid is greedy.

But that's OK cause Apple is getting owned!
Please go read up on Apple's lack of transparency regarding security. The users are getting owned because Apple has some hard-on for secrecy that doesn't go well with security.