news.volyx.in

Disclosure of three 0-day iOS vulnerabilities (habr.com)

2049 points by jayhoon · 1825 days ago · 456 comments on HN

Article summary

The article discusses the disclosure of three 0-day iOS vulnerabilities. The details of the article are not available, but the comments suggest that the vulnerabilities are significant and could have serious consequences. The discussion revolves around the security landscape and the treatment of researchers who discover vulnerabilities. The comments imply that the vulnerabilities could be used to access sensitive information, including contacts, address books, and device usage data.

Main themes

  • Mobile security landscape
  • Vulnerability disclosure
  • Bug bounty programs
  • Private vulnerability market
  • Ethics in security research
  • Responsible disclosure

What commenters say

  • Researchers who discover vulnerabilities are not treated seriously, leading to a lack of security in the mobile landscape.
  • The market for vulnerabilities is flawed, with private buyers paying higher amounts than official bug bounty programs.
  • Full disclosure of vulnerabilities is necessary, even if the vendor is not notified in advance, to ensure that security issues are addressed.
  • The use of vulnerabilities by private companies, such as Zerodium, raises ethical concerns and can put users' data at risk.
  • Some argue that working for companies that deal in vulnerabilities is unacceptable and should be considered a career-ending move.
  • Others believe that drawing a line between acceptable and unacceptable behavior in the security industry is difficult and may not be effective.
  • The severity of the disclosed vulnerabilities is debated, with some considering them to be highly severe and others arguing that they are not as critical as other types of exploits.
  • The mechanism of the vulnerability, including the requirement for a malicious app to be installed, affects its severity and the likelihood of it being exploited.