https://www.theregister.com/2021/09/24/apple_zeroday/ [user] [user] Sign in The Register(r) -- Biting the hand that feeds IT [magn] [burg] [burg] Topics Security Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem All On-PremServersStorageNetworksHPCPersonal Tech (X) Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice All Vendor VoiceAdobeAmazon Web Services (AWS)Amazon Web Services (AWS) MigrationGoogle CloudGoogle Cloud's ApigeeGoogle Workspace LenovoNutanixRapid7Red hatSophosVeeamVirtru (X) Resources * Whitepapers * Webinars * Newsletters Situation Publishing * The Next Platform * Devclass * Blocks and Files Get our Weekly newsletter [front] Security Frustrated dev drops three zero-day vulns affecting Apple iOS 15 after six-month wait Security Bounty program slammed over 'broken promises' Thomas Claburn in San Francisco Fri 24 Sep 2021 // 19:43 UTC 23 comment bubble on white --------------------------------------------------------------------- 23 comment bubble on white # reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy Upset with Apple's handling of its Security Bounty program, a bug researcher has released proof-of-concept exploit code for three zero-day vulnerabilities in Apple's newly released iOS 15 mobile operating system. The bug hunter, posting on Thursday to Russia-based IT blog Habr under the name IllusionOfChaos and to Twitter under the same moniker, expressed frustration with Apple's handling of vulnerability reports. "I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7, but Apple decided to cover it up and not list it on the security content page," the researcher wrote. [front] "When I confronted them, they apologized, assured me it happened due to a processing issue and promised to list it on the security content page of the next update. There were three releases since then and they broke their promise each time." [front] [front] The researcher added that the vulnerability dump conforms with responsible disclosure practices, noting that Apple was informed and has done nothing. And though the programming blunders are not terribly dire, from what we can tell, they ought to be addressed at some point. Apple on Thursday issued a patch for macOS Catalina to address a different zero-day, having gone through a similar exercise ten days earlier to address a zero-click iMessage bug used to target human rights activists and other flaws. [front] The three unpatched iOS flaws include: * Gamed 0-day, which provides access to sensitive data such as Apple ID email address, full name, the associated Apple ID authentication token, read access to a shared contacts database, the speed dial database, and the Address Book. * Nehelper Enumerate Installed Apps 0-day, which allows any user-installed app to determine whether any other app is installed. * Nehelper Wi-Fi Info 0-day, which allows an app with location access permission to use Wi-Fi without the required entitlement. The fixed flaw, Analyticsd, allowed a user-installed app to gain access to a shared set of analytics logs that contain medical data, device usage information, device accessory data, crash data, and language settings for viewed web pages. * Apple warns of arbitrary code execution zero-day being actively exploited on Macs * Break out your emergency change process and patch this ransomware-friendly bug ASAP, says VMware * Yes, of course there's now malware for Windows Subsystem for Linux * Microsoft's end-of-summer software security cleanse crushes more than 80 bugs IllusionOfChaos said the collection of this data shows the hypocrisy of Apple's claims to care about privacy. "All this data was being collected and available to an attacker even if 'Share analytics' was turned off in settings," the researcher said. Kosta Eleftheriou, the developer behind the Apple Watch keyboard app FlickType (who earlier this year sued Apple for App Store market abuse), said via Twitter that he tested the Gamed 0-day on iOS 14.8 and iOS 15 and confirmed that it works as advertised. "The bugs are neat, but unlikely to be widely exploited," security researcher Patrick Wardle, founder of free security project Objective See and director of research at security biz Synack, told The Register. "Any app that attempted to (ab)use them would need to first be approved by Apple, via the iOS app Store." "To me, the bigger takeaway is that Apple is shipping iOS with known bugs," Wardle continued, noting that IllusionOfChaos claims to have reported the bugs months ago. "And that security researchers are so frustrated by the Apple Bug Bounty program they are literally giving up on it, turning down (potential) money, to post free bugs online." [front] Wardle said he considered the researcher's critique of Apple's Security Bounty program to be fair. "It's not that Apple doesn't have resources or money to fix this," he said. "Clearly it's just not a priority to them. "IMHO, the underlying reason is Apple's hubris gets in the way. They (still) don't see security researchers or white-hat hackers as being on the same side." "Apple's internal security team gets it, but at the higher up, cultural level, they've all drunk the Apple juice, and believe their way is the right way, and they don't need any external help." While some developers have found Apple's Security Bounty program rewarding, others share the frustration expressed by IllusionOfChaos. In July, 2020, Jeff Johnson, who runs app biz Lapcat Software, went public with a privacy bypass vulnerability because Apple failed to fix the bug he had reported. At the time, he told The Register, "Talking to Apple Product Security is like talking to a brick wall." The Register asked Apple to comment, but the brick wall did not respond. (r) Get our Tech Resources #Share reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy 23 Comments Similar topics * MORE * Apple * Ios * Security * Software Corrections Send us news --------------------------------------------------------------------- [front] Other stories you might like * Huawei CFO Meng Wanzhou admits lying about Iran deal, gets to go home US puts charges on ice, extradition attempt halted Thomas Claburn in San Francisco Sat 25 Sep 2021 // 00:20 UTC 64 comment bubble on white Updated Huawei finance chief Meng Wanzhou has reached a deal with the US Justice Department to drop the fraud and conspiracy charges against her in exchange for admitting that she made false statements about her company's business dealings with Iran. The deferred prosecution agreement will end Uncle Sam's attempt to extradite Meng to the United States. It will allow her to depart Canada, where she has been detained since 2018, and return to China, easing a major source of diplomatic tension between Canada, China, and the US. After Canadian authorities arrested Meng at the Vancouver airport in December, 2018, on behalf of the Americans, the US Justice Department indicted her and her manufacturing giant for violating US sanctions on Iran by misrepresenting Huawei's relationship with Hong Kong-based Skycom, which operated in Iran. Continue reading * For the nth time, China bans cryptocurrencies Coin prices drop after People's Bank reiterates crackdown Katyanna Quach Fri 24 Sep 2021 // 21:51 UTC 20 comment bubble on white China has once again banned cryptocurrencies. It's not even the first time this month Beijing's done so, let alone the first time ever, yet word of the reiterated crackdown sent coin prices tumbling, which may have been the ultimate goal. After all, China would prefer its citizens use its non-illegal digital yuan. Bitcoin fell by 5.5 per cent, Ethererum by 7.4 per cent, and Dogecoin by 14.9 per cent, for instance, after this latest announcement and have since rebounded somewhat. Continue reading * Yugabyte's double-decker DBaaS follows Cochroach in distributed RDBMS Hopes to lure users with promise of relieving operational burden Lindsay Clark Fri 24 Sep 2021 // 18:41 UTC 8 comment bubble on white Distributed relational database Yugabyte has launched a database-as-a-service product following a rush of inspiration from Facebook, Google and the world of FOSS. While the open-source DBaaS impressed one analyst, it will have to cope with competition from well-funded CockroachDB, which has had its DBaaS on the market for nearly three years. Yugabyte is sort of a double-decker database. It is inspired by Google Spanner underneath and compatible with PostgreSQL on top. As Yugabyte founder and CTO Karthik Ranganathan, a former Facebook technical lead, explained to The Register earlier this year: Continue reading * EurekAI... Neural network leads chemists to discover 'four new materials' All said to conduct lithium atoms, may be useful for electric car batteries Katyanna Quach Fri 24 Sep 2021 // 17:36 UTC 18 comment bubble on white Chemists have discovered four new materials based on ideas generated from a neural network, according to research published in Nature. Uncovering new materials is challenging. Scientists have to search for combinations of molecules that lead to useful compounds that can be manufactured. Traditional methods rely on fiddling around with known materials, and although these techniques narrow down the search for materials that work well, they don't always produce something useful, according to Matt Rosseinsky, a chemistry professor at England's University of Liverpool who co-wrote the research paper . Continue reading * Scientists took cues from helicopter seeds to invent tiny microchips that float on wind 'Microfliers' could carry sensors to monitor air pollution and more Lindsay Clark Fri 24 Sep 2021 // 16:29 UTC 25 comment bubble on white Video As autumn arrives in the northern hemisphere, scientists have shown how tiny connected semiconductors can be distributed on the wind in a similar way to the seasonal spreading of airborne seeds. Researchers led by Professor John Rogers of the US's Northwestern University designed printed circuits able to manifest rotational behaviours, as seen in helicopter and spinner seeds, that enhance the stability and flying behaviour. In a paper published in Nature this week, they argue that simple electronics can be integrated into the designs, with one example containing a circuit to detect airborne particles. Continue reading * With just over two weeks to go, Microsoft punts Windows 11 to Release Preview What's that coming over the hill? Is it new hardware? Is it new hardware? Richard Speed Fri 24 Sep 2021 // 15:33 UTC 30 comment bubble on white Microsoft has followed up a lacklustre Surface hardware event with a Windows 11 Release Preview for Windows Insiders. Assuming, of course, those Insiders are possessed of an "eligible PC" - for Microsoft does not appear to be backing down on its vendor-delighting and customer-frustrating hardware requirements for the new operating system. The build in question is 22000.194, which emerged last week in the Beta Channel to the disappointment of users trying to run Windows 11 on a virtual machine that is not to Microsoft's liking. Its arrival in Release Preview yesterday, just over two weeks from general availability on 5 October, is an indicator that fans should expect little more than patches and updates until then. Continue reading * Fukushima studies show wildlife is doing nicely without humans, thank you very much Biodiversity increasing, endangered species gradually returning despite radioactive terror pig presence Matt Dupuy Fri 24 Sep 2021 // 14:45 UTC 51 comment bubble on white Studies of biodiversity around the former Fukushima nuclear power plant in Japan have shown that a decade after the nuclear incident there in March 2011, the local wildlife, at least, is mostly thriving. The incident at the Fukushima Daiichi site - in which three of the site's six reactors suffered meltdowns due to damage from an earthquake-induced tsunami - was one of only two events in history to be rated at level 7 on the International Nuclear and Radiological Event Scale (the other being Chernobyl). This scale is not related to the quantity of radioactive material released (although that was considerable), but by the number of people affected by the event. Following the incident, 154,000 people were evacuated from the area surrounding the plant due to the risk of radioactive contamination, a number second only to the 335,000 evacuated from the environs of the Chernobyl plant in 1986. Continue reading * HPE campaigns against 'cloud first' push in UK public sector Because HPE does not do public cloud? No, no, it is 'for the good' Tim Anderson Fri 24 Sep 2021 // 13:02 UTC 18 comment bubble on white Comment Hewlett Packard Enterprise has posted a "UK Public Sector Manifesto" with nine themes, alongside a campaign hyping the value of hybrid cloud. The bugbear for HPE is that UK government introduced a "cloud first" policy in 2013. The current version was revised in 2017 but it mandates that central government, when buying new IT services, must consider a cloud solution - and specifically a public cloud, rather than "a community, hybrid or private deployment model" - before any other option. Continue reading * Tech contractors fume over payday outage at Giant Pay after it sniffs 'suspicious activity' Technical difficulties, please stand by Tim Richardson Fri 24 Sep 2021 // 12:26 UTC 24 comment bubble on white Giant Pay - an umbrella company used by contractors across the UK - has confirmed "suspicious activity" on its platform is behind a days-long ongoing outage that has left folk fretting about whether they'll get paid this month. In an update on its website today, the firm said: "Upon detection of suspicious activity on our network on 22nd September 2021, we immediately assembled a response team including IT data experts and specialist lawyers, and we are currently working with the highest priority to resolve this issue. "As part of the investigation and as a measure of caution, we have proactively taken our systems offline and suspended all services temporarily." It also confirmed it had contacted regulatory authorities and assured contractors they would get paid. Continue reading * Parking is expensive. It can cost an arm, a leg, and a Windows licence Activate Windows and put up a parking lot Richard Speed Fri 24 Sep 2021 // 11:29 UTC 10 comment bubble on white Bork!Bork!Bork! Sometimes only the freshest of borks will do, and sometimes the best laid plans of administrators can go awry. Continue reading * 'Nobody in their right mind would build a naval base here today': Navigating in and out of Devonport Twisting and turning like a twisty-turny thing Gareth Corfield Fri 24 Sep 2021 // 10:49 UTC 31 comment bubble on white Boatnotes II As HMS Severn continues hosting the Royal Navy's Fleet Navigating Officer's course, The Register has taken a closer look at the precision demanded of naval officers conning their ships in and out of one of the most cramped ports where the Navy routinely operates. Entering and leaving Plymouth, home to Devonport naval base, is a tricky operation under naval rules as we observed. Continue reading ABOUT US* * Who we are * Under the hood * Contact us * Advertise with us * Seeking client-side dev MORE CONTENT* * Latest News * Popular Stories * Forums * Whitepapers * Webinars SITUATION PUBLISHING* * The Next Platform * DevClass * Blocks and Files * Continuous Lifecycle London * M-cubed Situation Publishing The Register - Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Twitter Facebook LinkedIn feeds no-js Biting the hand that feeds IT (c) 1998-2021 Do not sell my personal information Cookies Privacy Ts&Cs