Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If this doesn't impact costs for bad actors, it's hard to see how it impacts costs for good actors, since, in the status quo ante of this program, both good and bad actors shared the same vectors to get kernel access to devices.

Oh come on... I am a security researcher, and I have definitely had multiple opportunities to buy a stolen prototype device (as I am sure you would have also... but I also assume you don't need it as your company is one of the only companies in this space I have seen actively consulting for Apple--which I frankly feel like maybe you should be disclosing here? I guess you might still not have access to dev-fused devices as I have some vague memory of figuring out that you worked on server security... still :/--so maybe you don't pay as much attention or are as tempted as those of us on the outside); like just about every legitimate person who stumbles upon this, I said no, as I don't want to do something actively illegal (such as trafficking in stolen goods). Are you seriously trying to argue that I should be doing actively illegal things to do research?

> I may just not be understanding you; maybe we just agree that this program doesn't change a whole lot.

I never claimed the program (which I will assume you mean the device program, though I think this also mostly applies to the bug bounty program itself) did? I said "anyone who wants to should be able to buy such a device" and "this ends up feeling like yet another flat gesture" (and then cited numerous specific ways in which Apple clearly works against security research on their devices).

You are then here responding to a comment where I am defending against someone who is claiming anyone can do security research (as Apple can't legally stop me... which is "technically true" but "useless" as they can still sue me--as they did my friends at Corellium--and I can't afford to defend myself) and this device is sufficient as anyone can get one (if only they are willing to get over a few "hurdles") by explaining why most security researchers would not take part in these programs (which is, in fact, an argument for why this program "doesn't change a whole lot"). The argument is that Apple needs to do _more_, to put good actors (who have nothing but these programs and bootrom exploits for older devices) on the same level as bad actors (who have comparatively little issue doing research).



(1) I know you're a security researcher.

(2) I'm a software developer at Fly.io.

(3) Latacora, my previous security company, did no work at all for Apple.

(4) I have no idea what you mean by "server security"; you are probably thinking of someone else.

(5) I'm not asking whether you think it's OK that Apple sued Corellium. Most people in software security are not happy that Apple sued Corellium; I'm not going to be the oddball pissing into the wind this time with a contrary take.

If we agree, we agree, and it sounds like we do: one might not believe that the SRDP meaningfully improves security research on the iPhone, but it's hard to make an argument that the SRDP _harms_ it.


(Of course, I'm talking about Matasano Security / NCC Group ;P. I knew people there when you all worked out of the Dental Fabulous--no clue if you still do--and had some incredibly awkward run-ins involving Apple people, as everyone on all sides wanted to pretend that no one knew anyone else, due to what I'm sure was a ton of NDAs, explicit and implied... it was pretty epic, actually, as one of the people involved was essentially a "double-agent"! Regardless, I'm willing to believe that you had just left before all of these contracts with Apple had happened, and it certainly undermines the premise that you yourself don't need one of these devices to do research, so "point still taken".)


I left Matasano more than 6 years ago. Unfortunately, Matasano SFBA moved from the dentist's office (which I have fond memories of) to Sunnyvale. What I'll say right now is: I have the same disclosable interest in Apple's security as most veterans in software security: they're an elite employer and I have a bunch of friends there.

(The more important disclosure is that I don't specialize in the kind of work that would likely benefit from an unlocked phone.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: