TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Google reveals fistful of flaws in Apple's iMessage app

433 pointsby dmmalamalmost 6 years ago

22 comments

tristoralmost 6 years ago
I&#x27;m honestly appalled at the number of comments in this thread trying to lambast Project Zero for the good work they do in improving software security. Even if Google specifically started and ran Project Zero to target competitor&#x27;s products (which they didn&#x27;t, and they don&#x27;t, there&#x27;s over 100 bugs found by P0 in Google products), it wouldn&#x27;t matter because the effect would still be that the online world is a safer place with more secure software.<p>Of all places, I thought Hacker News would have a community which understands the critical importance of security research and the fact that fixing software security bugs is a net benefit to everyone, every time, all the time.
评论 #20569972 未加载
评论 #20568521 未加载
评论 #20568378 未加载
评论 #20571141 未加载
评论 #20569594 未加载
评论 #20568970 未加载
ziddoapalmost 6 years ago
It seems like peoples hatred for Google is leaking over to how they think vulnerability disclosures should happen.<p>Reading through the comments is disorientating - people are angry that researchers are.. <i>gasp</i>... researching vulnerabilities. It&#x27;s not some faceless Google Incarnate monstrosity, they are paid researchers (humans, too!). If it was Cure53 that did this, for free, and made the exact same announcement no one would bat an eye.<p>Good on <i>whatever</i> company does vulnerability research, follows established protocols in disclosure, and makes the world a safer place.
评论 #20567419 未加载
评论 #20567418 未加载
评论 #20567825 未加载
评论 #20567859 未加载
评论 #20567393 未加载
tptacekalmost 6 years ago
I believe Natalie Silvanovich is giving a talk at Black Hat about some of these next week. Silvanovich is a machine.
评论 #20566220 未加载
sigmaralmost 6 years ago
&gt;We are withholding CVE-2019-8641 until its deadline because the fix in the advisory did not resolve the vulnerability<p>Wonder how this happened? rushed patch or perhaps they only tested against a submitted PoC? Only a week left until the defcon talk. Still listed as &quot;fixed&quot; in Apple&#x27;s release here: <a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT210346" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT210346</a>
评论 #20566366 未加载
评论 #20566921 未加载
评论 #20566168 未加载
skcalmost 6 years ago
This type of thread always goes alot differently when the flaws revealed aren&#x27;t in Apple products
评论 #20568249 未加载
mktmkralmost 6 years ago
Apparently iOS 12.4 came out last week but I have automatic updates on and the update is not installed. I just triggered it manually a moment ago.
评论 #20566354 未加载
评论 #20566454 未加载
macraelalmost 6 years ago
Project Zero continues to be a Good Thing
0x0almost 6 years ago
Is this why Apple also quietly released updates for older devices as iOS 9.3.6 and 10.3.4? IIRC Apple has only patched EOL&#x27;d iOS releases once before - in 6.1.6 for the ssl gotofail?
评论 #20566097 未加载
meyalmost 6 years ago
Interesting that there isn&#x27;t a post on Project Zero&#x27;s blog. That&#x27;s typically how they do public notification.
评论 #20569621 未加载
snazzalmost 6 years ago
I wonder what kind of infrastructure they had set up to find these vulnerabilities and extract names of classes and methods. Do they jailbreak iPhones and run fuzzers directly on the device? Do they analyze IPSWs directly?<p>Edit: <i>and explains how to set up tooling to test these components.</i> I&#x27;ll wait for the BlackHat slides.
评论 #20567577 未加载
mavrick33almost 6 years ago
Glad to see tech companies holding each other accountable. I hope the white hat hacking between these folks continues. The more vulnerabilities found, the safer our data will be.
caycepalmost 6 years ago
TBH, while I think the iMessage service is invaluable, the app itself is often buggy for me. On OS X, it often hangs w&#x2F; the spinning beach ball when attempting text input, the iCloud sync can be spotty, and the cardinal sin, on my iPhone X, there are inexcusable screen draw bugs w&#x2F; orientation rotation, or w&#x2F; the keyboard popping up to type....so I am not entirely surprised. It is an app in need of a good overall bug hunt.
评论 #20571865 未加载
jwildeboeralmost 6 years ago
TL;DR Apple happily fixes what Google’s hackers uncover and responsibly disclose but the beeb desperately spices things up because clickbait ;)
评论 #20571560 未加载
garysahota93almost 6 years ago
Does anyone know how to file a bug report for iMessages? I have a slew of bugs I&#x27;d like to report from my day to day usage.
评论 #20571665 未加载
goldrakealmost 6 years ago
Meanwhile google keyboard collects everything you type and android collects everything you say. Who needs bugs..
sixothreealmost 6 years ago
On the surface it appears Google is spending millions of dollars to expose flaws in competitor&#x27;s products.
评论 #20566724 未加载
评论 #20566902 未加载
评论 #20566727 未加载
评论 #20567846 未加载
评论 #20566986 未加载
评论 #20566850 未加载
评论 #20567270 未加载
评论 #20567477 未加载
评论 #20566954 未加载
评论 #20566721 未加载
评论 #20567959 未加载
评论 #20567302 未加载
评论 #20568128 未加载
评论 #20581726 未加载
评论 #20567140 未加载
评论 #20566769 未加载
pmarreckalmost 6 years ago
Would be nice if Google finally came out with their own iMessage-like service that texted over the Internet instead of 30 year old SMS
Bhilaialmost 6 years ago
The recent barrage of security bugs in iOS makes me wonder if Apple has been more lenient on their security posture in recent times.<p>It also shows that Google Project Zero is very successful in marketing their work. There are several other players reporting security bugs in iOS regularly, I see Tencent KeenLab, Pangu, Checkpoint, GaTech SSLab in the last two releases to name a few, but very few have achieved similar recognition as GPZ.
评论 #20569942 未加载
jeffrallenalmost 6 years ago
A fish, a barrel, and a smoking gun.
评论 #20565960 未加载
sambroneralmost 6 years ago
Hard to tell what’s really going on here from this article. Although it seems like five vulnerabilities were fixed and one remains (and google is being unusually patient about the sixth issue)<p>One thing I’ve always struggled with is the strategy of these white hat teams. I’m sure Google Zero spends a lot of time on Apple because Apple is an enormous company, large partner, and competitor in some spaces.<p>So now I wonder: does the release of vulnerabilities ever get effected by business agenda?<p>I assume it has to, although I’m not sure of the agenda here. In this case, iMessage is in direct competition with a Google sms protocol (although googles hasn’t gained much traction). Maybe the vuln is less impressive than saying, “there’s one more”?
评论 #20566392 未加载
评论 #20565759 未加载
评论 #20566230 未加载
finnthehumanalmost 6 years ago
Project Zero Works for the manufacturer of the largest data exfiltration vector in human history and don’t seem to be making meaningful progress on fixing that.<p>All their bug reports come with a bad taste in my mouth.
评论 #20566171 未加载
评论 #20566374 未加载
评论 #20566209 未加载
d2mwalmost 6 years ago
Project Zero has always been disguised marketing, and IMHO an extremely nasty form of it. I have no doubt they plan coordinated releases like this on a regular basis<p>(these downvotes are confusing. Do you disagree that it is marketing? That their approach is brutal? That they plan this regularly?)
评论 #20566012 未加载
评论 #20566316 未加载
评论 #20565851 未加载
评论 #20565802 未加载
评论 #20566898 未加载
评论 #20568210 未加载
评论 #20566648 未加载
评论 #20568165 未加载
评论 #20569221 未加载