TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Security researcher discloses Safari bug after Apple delays patch

34 pointsby caiobegottiover 4 years ago

4 comments

fsfloverover 4 years ago
Another proof that Apple, by restricting use of alternative browsers, does not have a goal of security in mind but control.<p>&gt; Does Apple permit iPhone users to set a browser other than Safari as the defaultbrowser?<p>&gt; iPhone users cannot set another browser as the default browser. Safari is one of the apps that Apple believes defines the core user experience on iOS, with industry-leading security and privacy features.<p><a href="https:&#x2F;&#x2F;docs.house.gov&#x2F;meetings&#x2F;JU&#x2F;JU05&#x2F;20190716&#x2F;109793&#x2F;HHRG-116-JU05-20190716-SD036.pdf" rel="nofollow">https:&#x2F;&#x2F;docs.house.gov&#x2F;meetings&#x2F;JU&#x2F;JU05&#x2F;20190716&#x2F;109793&#x2F;HHRG...</a>
评论 #24273084 未加载
评论 #24273317 未加载
评论 #24272935 未加载
评论 #24273200 未加载
评论 #24272921 未加载
saurikover 4 years ago
Apple is really bad at dealing with security researchers, and would rather figure out ways to silence them than prioritize fixing anything. For a more fleshed out argument about this, see this Twitter thread I posted last week (which starts out talking about Epic Games but quickly moves through the Corellium lawsuit to focus on this topic).<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;saurik&#x2F;status&#x2F;1295024384596312064" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;saurik&#x2F;status&#x2F;1295024384596312064</a>
caiobegottiover 4 years ago
I believe the lead here is this part (and goes on):<p>&quot;However, the real issue here is not just the bug itself and how easy or complex it is to exploit it, but how Apple handled the bug report.&quot;
medmundsover 4 years ago
Actual bug and disclosure timeline: &quot;Stealing local files using Safari Web Share API&quot; <a href="https:&#x2F;&#x2F;blog.redteam.pl&#x2F;2020&#x2F;08&#x2F;stealing-local-files-using-safari-web.html" rel="nofollow">https:&#x2F;&#x2F;blog.redteam.pl&#x2F;2020&#x2F;08&#x2F;stealing-local-files-using-s...</a>