Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

* * * * * THIS TERMINAL IS IN USE * * * * *


computers / comp.sys.mac.system / Apple only fixes known security bugs when the shit hits the fan

SubjectAuthor
* Apple only fixes known security bugs when the shit hits the fanAndy Burnelli
`* Re: Apple only fixes known security bugs when the shit hits the fannospam
 +* Re: Apple only fixes known security bugs when the shit hits the fanJolly Roger
 |`- Re: Apple only fixes known security bugs when the shit hits the fanAndy Burnelli
 +- Re: Apple only fixes known security bugs when the shit hits the fanAndy Burnelli
 `* Re: Apple only fixes known security bugs when the shit hits the fan*Hemidactylus*
  `- Re: Apple only fixes known security bugs when the shit hits the fanAndy Burnelli

1
Apple only fixes known security bugs when the shit hits the fan

<sroest$10aq$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=13586&group=comp.sys.mac.system#13586

  copy link   Newsgroups: misc.phone.mobile.iphone comp.sys.mac.system
Path: i2pn2.org!i2pn.org!aioe.org!3PLzD/rb74ta/CXxNcmbeA.user.46.165.242.75.POSTED!not-for-mail
From: spa...@nospam.com (Andy Burnelli)
Newsgroups: misc.phone.mobile.iphone,comp.sys.mac.system
Subject: Apple only fixes known security bugs when the shit hits the fan
Date: Thu, 13 Jan 2022 05:55:42 -0000 (UTC)
Organization: Aioe.org NNTP Server
Message-ID: <sroest$10aq$1@gioia.aioe.org>
Injection-Info: gioia.aioe.org; logging-data="33114"; posting-host="3PLzD/rb74ta/CXxNcmbeA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Notice: Filtered by postfilter v. 0.9.2
 by: Andy Burnelli - Thu, 13 Jan 2022 05:55 UTC

Apple's sophomoric iOS QA team missed this bug since as far back as iOS 14
<https://www.engadget.com/ios-15-2-1-homekit-vulerability-fix-201158978.html>

"Spiniolas found that the vulnerability is present within Apple's mobile
operating system as far back as iOS 14.7, but said he believes it exists in
all versions of iOS 14."

Worse, Apple took forever to fix it after Apple was told about it.

"Security researcher Trevor Spiniolas discovered the vulnerability and
publicly disclosed it on January 1st. According to Spiniolas, he informed
Apple of the bug way back in August of last year!"

Re: Apple only fixes known security bugs when the shit hits the fan

<130120220959433603%nospam@nospam.invalid>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=13587&group=comp.sys.mac.system#13587

  copy link   Newsgroups: misc.phone.mobile.iphone comp.sys.mac.system
Path: i2pn2.org!rocksolid2!news.neodome.net!news.mixmin.net!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nos...@nospam.invalid (nospam)
Newsgroups: misc.phone.mobile.iphone,comp.sys.mac.system
Subject: Re: Apple only fixes known security bugs when the shit hits the fan
Date: Thu, 13 Jan 2022 09:59:43 -0500
Organization: A noiseless patient Spider
Lines: 16
Message-ID: <130120220959433603%nospam@nospam.invalid>
References: <sroest$10aq$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Info: reader02.eternal-september.org; posting-host="41bf0c0d97272eb3548d9465b24cc74e";
logging-data="1298"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+yX6syI1Qa16RcMfv9g8qc"
User-Agent: Thoth/1.9.0 (Mac OS X)
Cancel-Lock: sha1:pUMHKg9UA8SHmEnVzUurz0KwtGw=
 by: nospam - Thu, 13 Jan 2022 14:59 UTC

In article <sroest$10aq$1@gioia.aioe.org>, Andy Burnelli
<spam@nospam.com> wrote:

> Apple's sophomoric iOS QA team missed this bug since as far back as iOS 14

right, because having homekit device names longer than 500,000
characters is so incredibly common.

how could that have possibly slipped through??

it should have been the first thing to test.

for reference, 500,000 characters is roughly 1000 *pages* of
single-spaced text, which would take nearly 17 continuous hours to
type, assuming a sustained 100 wpm for the entire time, without any
breaks for food, bathroom or anything else.

Re: Apple only fixes known security bugs when the shit hits the fan

<j4autvFd7m3U1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=13588&group=comp.sys.mac.system#13588

  copy link   Newsgroups: misc.phone.mobile.iphone comp.sys.mac.system
Path: i2pn2.org!i2pn.org!news.niel.me!aioe.org!news.uzoreto.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: jollyro...@pobox.com (Jolly Roger)
Newsgroups: misc.phone.mobile.iphone,comp.sys.mac.system
Subject: Re: Apple only fixes known security bugs when the shit hits the fan
Date: 13 Jan 2022 15:31:11 GMT
Organization: People for the Ethical Treatment of Pirates
Lines: 31
Message-ID: <j4autvFd7m3U1@mid.individual.net>
References: <sroest$10aq$1@gioia.aioe.org>
<130120220959433603%nospam@nospam.invalid>
X-Trace: individual.net /IzcpuGLyxJjaN4GXBGTVwXXsxuO7dU1ZnBBSfwp9IyNKQTuMW
Cancel-Lock: sha1:edfYSeHqeAU2/E8sUXWYJFOq1YU=
Mail-Copies-To: nobody
X-Face: _.g>n!a$f3/H3jA]>9pN55*5<`}Tud57>1<n@LQ!aZ7vLO_nWbK~@T'XIS0,oAJcU.qLM
dk/j8Udo?O"o9B9Jyx+ez2:B<nx(k3EdHnTvB]'eoVaR495,Rv~/vPa[e^JI+^h5Zk*i`Q;ezqDW<
ZFs6kmAJWZjOH\8[$$7jm,Ogw3C_%QM'|H6nygNGhhl+@}n30Nz(^vWo@h>Y%b|b-Y~()~\t,LZ3e
up1/bO{=-)
User-Agent: slrn/1.0.3 (Darwin)
 by: Jolly Roger - Thu, 13 Jan 2022 15:31 UTC

On 2022-01-13, nospam <nospam@nospam.invalid> wrote:
> In article <sroest$10aq$1@gioia.aioe.org>, Andy Burnelli
><spam@nospam.com> wrote:
>
>> Apple's sophomoric iOS QA team missed this bug since as far back as
>> iOS 14
>
> right, because having homekit device names longer than 500,000
> characters is so incredibly common.
>
> how could that have possibly slipped through??
>
> it should have been the first thing to test.
>
> for reference, 500,000 characters is roughly 1000 *pages* of
> single-spaced text, which would take nearly 17 continuous hours to
> type, assuming a sustained 100 wpm for the entire time, without any
> breaks for food, bathroom or anything else.

A reflection of himself, Arlen's trolls are just plain dumb. He doesn't
bother researching the things he trolls about, nor would he truly
comprehend them if he did. Due to his perpetual little Apple hate boner,
he's perfectly happy to turn even the most ridiculous trivial things
into a troll against Apple because it makes him FEEL better. He's a
pathetic waste of a human being who spends all day every day trolling.

--
E-mail sent to this address may be devoured by my ravenous SPAM filter.
I often ignore posts from Google. Use a real news client instead.

JR

Re: Apple only fixes known security bugs when the shit hits the fan

<srphne$13ge$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=13589&group=comp.sys.mac.system#13589

  copy link   Newsgroups: misc.phone.mobile.iphone comp.sys.mac.system alt.privacy
Path: i2pn2.org!i2pn.org!aioe.org!3PLzD/rb74ta/CXxNcmbeA.user.46.165.242.75.POSTED!not-for-mail
From: spa...@nospam.com (Andy Burnelli)
Newsgroups: misc.phone.mobile.iphone,comp.sys.mac.system,alt.privacy
Subject: Re: Apple only fixes known security bugs when the shit hits the fan
Date: Thu, 13 Jan 2022 15:50:06 -0000 (UTC)
Organization: Aioe.org NNTP Server
Message-ID: <srphne$13ge$1@gioia.aioe.org>
References: <sroest$10aq$1@gioia.aioe.org> <130120220959433603%nospam@nospam.invalid> <j4autvFd7m3U1@mid.individual.net>
Injection-Info: gioia.aioe.org; logging-data="36366"; posting-host="3PLzD/rb74ta/CXxNcmbeA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Notice: Filtered by postfilter v. 0.9.2
 by: Andy Burnelli - Thu, 13 Jan 2022 15:50 UTC

On 13 Jan 2022 15:31:11 GMT, Jolly Roger wrote:

> A reflection of himself, Arlen's trolls are just plain dumb. He doesn't
> bother researching the things he trolls about, nor would he truly
> comprehend them if he did. Due to his perpetual little Apple hate boner,
> he's perfectly happy to turn even the most ridiculous trivial things
> into a troll against Apple because it makes him FEEL better. He's a
> pathetic waste of a human being who spends all day every day trolling.

FACTS (which are incontrovertible):
1. The bug was _not_ found by Apple QA
2. The bug is a _classic_ (which means there is _no_ Apple QA to speak of!)
3. The bug was reported to Apple in the middle of last year
4. Apple refused to fix it in a timely manner (by _all_ accounts!)
5. Exasperated, researches made the bub public (after waiting half a year!)
6. Only then did Apple even _bother_ to fix this rather serious flaw.

ASSESSMENT (by intelligent people):
*Apple only fixed a known security bug well _after_ the shit hit the fan!*

ASSESSMENT by Jolly Roger:
Apple can do no wrong, but worse - anyone who points out any facts must be a
troll because Jolly Roger himself wishes to remain completely oblivious of
facts that tell the truth about how sordid Apples almost total lack of QA
truly is (Apple QA can't even predict a buffer overflow for God's sake!).

Re: Apple only fixes known security bugs when the shit hits the fan

<srphns$149o$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=13590&group=comp.sys.mac.system#13590

  copy link   Newsgroups: misc.phone.mobile.iphone comp.sys.mac.system comp.sys.mac.apps
Path: i2pn2.org!i2pn.org!aioe.org!3PLzD/rb74ta/CXxNcmbeA.user.46.165.242.75.POSTED!not-for-mail
From: spa...@nospam.com (Andy Burnelli)
Newsgroups: misc.phone.mobile.iphone,comp.sys.mac.system,comp.sys.mac.apps
Subject: Re: Apple only fixes known security bugs when the shit hits the fan
Date: Thu, 13 Jan 2022 15:50:21 -0000 (UTC)
Organization: Aioe.org NNTP Server
Message-ID: <srphns$149o$1@gioia.aioe.org>
References: <sroest$10aq$1@gioia.aioe.org> <130120220959433603%nospam@nospam.invalid>
Injection-Info: gioia.aioe.org; logging-data="37176"; posting-host="3PLzD/rb74ta/CXxNcmbeA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Notice: Filtered by postfilter v. 0.9.2
 by: Andy Burnelli - Thu, 13 Jan 2022 15:50 UTC

On Thu, 13 Jan 2022 09:59:43 -0500, nospam wrote:

> because having homekit device names longer than 500,000
> characters is so incredibly common.
>
> how could that have possibly slipped through??

FACTS:
1. The bug was _not_ found by Apple QA
2. The bug is a _classic_ (which means there is _no_ Apple QA to speak of!)
3. The bug was reported to Apple in the middle of last year
4. Apple refused to fix it in a timely manner (by _all_ accounts!)
5. Exasperated, researches made the bub public (after waiting half a year!)
6. Only then did Apple even _bother_ to fix this rather serious flaw.

ASSESSMENT:
*Apple only fixes known security bugs well _after_ the shit hits the fan!*

I realize you make excuses for Apple no matter what, but the fact remains
that an overflow (such as the classic buffer overflow) is not only easy to
predict but it's also one of the _first things_ a decent QA team tests for.

While even the head of engineering said Apple's QA is atrocious in an
internal memo (which we've discussed in the past), it's _trivial_ to test
for buffer overflows.

They just didn't bother to test even this, the _simplest_ of expected tests.
> it should have been the first thing to test.
>
> for reference, 500,000 characters is roughly 1000 *pages* of
> single-spaced text, which would take nearly 17 continuous hours to
> type, assuming a sustained 100 wpm for the entire time, without any
> breaks for food, bathroom or anything else.

Again, you'll excuse every Apple flaw, where now you claim computers can't
add one repetitively to any buffer QA test (which is patently ridiculous).

What you fail to comprehend in your quest to defend even this huge Apple QA
flaw is the following accurate observation in the aforementioned reference:
"'*I believe this bug is being handled inappropriately*
as it poses a serious risk to users
and many months have passed without a comprehensive fix' Spiniolas said.

Re: Apple only fixes known security bugs when the shit hits the fan

<M-GdnbrMKa5O1338nZ2dnUU7-W_NnZ2d@giganews.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=13591&group=comp.sys.mac.system#13591

  copy link   Newsgroups: misc.phone.mobile.iphone comp.sys.mac.system
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!border2.nntp.dca1.giganews.com!nntp.giganews.com!buffer2.nntp.dca1.giganews.com!buffer1.nntp.dca1.giganews.com!news.giganews.com.POSTED!not-for-mail
NNTP-Posting-Date: Thu, 13 Jan 2022 09:52:51 -0600
User-Agent: NewsTap/5.5 (iPhone/iPod Touch)
Cancel-Lock: sha1:O309nFECNS/s0WOhB/SdHgufosY=
Newsgroups: misc.phone.mobile.iphone,comp.sys.mac.system
Subject: Re: Apple only fixes known security bugs when the shit hits the fan
Content-Type: text/plain; charset=UTF-8
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
From: ecpho...@allspamis.invalid (*Hemidactylus*)
References: <sroest$10aq$1@gioia.aioe.org>
<130120220959433603%nospam@nospam.invalid>
Message-ID: <M-GdnbrMKa5O1338nZ2dnUU7-W_NnZ2d@giganews.com>
Date: Thu, 13 Jan 2022 09:52:51 -0600
Lines: 23
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-w0pe5/XTw2P6VJwh0ONuS7pJxfxDcJ9EYIYQRtOAniJjI6qAV00PNlRKTEBHBb479V2j4BxZKpyRfX4!uPa+5wy//ngkkbBNjz2Hipjgdex0ue5n1cT9O2GH056civu1VWtztf2MVeDl5G3mNe3kstneBBB1
X-Complaints-To: abuse@giganews.com
X-DMCA-Notifications: http://www.giganews.com/info/dmca.html
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 2121
 by: *Hemidactylus* - Thu, 13 Jan 2022 15:52 UTC

nospam <nospam@nospam.invalid> wrote:
> In article <sroest$10aq$1@gioia.aioe.org>, Andy Burnelli
> <spam@nospam.com> wrote:
>
>> Apple's sophomoric iOS QA team missed this bug since as far back as iOS 14
>
> right, because having homekit device names longer than 500,000
> characters is so incredibly common.
>
> how could that have possibly slipped through??
>
> it should have been the first thing to test.
>
> for reference, 500,000 characters is roughly 1000 *pages* of
> single-spaced text, which would take nearly 17 continuous hours to
> type, assuming a sustained 100 wpm for the entire time, without any
> breaks for food, bathroom or anything else.
>
Given his obsessive typing here I doubt Arlen would have any problem giving
his devices names longer than 500000 characters, hence his concern. If only
he spent more time naming his favorite devices and less time spamming the
group.

Re: Apple only fixes known security bugs when the shit hits the fan

<srpko7$oc4$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=13592&group=comp.sys.mac.system#13592

  copy link   Newsgroups: misc.phone.mobile.iphone comp.sys.mac.system comp.mobile.ipad
Path: i2pn2.org!i2pn.org!news.neodome.net!news.mixmin.net!aioe.org!3PLzD/rb74ta/CXxNcmbeA.user.46.165.242.75.POSTED!not-for-mail
From: spa...@nospam.com (Andy Burnelli)
Newsgroups: misc.phone.mobile.iphone,comp.sys.mac.system,comp.mobile.ipad
Subject: Re: Apple only fixes known security bugs when the shit hits the fan
Date: Thu, 13 Jan 2022 16:41:44 -0000 (UTC)
Organization: Aioe.org NNTP Server
Message-ID: <srpko7$oc4$1@gioia.aioe.org>
References: <sroest$10aq$1@gioia.aioe.org> <130120220959433603%nospam@nospam.invalid> <M-GdnbrMKa5O1338nZ2dnUU7-W_NnZ2d@giganews.com>
Injection-Info: gioia.aioe.org; logging-data="24964"; posting-host="3PLzD/rb74ta/CXxNcmbeA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Notice: Filtered by postfilter v. 0.9.2
 by: Andy Burnelli - Thu, 13 Jan 2022 16:41 UTC

On Thu, 13 Jan 2022 09:52:51 -0600, *Hemidactylus* wrote:

> Given his obsessive typing here I doubt Arlen would have any problem giving
> his devices names longer than 500000 characters, hence his concern. If only
> he spent more time naming his favorite devices and less time spamming the
> group.

Apologists can't deny facts so they attack the mere messenger of the facts?

What I find interesting is that all you ignorant apologists don't realize
that a computer can easily add 1 to anything (which should be obvious to all
developers and QA testers - but which is not obvious to Apple employees).
*The fact remains that it's trivial to test for buffer overflows.*

Also, I find it interesting that the ignorant apologists don't realize it's
trivial for a computer programmer to code a proper error when it happens.
*The fact remains that it's trivial to code an error on a buffer overflow.*

That the clearly sophomoric iOS developers did _not_ code properly is clear.
That the clearly incompetent iOS QA testers didn't test properly is obvious.

But what this thread is about is that Apple _knew_ about this bug since
August and Apple did absolutely nothing about it.

Apple doesn't care about the bugs until the shit hits the fan.
Only then does Apple fix even this, a very simple yet severe coding flaw.

Apple essentially _waited_ until the security researchers gave up.
*Apple only bothers to fix serious flaws _after_ the shit hits the fan.*

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor