Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

There's got to be more to life than compile-and-go.


computers / comp.sys.mac.apps / Re: First two iOS/macOS zero-day vulnerabilities of 2022 - exploited

SubjectAuthor
o Re: First two iOS/macOS zero-day vulnerabilities of 2022 - exploitedAndy Burnelli

1
Re: First two iOS/macOS zero-day vulnerabilities of 2022 - exploited

<ssunhl$2bm$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=689&group=comp.sys.mac.apps#689

  copy link   Newsgroups: misc.phone.mobile.iphone comp.sys.mac.apps
Path: i2pn2.org!i2pn.org!aioe.org!3PLzD/rb74ta/CXxNcmbeA.user.46.165.242.75.POSTED!not-for-mail
From: spam@nospam.com (Andy Burnelli)
Newsgroups: misc.phone.mobile.iphone,comp.sys.mac.apps
Subject: Re: First two iOS/macOS zero-day vulnerabilities of 2022 - exploited
Date: Thu, 27 Jan 2022 18:16:21 -0000 (UTC)
Organization: Aioe.org NNTP Server
Message-ID: <ssunhl$2bm$1@gioia.aioe.org>
References: <sst0au$1k3p5$1@paganini.bofh.team> <j5fvalFg5qbU1@mid.individual.net>
Injection-Info: gioia.aioe.org; logging-data="2422"; posting-host="3PLzD/rb74ta/CXxNcmbeA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Notice: Filtered by postfilter v. 0.9.2
 by: Andy Burnelli - Thu, 27 Jan 2022 18:16 UTC

On 27 Jan 2022 16:24:53 GMT, Jolly Roger wrote:

> these vulnerabilities
> have already been patched

Why are the iKooks so _desperate_ to minimize clearly very serious problems?
*Safari isn't protecting the web, it's killing it*
<https://httptoolkit.tech/blog/safari-is-killing-the-web/>

Fact 1: Apple QA failed to find these flaws
Fact 2: Apple was told long ago about these flaws
Fact 3: Experts say these are _serious_ flaws indeed
Fact 4: Apple _still_ had no plans to fix the flaws
Fact 5: Exasperated, the researchers _published_ the flaws
Fact 6: As a result, the flaws were actively exploited
Fact 7: Apple finally decided to fix the flaws... but...
Fact 8: Apple couldn't _ship_ the fix
Fact 9: Because Apple had to wait for the rest of iOS 15.3

ASSESSMENT:
Not only did Apple _not_ find the bugs, but the bugs were _serious_ indeed!
*Safari 15 may have a serious security flaw & there's _no patch in sight_*
<https://www.techradar.com/news/safari-15-may-have-a-serious-security-flaw-no-patch-in-sight>

ASSESSMENT:
Worse, Apple had no plans to _fix_ this serious flaw, which is _why_ the
researchers were forced to publish the flaw (to "prod" Apple into action).
*Disclosure of WebKit flaw appears to have _prodded_ iBiz to undertake repairs*
<https://www.theregister.com/2022/01/21/apple_safari_webkit_indexeddb/>

ASSESSMENT:
The funny thing is that Apple actually had a fix; but they couldn't release
that fix because of Apple's primitive monolithic os-release clusterfuck.
*It's time to make Safari update schedule like Chrome and Firefox*
<https://www.reddit.com/r/apple/comments/rmrm51/apple_safari_engineers_of_reddit_its_time_to_make/>
--
Nobody in high tech has higher MARKETING nor lower R&D costs than Apple.


computers / comp.sys.mac.apps / Re: First two iOS/macOS zero-day vulnerabilities of 2022 - exploited

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor