• notkame@lemmy.fmhy.ml
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    But to get to the point that the vulnerability is now being used as a service, doesn’t that mean it’s been there for a while?(I think he mentions that there’s another company that did a bunch of research on the service and the vulnerability for a long time), and if Apple hasn’t given any attention to this major security problem how else will they get pressured into working on a fix? Idk, for me it’s the best way forward given their lack of attention to the problem so far. Also, if I’m not mistaken, it falls in line with a “common practice” that some security researches do, which is to warn the company of the problem, and if they don’t act on it after a certain amount of time, they disclose it to the public so there’s pressure for a fix.

    • Skullvalanche@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      (full disclosure, I used to work at HQ in Cupertino) … it’s not generally Apple’s M.O. to respond to things like this with, at most, “we received your message”.

      Apple’s infosec team is almost certainly looking into this, assuming the report made it’s way to them. I’ll reach out to some of my contacts there n’ make sure they’re at least aware of the exploit.

      Given how guarded Apple is about revealing anything, I wouldn’t expect much of a response though, even from a friend.