Technology With Apple, iOS security vulnerabilities are no longer worth...

With Apple, iOS security vulnerabilities are no longer worth tripping

A security breach merchant is sounding the alarm: those that victimize Apple systems, iOS in particular, are so numerous that they lose their value.

When an IT security breach is exposed, it is usually already plugged. Security researchers test devices and systems year-round and, when they discover a security defect, discreetly alert manufacturers and publishers so that they can correct it. The latter, which have dedicated funding procedures (programs of the type bug bounty), then pay more or less generously these experts who help them keep their creations as impervious to attack as possible.

Of course, sometimes things don’t happen that way. And without reaction from the companies concerned, security researchers end up from time to time placing them before the fait accompli, pointing the spotlight on important security holes always open and inviting somewhere the pirates to rush into it .

In short, we describe there very succinctly the classic operation of the discovery of security vulnerabilities in the tech industry. In reality, things have become a little more complex. Faced with the immensity of the task facing the security researchers, as well as the problems of funding their work, a “fault market” has been created. Here, “wholesalers” buy loopholes from experts before trying to get paid from manufacturers, developers of software and other operating systems, or even publishers of antivirus solutions.

A disturbance in the fault

This preamble – a bit long, sorry – helps to better understand the position expressed by the platform Zerodium, one of these intermediaries, which made an announcement very detrimental to the image of Apple products.

This company specializing in the trade of security vulnerabilities announced on Twitter the suspension of its purchases of vulnerabilities related to Apple products. Evoking too many offers, she will thus refuse “For a period of two to three months” the more or less critical flaws identified for iOS and Safari, among others.

Chouaki Bekrar, security researcher and boss of Zerodium, indicates that the price of Apple vulnerabilities has already dropped, and that those that require user action to be exploitable will more particularly be demonetized. He also fears that the global market for iOS vulnerabilities will eventually sink.

The one who talks about iOS security as simply “crappy” finds that the security of iOS is more than a few barriers that hackers sometimes manage to bypass.

The most profitable Android vulnerabilities

So that to date, the discovery of flaws in Android has more value for Zerodium than those in iOS, a first. It is true that more and more 0-day flaws (completely unknown before, but present in systems for a long time) are highlighted on the side of Apple in recent times. In these conditions, it is clear that the security component of iOS 14 will be expected at the turn. The fault traders are no doubt hoping that the system will be more robust, which would cause this strange market to rise.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest news

What is true and what is false in the mini-series “Great” about Catherine II – Newspaper

What is true and what is false in the mini-series "The Great" about Catherine II Gazeta.Ru.

Pakistani Airbus A320 crashes in residential Karachi, at least 80 dead

InternationalCRASH - A plane crash occurred this Friday morning in a residential area of ​​the city of...

They enabled the walks for the weekend in Córdoba – Informed, upon return

They enabled the walks for the weekend in Córdoba - Informed, on the return - Chain 3 Argentina ...

Price of the dollar today Friday May 22, 2020 at the close, exchange rate

Mexico City. Today Friday May 22, 2020 the dollar listed on $ 22.73 pesos, according to the investing.com platform....

You might also likeRELATED
Recommended to you