[Thread] Apple's response to Project Zero downplays exploits against an oppressed minority, discounts the risk of other targets, and ends in unseemly marketese
Apple's response to the worst known iOS attack in history should be graded somewhere between “disappointing” and “disgusting”. First off, disputing Google's correct use of “indiscriminate” when describing a watering hole attack smacks of “it's ok, it didn't hit white people.” https://twitter.com/...
@alexstamos Alex Stamos
Related Coverage
- Apple Disputes Google's Claims of a Devastating iPhone Hack VICE · Lorenzo Franceschi-Bicchierai
- Apple takes flak for disputing iOS security bombshell dropped by Google Ars Technica · Dan Goodin
- Apple Hints China Behind ‘Billion Device iPhone Hack’ That Google Reported Forbes · John Koetsier
- Apple, angry at Google, hits back at hack claims BBC · Dave Lee
- Apple accuses Google of ‘stoking fear’ over iPhone security issues The Verge · Tom Warren
- The stakes are too high for Apple to spin the iPhone exploits The Verge · T.C. Sottek
- ‘Indiscriminate’ iOS hacking was relatively limited, Apple says. Try telling that to the Uighur population. CyberScoop · Jeff Stone
- Apple tries to clear up Google's claims about iOS vulnerabilities Engadget · Christine Fisher
- Apple Disputes Some Details of Google's Project Zero Report on iOS Security Vulnerabilities MacRumors · Juli Clover
- Apple slams Google for creating false iPhone hack scare International Business Times · Sami Khan
- Apple Disputes Google Description of a Widespread iPhone Attack Bloomberg · Mark Gurman
- Apple says Uighurs targeted in iPhone attack but disputes Google findings Reuters · Stephen Nellis
- Apple Says Google Scares iPhone Users for No Reason Softpedia News · Bogdan Popa
- Apple Has Confirmed Uighurs Were Targeted In Wide-Ranging Phone Hacking Scheme BuzzFeed News · Ryan Mac
- Apple calls iPhone exploits ‘narrowly focused,’ accuses Google of ‘stoking fear’ Mashable · Karissa Bell
- Apple Responds To Google's iOS Security Blog Post With Its Own ‘Facts’ iOS Hacker · Zaib Ali
- Apple angry at Google for bursting iPhone security myth bubble MSPoweruser · Surur
- Apple Can Feel Its Reputation for Bulletproof Security Slipping Through Its Fingers Gizmodo · Rhett Jones
- Apple disputes Google's accuracy on recent iOS hacks, and they may be right ZDNet · Catalin Cimpanu
- Apple disputes Google's iPhone hack claim, says report ‘creates false impression’ Fox News · Chris Ciaccia
- Apple Lashes Out Against Google Over iPhone Hack Report — And They're Wrong Tom's Guide · Paul Wagenseil
- Apple Responds to Project Zero Michael Tsai
- Apple hits back at Google, accusing it of creating a ‘false impression’ of ‘mass exploitation’ around iPhone exploits Firstpost Tech
- Google stands by iOS vulnerability research following Apple rebuttal 9to5Google · Abner Li
- Apple, Google At Odds On iPhone Security Flaws Tied To Attacks PYMNTS.com
- Apple delivers message on iOS security in wake of Google's Project Zero report iDownloadBlog.com · Cody Lee
- Apple slams Google for hyperbolized reports of the recent mass exploitation of iPhones Neowin · Ather Fawaz
- Apple Downplays iPhone Security Issue Thurrott · Paul Thurrott
- Apple Disputes Google Project Zero Findings, Issues Statement Highlighting iOS Security iPhone Hacks · Mahit Huilgol
- Apple says China's Uighur Muslims were targeted in the recent iPhone hacking campaign MIT Technology Review · Patrick Howell O'Neill
- Google's Security Team Finds iPhones Infected by Monitoring Implants Observer · Harmon Leon
- Apple Finally Breaks Its Silence on iOS Hacking Campaign Wired · Lily Hay Newman
- Apple issues statement in response to Google security vulnerabilities report Macworld · Jason Cross
- Apple accuses Google of ‘stoking fear’ over iPhone hacking Telegraph · James Titcomb
- Apple just accused Google of iPhone security fake news [Update] SlashGear · Chris Davies
- Apple Pushes Back on iOS Security in Wake of Google's Report Daring Fireball · John Gruber
- Apple just put Google on blast for trying to stoke ‘fear among all iPhone users that their devices had been compromised’ Business Insider · Dave Smith
- Apple implies iPhones were hacked to spy on China's Uyghur Muslims Quartz · Mike Murphy
- Apple fires back at Google report over iPhone security flaws CNBC · Kif Leswing
- Apple doesn't want Google ‘stoking fear’ about serious iOS security exploits TechCrunch · Devin Coldewey
- Apple blasts Google Project Zero over iOS Uighur security claims VentureBeat · Jeremy Horwitz
- Apple responds vehemently to concerns about iOS security vulnerabilities Android Central · Danny Zepeda
- Apple attacks Google for ‘stoking fear’ over iPhone exploit Digital Trends · Christian de Looper
- Apple pushes back against Google on iOS hack targeting Muslims CNET · Alfred Ng
- Apple claps back at Google's claims of iPhone vulnerabilities Cult of Mac · Ed Hardy
- Apple accuses Google of ‘stoking fear’ over iPhone attack Financial Times · Patrick McGee
- Apple defends iOS security in new statement, takes issue with Google Project Zero findings 9to5Mac · Chance Miller
- Apple issues statement refuting Google's ‘false impression’ of iOS security AppleInsider · William Gallagher
- Apple Explains iOS Security and Those Exploits The Mac Observer · Andrew Orr
- Apple says Uighurs targeted in iPhone attack but disputes scope of Google's claim MacDailyNews
- Apple Slams Google's Claims Regarding Security Vulnerabilities in iOS iPhone in Canada Blog · Usman Qureshi
Discussion
-
@ydklijnsma
Yonathan Klijnsma
on x
One thing misunderstood slightly is the scope of the P0 & @volexity published campaign(s). This watering hole wasn't for everyone. Injections were planted on sites visited by specific communities some with country filtering. From Apr => Sept we only saw 166 payload requests f.e. …
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
Even former Apple security engineers think Apple's statement on this is bad. https://www.vice.com/... https://twitter.com/...
-
@juanandres_gs
J. A. Guerrero-Saade
on x
Wow @apple... 'It didn't happen the way they said it happened, but it happened, but it wasn't that bad, and it's just Uyghurs so you shouldn't care anyways. No advice to give here. Just move along.'
-
@martijn_grooten
Martijn Grooten
on x
I am grateful to @alexstamos for calling it what it is. A lot of our responses to digital threats are a variation of “well yes, but does it affect white people?” https://twitter.com/...
-
@dangoodin001
Dan Goodin
on x
.@RiskIQ's head of threat research says that the watering hole attacks that infected iOS users were indeed targeted. Assuming this is true, it doesn't excuse Apple's tone-deaf statement on Friday, but it would be noteworthy nonetheless. https://twitter.com/...
-
@ydklijnsma
Yonathan Klijnsma
on x
We'll break down a timeline with some additional infrastructure soon. General conclusion: the unsettling and ongoing surveillance state for the Uyghur community is perpetrated equally or even broader online. https://twitter.com/...
-
@gizmodo
@gizmodo
on x
Apple can feel its reputation for bulletproof security slipping through its fingers http://gizmo.do/gcjMkKg pic.twitter.com/jFWb3xBx6j
-
@slightlylate
Alex Russell
on x
In which @alexstamos says out loud what every security team on the planet has been DMing each other all morning. https://twitter.com/...
-
@edbott
Ed Bott
on x
Helluva thread. Apple's “circle the wagons” mentality is never more powerful than when they are confronted with a security issue. They haven't changed in years, and that's disappointing. https://twitter.com/...
-
@tomwarren
Tom Warren
on x
they didn't dispute the “indiscriminate” claim, they disputed the “exploiting iPhones en masse” claim.
-
@caseynewton
Casey Newton
on x
@Techmeme i always tell comms people ... if you're going to end in marketese, the least you can do is make it seemly
-
@tqbf
Thomas Ptacek
on x
Cosign all of this. Apple does astonishing technical work to secure the iOS platform, and this statement squanders the moral authority they earned. https://twitter.com/...
-
@patrickbeuth
Patrick Beuth
on x
This thread is one hell of a response to Apple's remarkable statement regarding a 5-exploit-chains-watering-hole- campaign against the Uighurs. It may sound somewhat unfair, but I think journalists would need to see Apple's proof for its claims before setting any record straight.…
-
@mattblaze
Matt Blaze
on x
This thread from @alexstamos. I hope my friends at Apple read it very carefully. There's important, hard-earned wisdom here. https://twitter.com/...
-
@zackwhittaker
Zack Whittaker
on x
Pretty much. Glad that Apple eventually said *something* but its statement comes across as crass and dismissive of the victims. https://twitter.com/...
-
@shiraovide
Shira Ovide
on x
This is savage and good. Humility is a highly useful quality in people, and in companies. https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
Story updated with comment from a former Apple security employee; calls out Apple's bad statement https://www.vice.com/... https://twitter.com/...
-
@itswillis
Tim Willis
on x
Contrary to some commentary, Project Zero's long form blogs are based on deep technical research into 0-days and novel exploitation, not a commentary on target populations or the wider threat space. Specifically though in this case (and as a one-off), I can tell you that...
-
@alexstamos
Alex Stamos
on x
Hey, Apple! I fixed your press release for you. https://twitter.com/...
-
@stevesi
m pszStevenSinofsky
on x
Microsoft hits back at Google's approach to security patches https://www.theverge.com/... via @Verge // from 2017
-
@josephfcox
Joseph Cox
on x
i don't think anything has ever brought the infosec community together as much as this unanimous response to apple's statement
-
@alexstamos
Alex Stamos
on x
Even if we accept Apple's framing that exploiting Uyghurs isn't as big a deal as Google makes it out to be, they have no idea whether these exploits were used by the PRC in more targeted situations. Dismissing such a possibility out of hand is extremely risky.
-
@alexstamos
Alex Stamos
on x
Third, the pivot to Apple's arrogant marketing is not only tone-deaf but really rings hollow to the security community when Google did all the heavy lifting here. I'm guessing we won't hear Tim talk about how they are going to do better on stage next week. https://twitter.com/...
-
@glitchiepixel
@glitchiepixel
on x
That shade tho pic.twitter.com/qrBmRKVYqR
-
@alexstamos
Alex Stamos
on x
Second, the word “China” is conspicuously absent, once again demonstrating the value the PRC gets from their leverage over the world's most valuable public company. To be fair, Google's post also didn't mention China. Their employees likely leaked attribution on background. https…
-
@tomwarren
Tom Warren
on x
Google has now responded to Apple's FUD accusations, standing by its research https://www.theverge.com/... https://twitter.com/...
-
@tomwarren
Tom Warren
on x
wowzers. Apple is accusing Google of spreading FUD and “stoking fear” about the iPhone security problems. Details here: https://www.theverge.com/... pic.twitter.com/oYFG4OcWpX
-
@chillmage
@chillmage
on x
Apple's defensive tone in this shot at Google is pretty callous toward the actual community of persecuted people who were affected by the vulnerability. Apple seems to erase them with its framing. And no mention of China at all? https://www.theverge.com/...
-
@reckless
Nilay Patel
on x
Good call out by @stevesi - Google's security team is very empowered and very aggressive in disclosing exploits across platforms, which you can have many kinds of feelings about https://twitter.com/...
-
@pwnallthethings
@pwnallthethings
on x
Apple statement about the iOS 0days found by Google's Threat Analysis Group https://www.apple.com/...
-
@reneritchie
Rene Ritchie
on x
China is conspicuous by its absence in both blog and retort. But deflecting from *Google* Project Zero releasing a targeted blog post months after a fix, creating widespread concern about a *competitor*, on the eve of Android 10/iOS 13, Pixel 4/iPhone 11 launch, is *bad* for PZ. …
-
@tomwarren
Tom Warren
on x
Apple's statement about Google is unnecessary. Apple is feeling the heat over its security problems over the past year. We've had lockscreen exploits, a big FaceTime bug, Walkie Talkie bug, iMessage flaws, 0days etc. Apple even unpatched a vulnerability, and iOS 13 is 🤔
-
@josephfcox
Joseph Cox
on x
The whole statement is pretty dismissive of the targeting of the Uighur minority. Notice it doesn't actually say how many devices were infected either, just tries to suggest smaller impact than Google said https://www.vice.com/... https://twitter.com/...
-
@reneritchie
Rene Ritchie
on x
Google's response only highlights the blindspot. No one, to my knowledge, took any issue with the technical discussion. But, Project Zero being owned by Google yet investigating competitors to Android and Chrome, needs to act above reproach. They failed and are still failing http…
-
@mattblaze
Matt Blaze
on x
Aside from everything else, using PR to minimize the significance of discovered vulnerabilities is number one on my list of things that make me trust a vendor's products less. The response to a flaw tells us far more about the security of a product than the flaw itself.
-
@anildash
Anil Dash
on x
I don't have an informed opinion about Apple & Google going back & forth on this security disclosure, but since when does Apple's style guide call an individual blog post “a blog”? That's like falling an article “a newspaper”. https://www.apple.com/... https://twitter.com/...
-
@carnage4life
Dare Obasanjo
on x
I love that Apple and Google are now targeting each other's core business under cover of virtue. Safari blocks ad trackers to protect user privacy. Google Zero spreads news about iPhone vulnerabilities claiming security. https://www.apple.com/...
-
@alexstamos
Alex Stamos
on x
Dear Apple employees: I have worked for companies that took too long to publicly address their responsibilities. This is not a path you want to take. Apple does some incredible security work, but this kind of legal/comms driven response can undermine that work. Demand better.
-
@alexstamos
Alex Stamos
on x
The use of multiple exploits against an oppressed minority in an authoritarian state makes the likely outcomes *worse* than the Huffington Post example a former Apple engineer posited. It is possible that this data contributed to real people being “reeducated” or even executed.
-
@reckless
Nilay Patel
on x
Feels like Apple walked into a lot more scrutiny by approaching its statement about iOS vulnerabilities as Google spreading FUD https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
Updated: Google has responded to Apple's response to Google's research. Project Zero stands by its technical analysis (doesn't actually say it stands specifically by the two year claim; but standing by research) https://www.vice.com/... pic.twitter.com/3BPhJfqWPW
-
@suka_hiroaki
Andreas Proschofsky
on x
Google: Hey, we found a bunch of full exploit chains for iOS, here is how to fix them. Apple: HOW DARE YOU!!! https://twitter.com/...
-
@yoda
Drew Olanoff
on x
and then google was all like nuhhh uhhh and then apple was like yes huhhhhh https://twitter.com/...
-
@technologypoet
Vanessa Harris
on x
Is anyone else sick and tired of the fear monger and aggressive security posturing of the Google Project Zero folks? Between spinning half truths about Apple and not giving Microsoft time until patch release before publishing one would think security was not their entire mandate.…
-
@markgurman
Mark Gurman
on x
First Siri privacy issues, now Apple puts Google malware finding controversy behind it ahead of Tuesday. They're blasting Google for posting about it 6 months after it was fixed. https://www.bloomberg.com/...
-
@reneritchie
Rene Ritchie
on x
While I can't condone the language, I can imagine those bars spat over a circa 1992 Ice Cube/Sir Jinx jam. https://twitter.com/...
-
@sushubh
@sushubh
on x
maybe start a similar platform and report all the bugs in android. https://twitter.com/...
-
@howelloneill
Patrick Howell O'Neill
on x
Apple confirms the iOS watering hole attack target Uighers. The company also takes a lot of issues with the Google report including the length of the attack and “the false impression of mass exploitation” they say it created. https://www.apple.com/...
-
@appleinsider
@appleinsider
on x
#Apple has challenged some of #Google's claims regarding iOS vulnerabilities, and stresses that its own ‘end-to-end’ security systems are ‘unmatched’ by its rivals. https://appleinsider.com/... pic.twitter.com/Fi2SDABIW6
-
@jamestitcomb
James Titcomb
on x
Apple is not pleased about last week's iPhone security disclosure from Google https://www.apple.com/...
-
@zackwhittaker
Zack Whittaker
on x
Apple has issued a rare statement about iOS security re: Google's iPhone exploits it posted last week, basically confirming my reporting about the attacks targeting Uyghur Muslims. https://www.apple.com/...
-
@martinsfp
Martin Sfp Bryant
on x
It took a while, but good to see Apple speak out about the iOS security holes flagged by Google last week. Its message? It's apparently not quite as serious as they suggested https://www.apple.com/...
-
@daveleebbc
Dave Lee
on x
Apple defends itself on the iOS hack publicised by Google last week. Says it was narrow and only lasted two months. It was targeted at Uighurs. https://www.apple.com/...
-
@tailosivetech
@tailosivetech
on x
https://www.apple.com/... the TLDR is “Google, go home”
-
@howelloneill
Patrick Howell O'Neill
on x
Very interesting and substantial disputing of facts here: “All evidence indicates that these website attacks were only operational for a brief period, roughly two months, not ‘two years’ as Google implies” https://www.apple.com/...
-
@mcwm
Mike Murphy
on x
Apple downplays the Google security team's research on iOS vulnerabilities from last week, saying it (rather interestingly) only affected websites targeted to the Uighur community. Doesn't say that it couldn't have happened elsewhere, though. via @qz https://qz.com/...
-
@reneritchie
Rene Ritchie
on x
Looks like Apple wasn't too happy with Google Project Zero's weirdly context-lacking blog post either. And they've responded. https://www.apple.com/...