Apple accuses Google's Project Zero of stoking fear by creating a “false impression of mass exploitation”, says the sophisticated attack was narrowly focused
And They're Wrong PYMNTS.com : Apple, Google At Odds On iPhone Security Flaws Tied To Attacks Michael Tsai : Apple Responds to Project Zero Abner Li / 9to5Google : Google stands by iOS vulnerability research following Apple rebuttal Catalin Cimpanu / ZDNet : Apple disputes Google's accuracy on recent iOS hacks, and they may be right Karissa Bell / Mashable : Apple calls iPhone exploits ‘narrowly focused,’ accuses Google of ‘stoking fear’ Stephen Nellis / Reuters : Apple says Uighurs targeted in iPhone attack but disputes Google findings Firstpost Tech : Apple hits back at Google, accusing it of creating a ‘false impression’ of ‘mass exploitation’ around iPhone exploits Cody Lee / iDownloadBlog.com : Apple delivers message on iOS security in wake of Google's Project Zero report Juli Clover / MacRumors : Apple Disputes Some Details of Google's Project Zero Report on iOS Security Vulnerabilities Mark Gurman / Bloomberg : Apple Disputes Google Description of a Widespread iPhone Attack Ather Fawaz / Neowin : Apple slams Google for hyperbolized reports of the recent mass exploitation of iPhones Paul Thurrott / Thurrott : Apple Downplays iPhone Security Issue Mahit Huilgol / iPhone Hacks : Apple Disputes Google Project Zero Findings, Issues Statement Highlighting iOS Security Ryan Mac / BuzzFeed News : Apple Has Confirmed Uighurs Were Targeted In Wide-Ranging Phone Hacking Scheme Patrick Howell O'Neill / MIT Technology Review : Apple says China's Uighur Muslims were targeted in the recent iPhone hacking campaign Harmon Leon / Observer : Google's Security Team Finds iPhones Infected by Monitoring Implants Lily Hay Newman / Wired : Apple Finally Breaks Its Silence on iOS Hacking Campaign Jason Cross / Macworld : Apple issues statement in response to Google security vulnerabilities report Ed Hardy / Cult of Mac : Apple claps back at Google's claims of iPhone vulnerabilities MacDailyNews : Apple says Uighurs targeted in iPhone attack but disputes scope of Google's claim James Titcomb / Telegraph : Apple accuses Google of ‘stoking fear’ over iPhone hacking Danny Zepeda / Android Central : Apple responds vehemently to concerns about iOS security vulnerabilities Patrick McGee / Financial Times : Apple accuses Google of ‘stoking fear’ over iPhone attack Chris Davies / SlashGear : Apple just accused Google of iPhone security fake news [Update] Alfred Ng / CNET : Apple pushes back against Google on iOS hack targeting Muslims John Gruber / Daring Fireball : Apple Pushes Back on iOS Security in Wake of Google's Report Dave Smith / Business Insider : Apple just put Google on blast for trying to stoke ‘fear among all iPhone users that their devices had been compromised’ Mike Murphy / Quartz : Apple implies iPhones were hacked to spy on China's Uyghur Muslims Kif Leswing / CNBC : Apple fires back at Google report over iPhone security flaws Devin Coldewey / TechCrunch : Apple doesn't want Google ‘stoking fear’ about serious iOS security exploits Jeremy Horwitz / VentureBeat : Apple blasts Google Project Zero over iOS Uighur security claims Christian de Looper / Digital Trends : Apple attacks Google for ‘stoking fear’ over iPhone exploit Tweets: Stefan Esser / @i0n1c : You cannot classify Corellium as security researchers when their product is targetted at 0-say sales companies. Also Apple management has been attacking P0 (behind curtains) for a long time. https://twitter.com/... Alex Stamos / @alexstamos : Hey, Apple! I fixed your press release for you. https://twitter.com/... m pszStevenSinofsky / @stevesi : Microsoft hits back at Google's approach to security patches https://www.theverge.com/... via @Verge // from 2017 Lorenzo Franceschi-Bicchierai / @lorenzofb : Even former Apple security engineers think Apple's statement on this is bad. https://www.vice.com/... https://twitter.com/... Alex Stamos / @alexstamos : Even if we accept Apple's framing that exploiting Uyghurs isn't as big a deal as Google makes it out to be, they have no idea whether these exploits were used by the PRC in more targeted situations. Dismissing such a possibility out of hand is extremely risky. Joseph Cox / @josephfcox : i don't think anything has ever brought the infosec community together as much as this unanimous response to apple's statement Alex Stamos / @alexstamos : Third, the pivot to Apple's arrogant marketing is not only tone-deaf but really rings hollow to the security community when Google did all the heavy lifting here. I'm guessing we won't hear Tim talk about how they are going to do better on stage next week. https://twitter.com/... Alex Stamos / @alexstamos : Second, the word “China” is conspicuously absent, once again demonstrating the value the PRC gets from their leverage over the world's most valuable public company. To be fair, Google's post also didn't mention China. Their employees likely leaked attribution on background. https://twitter.com/... Rene Ritchie / @reneritchie : China is conspicuous by its absence in both blog and retort. But deflecting from *Google* Project Zero releasing a targeted blog post months after a fix, creating widespread concern about a *competitor*, on the eve of Android 10/iOS 13, Pixel 4/iPhone 11 launch, is *bad* for PZ. https://twitter.com/... Dan Goodin / @dangoodin001 : .@RiskIQ's head of threat research says that the watering hole attacks that infected iOS users were indeed targeted. Assuming this is true, it doesn't excuse Apple's tone-deaf statement on Friday, but it would be noteworthy nonetheless. https://twitter.com/... @glitchiepixel : That shade tho pic.twitter.com/qrBmRKVYqR Tom Warren / @tomwarren : Google has now responded to Apple's FUD accusations, standing by its research https://www.theverge.com/... https://twitter.com/... Tom Warren / @tomwarren : wowzers. Apple is accusing Google of spreading FUD and “stoking fear” about the iPhone security problems. Details here: https://www.theverge.com/... pic.twitter.com/oYFG4OcWpX Joseph Cox / @josephfcox : The whole statement is pretty dismissive of the targeting of the Uighur minority. Notice it doesn't actually say how many devices were infected either, just tries to suggest smaller impact than Google said https://www.vice.com/... https://twitter.com/... @pwnallthethings : Apple statement about the iOS 0days found by Google's Threat Analysis Group https://www.apple.com/... @chillmage : Apple's defensive tone in this shot at Google is pretty callous toward the actual community of persecuted people who were affected by the vulnerability. Apple seems to erase them with its framing. And no mention of China at all? https://www.theverge.com/... Nilay Patel / @reckless : Good call out by @stevesi - Google's security team is very empowered and very aggressive in disclosing exploits across platforms, which you can have many kinds of feelings about https://twitter.com/... Tom Warren / @tomwarren : Apple's statement about Google is unnecessary. Apple is feeling the heat over its security problems over the past year. We've had lockscreen exploits, a big FaceTime bug, Walkie Talkie bug, iMessage flaws, 0days etc. Apple even unpatched a vulnerability, and iOS 13 is 🤔 Alex Stamos / @alexstamos : The use of multiple exploits against an oppressed minority in an authoritarian state makes the likely outcomes *worse* than the Huffington Post example a former Apple engineer posited. It is possible that this data contributed to real people being “reeducated” or even executed. Tom Warren / @tomwarren : they didn't dispute the “indiscriminate” claim, they disputed the “exploiting iPhones en masse” claim. Thomas Ptacek / @tqbf : Cosign all of this. Apple does astonishing technical work to secure the iOS platform, and this statement squanders the moral authority they earned. https://twitter.com/... Patrick Beuth / @patrickbeuth : This thread is one hell of a response to Apple's remarkable statement regarding a 5-exploit-chains-watering-hole- campaign against the Uighurs. It may sound somewhat unfair, but I think journalists would need to see Apple's proof for its claims before setting any record straight. https://twitter.com/... Rene Ritchie / @reneritchie : Google's response only highlights the blindspot. No one, to my knowledge, took any issue with the technical discussion. But, Project Zero being owned by Google yet investigating competitors to Android and Chrome, needs to act above reproach. They failed and are still failing https://twitter.com/... Matt Blaze / @mattblaze : Aside from everything else, using PR to minimize the significance of discovered vulnerabilities is number one on my list of things that make me trust a vendor's products less. The response to a flaw tells us far more about the security of a product than the flaw itself. Anil Dash / @anildash : I don't have an informed opinion about Apple & Google going back & forth on this security disclosure, but since when does Apple's style guide call an individual blog post “a blog”? That's like falling an article “a newspaper”. https://www.apple.com/... https://twitter.com/... Dare Obasanjo / @carnage4life : I love that Apple and Google are now targeting each other's core business under cover of virtue. Safari blocks ad trackers to protect user privacy. Google Zero spreads news about iPhone vulnerabilities claiming security. https://www.apple.com/... Joseph Cox / @josephfcox : Story updated with comment from a former Apple security employee; calls out Apple's bad statement https://www.vice.com/... https://twitter.com/... Alex Stamos / @alexstamos : Dear Apple employees: I have worked for companies that took too long to publicly address their responsibilities. This is not a path you want to take. Apple does some incredible security work, but this kind of legal/comms driven response can undermine that work. Demand better. Nilay Patel / @reckless : Feels like Apple walked into a lot more scrutiny by approaching its statement about iOS vulnerabilities as Google spreading FUD https://twitter.com/... Joseph Cox / @josephfcox : Updated: Google has responded to Apple's response to Google's research. Project Zero stands by its technical analysis (doesn't actually say it stands specifically by the two year claim; but standing by research) https://www.vice.com/... pic.twitter.com/3BPhJfqWPW Andreas Proschofsky / @suka_hiroaki : Google: Hey, we found a bunch of full exploit chains for iOS, here is how to fix them. Apple: HOW DARE YOU!!! https://twitter.com/... Drew Olanoff / @yoda : and then google was all like nuhhh uhhh and then apple was like yes huhhhhh https://twitter.com/... Vanessa Harris / @technologypoet : Is anyone else sick and tired of the fear monger and aggressive security posturing of the Google Project Zero folks? Between spinning half truths about Apple and not giving Microsoft time until patch release before publishing one would think security was not their entire mandate. https://twitter.com/... Mark Gurman / @markgurman : First Siri privacy issues, now Apple puts Google malware finding controversy behind it ahead of Tuesday. They're blasting Google for posting about it 6 months after it was fixed. https://www.bloomberg.com/... Rene Ritchie / @reneritchie : While I can't condone the language, I can imagine those bars spat over a circa 1992 Ice Cube/Sir Jinx jam. https://twitter.com/... @sushubh : maybe start a similar platform and report all the bugs in android. https://twitter.com/... Patrick Howell O'Neill / @howelloneill : Apple confirms the iOS watering hole attack target Uighers. The company also takes a lot of issues with the Google report including the length of the attack and “the false impression of mass exploitation” they say it created. https://www.apple.com/... @appleinsider : #Apple has challenged some of #Google's claims regarding iOS vulnerabilities, and stresses that its own ‘end-to-end’ security systems are ‘unmatched’ by its rivals. https://appleinsider.com/... pic.twitter.com/Fi2SDABIW6 James Titcomb / @jamestitcomb : Apple is not pleased about last week's iPhone security disclosure from Google https://www.apple.com/... Tim Willis / @itswillis : Contrary to some commentary, Project Zero's long form blogs are based on deep technical research into 0-days and novel exploitation, not a commentary on target populations or the wider threat space. Specifically though in this case (and as a one-off), I can tell you that... Zack Whittaker / @zackwhittaker : Apple has issued a rare statement about iOS security re: Google's iPhone exploits it posted last week, basically confirming my reporting about the attacks targeting Uyghur Muslims. https://www.apple.com/... Martin Sfp Bryant / @martinsfp : It took a while, but good to see Apple speak out about the iOS security holes flagged by Google last week. Its message? It's apparently not quite as serious as they suggested https://www.apple.com/... Dave Lee / @daveleebbc : Apple defends itself on the iOS hack publicised by Google last week. Says it was narrow and only lasted two months. It was targeted at Uighurs. https://www.apple.com/... Patrick Howell O'Neill / @howelloneill : Very interesting and substantial disputing of facts here: “All evidence indicates that these website attacks were only operational for a brief period, roughly two months, not ‘two years’ as Google implies” https://www.apple.com/... @tailosivetech : https://www.apple.com/... the TLDR is “Google, go home” Mike Murphy / @mcwm : Apple downplays the Google security team's research on iOS vulnerabilities from last week, saying it (rather interestingly) only affected websites targeted to the Uighur community. Doesn't say that it couldn't have happened elsewhere, though. via @qz https://qz.com/... Rene Ritchie / @reneritchie : Looks like Apple wasn't too happy with Google Project Zero's weirdly context-lacking blog post either. And they've responded. https://www.apple.com/... Alex Stamos / @alexstamos : [Thread] Apple's response to Project Zero downplays exploits against an oppressed minority, discounts the risk of other targets, and ends in unseemly marketese