Hacker News new | ask | show | jobs
by BrentOzar 1160 days ago
Talk to a few of your trusted peers about the effect (not the mechanics) of the vulnerability.

As in, "If you hand me your iPhone, I can unlock it without knowing your password." Don't tell them how, just describe in 1 sentence what access you need, and what you're able to do. If your trusted peers (not drinking buddies who do other jobs) are impressed, then widen the circle a little - tell strangers (like HN readers) that same thing, and ask if it's a vulnerability.

It'll just help you have a sanity check about whether or not it's actually a vulnerability that Apple needs to fix, or perhaps it's someone else's, or not really that big of a deal.

1 comments

Maybe I'm drinking my own koolaid here but I don't feel safe when I use this Apple device regularly.

How does Apple establish "prior art" if I go public with it? Can someone else claim credit for it?

> How does Apple establish "prior art" if I go public with it?

You're not going public with the HOW, only the effects. Reread my comment about asking your trusted peers, please.

And then send Apple my survey results?! Not seeing the light at the end of the tunnel here.
You're assuming your peers will agree with you. I'm gently suggesting that they may not, and you need that check.

You might be right. It might be the next Meltdown vulnerability. But it might not, and Apple already told you it isn't, and that's why you need to talk to your peers.