Hacker News new | ask | show | jobs
by crimsontech 959 days ago
Fully agree. I work in security and sent Apple a bypass for child restriction policies on iOS, they told me to send it to feedback.

Testing, reproducing, writing it up all takes time and effort. I didn’t want anything from them other than for it to be fixed, I have kids with iPhones.

It’s no different than other companies though, I sent a remote code execution to Cisco and they just replied that they already knew about it but the product was approaching end of life so they wouldn’t fix it.

I’ve stumbled across so many vulnerabilities over the years and I tend to just ignore them unless I’m being paid to find them. It’s not worth the frustration.

2 comments

> It’s no different than other companies though, I sent a remote code execution to Cisco and they just replied that they already knew about it but the product was approaching end of life so they wouldn’t fix it.

Huh? That sounds very different from Apple. In that instance, the communication is professional, mature, and respectful of your time and effort.

To be fair, remote code execution and "I got around the child lock on this device" are somewhat different in severity.
> remote code execution and "I got around the child lock on this device" are somewhat different in severity

You’ll notice that the recipients of both reports responded similarly, with apathy. Perhaps that was the point of juxtaposing them?