(Replying to PARENT post)
It simply isn't as easy as saying 'flag all reports with 'security vulnerability' in the submission for priority.' That could still be thousands of reports in the 'priority' queue, most of which some person would need to manually investigate one by one.
(Replying to PARENT post)
(Replying to PARENT post)
I think at this point, we need Tim Cook to write an apology piece about how they screwed up, how this won't happen again, and who got fired.
(Replying to PARENT post)
(Replying to PARENT post)
Something is quite wrong ...
(Replying to PARENT post)
(Replying to PARENT post)
I am not surprised about what happened at all. There is an argument that can be made about the fact that it took Apple so many years to finally implement group video call that they could take a little bit of time to do it right but other than that, I don't see how Apple could have prevented a bug that a person wasn't willing to disclose without having money first.
(Replying to PARENT post)
(Replying to PARENT post)
This stuff is hard.
(Replying to PARENT post)
(Replying to PARENT post)
[0] - https://resources.sei.cmu.edu/asset_files/SpecialReport/2017...
EDIT: Changed the link to the CERT guide for CVD.
(Replying to PARENT post)
What's especially pathetic is it doesn't matter what you're reporting - a grave security bug, a widespread hardware flaw, a longing for better functionality - Apple doesn't want to know. In fact they warned iOS developers against trying to get their attention.
https://medium.com/@krave/apple-s-app-store-review-process-i...