Hacker News new | past | comments | ask | show | jobs | submit login

That's a view of the world for sure :) Personally I don't think it's irrelevant. From a threat modelling perspective, exposed services are expected to be attacked.

Client services with zero interaction, have traditionally been regarded as safer, usually for client side attacks we'd expect a trigger from user action (e.g. a link being clicked, a PDF file being opened).

Just because you don't find something to be useful as a distinction in your line of work doesn't necessarily mean that it's not useful to anyone ...




Client services like these are also expected to be attacked.

iMessage isn’t meaningfully different from Apache, instead of listening on a TCP number it listens on your Apple user id.


This is really flyfucking of the worst kind: the kind that doesn't serve any useful purpose.

From any useful perspective, RCE and zero-click exploits are the same thing. The latter is just a fancy name for the moron journalists like the one who wrote this article to bandy about to lure in some readers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: