Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Props to the author. One small critique though:

> I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7

It would have been clearer if in each of the 4 vulnerabilities the timeline was given. The article only gives a timeline for the last vuln (the fixed one).



The second sentence of the article gives a sufficient timeline.

> I've reported four 0-day vulnerabilities this year between March 10 and May 4

So the vulnerabilities were reported at least 140 days ago. He also mentions 3 upgrades of iOS were published after his reports.


Yeah, I quoted it myself. My point is that the article is formatted in a confusing way. It's formatted into 4 vulnerabilities, but only 1 of them has a timeline, which immediately made me wonder why there weren't 3 more timelines.

Even though I read the sentence at the beginning saying the author reported all 4 to Apple, when I saw there was a reporting timeline on 1 vuln but not the other 3 I started doubting my own memory and thought maybe the author only reported 1 vuln to Apple. I had to go back and re-read the first paragraph again to reassure myself that all 4 were reported to Apple.


I've updated the article to include a timeline for each vulnerability


Thanks!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: