Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

33% Positive

Analyzed from 288 words in the discussion.

Trending Topics

#zero#macos#clickfix#code#meta#handle#attack#social#system#level

Discussion (30 Comments)Read Original on HackerNews

gavinrayabout 1 hour ago
The "zero day" is something they call a "ClickFix Attack"

Upon Googling "ClickFix":

  > "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"
I'm sorry, that's not a zero-day, that's idiocy that's as old as time.
failbufferabout 1 hour ago
We filed a bug report but the original maintainer seems to have dropped offline. The community's had some success in correcting bugs with low-level hacking, but it's hard to make progress without the source code.
theultdev26 minutes ago
words don't seem to mean anything anymore.

clickbait headline should be changed, not a 0-day.

willtemperleyabout 2 hours ago
Who in their right mind would install a Meta AI with near admin privileges?
imageticabout 2 hours ago
We all fear the true answer to that question.
snapcasterabout 2 hours ago
almost every normal person
yalokabout 2 hours ago
> macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device

Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…

sippingabonedryabout 2 hours ago
Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.
axusabout 2 hours ago
Did the band end up getting money for that?
echelonabout 1 hour ago
Presumably. They changed their handle on non-Meta social networks to match at around the same time as the Meta handle change.
ilabout 1 hour ago
How is this a serious zero day if it requires local code execution to run?
peri-clabout 2 hours ago
I'm confused what the vulnerability is. Does macOS have some specific function for protecting key material, that it's unexpected that if you execute user-privileged code locally, outside of a sandbox, it gets full read access?
voxic11about 2 hours ago
Yeah macOS security is capability based rather than purely identity based. So if you don't pass the required entitlements to an application then it cannot do stuff like read from the system keychain even if its running as your user.
adamsb6about 1 hour ago
Is 12 hours to deliver a local privilege escalation fix not a good response time?
SoftTalkerabout 2 hours ago
A zero day? Of course it does. It likely has many. Given the history of software, it's impossible to think it wouldn't.