The researcher who discovered the macOS keychain hole finally collaborates with Apple

Keychain app icon on the Dock

Days ago we commented on the work of Linus henze in relation to the discovery in the macOS keychain, which allowed through a exploit, access credentials and passwords contained in our Mac.

There are more and more users on macOS and therefore the industry is turning to this operating system, including security researchers. This time the researcher had decided do not share with Apple the discovery of the finding given that Apple does not reward researchers for security holes in macOS, which it does with iOS. But finally Henze has decided to share his find.

Henze does it for users, but Apple agrees to review its rewards policy, in this case for macOS. As we said, in iOS there is already a similar program since 2017. Until that moment, the errors found in macOS were insignificant, but time seems to indicate that these errors were there, but nobody had noticed them. The demand of researchers like Henze, is that their work is unpaid, as if it happens in other operating systems such as iOS.

Henze communication with Apple about the Keychain security hole

El investigador received a communication from Apple asking him to send them the details of the attack. I answer that I would if I could get a financial benefit from your work. Later, on February 8, he asks by email to AppleSecurity, the reasons why you don't have a bounty program on Mac users' bugs found.

In the first place, Apple ignored this email, because he did not want to deviate from the line applied to the rewards program of his products. Apple should review its policy, as it favors the same company, as well as users of an operating system that for a long time carried the emblem of the most secure operating system. With the information provided by Henze, surely Apple will prepare a patch that we will see in the next few days, available for installation.


Buy a domain
You are interested in:
The secrets to launching your website successfully

Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.