The Talk Show with John Gruber
The Talk Show with John Gruber

162: ‘Special Bullying Venue’ With Glenn Fleishman

Special guest Glenn Fleishman returns to the show. Topics include security vulnerabilities on MacOS and iOS, ransomware, counterfeit products and outright fraud on Amazon, and online harassment and “free speech”.

Featured Speakers

John Gruber Host

Topics Discussed

Episode Summary

Executive Summary: The discussion ranges from Apple security vulnerabilities and the economics of malware, to the limits of DRM, repair rights, Amazon marketplace fraud, Twitter abuse and moderation, and the rise of Slack as a private alternative to noisy public discourse. A central theme is that technology risk is often shaped less by absolute security and more by target size, incentives, and platform design choices.

Main Topics: Apple image-parsing vulnerability and patching (Priority: 5/5): A severe TIFF/image parsing flaw in Apple’s OSes could allow code execution merely by rendering a malicious image in Safari, Messages, or Quick Look. The hosts stress that Apple patched it responsibly and that users who update are protected. Mac security, malware economics, and false equivalence (Priority: 5/5): The conversation pushes back on the idea that Macs are immune to malware. Apple devices have been lucky partly because they are smaller targets, but rapid updates, sandboxing, and a shorter vulnerable tail make them less attractive to mass attackers. DRM, DMCA Section 1201, and right-to-repair (Priority: 4/5): The speakers criticize legal restrictions that limit reverse engineering and repair, arguing that the DMCA’s anti-circumvention rules chill innovation and self-repair. They contrast manufacturer freedom to lock down products with the public’s need to examine and repair them. Amazon marketplace counterfeit and co-mingled inventory problems (Priority: 5/5): Amazon is portrayed as failing at trust and inventory integrity, allowing counterfeit or misleading third-party products to ride on legitimate listings. Examples include Cuisinart kettles and Birkenstock’s reported pullout over counterfeit concerns. Twitter harassment, moderation, and the Milo Yiannopoulos/Leslie Jones incident (Priority: 5/5): The show examines how Twitter enables asymmetric harassment, especially against women and minorities, and why suspending abusive accounts is a platform-safety issue rather than censorship. It also debates how much offensive speech should be allowed versus targeted abuse. Slack as a safer, more controlled communication layer (Priority: 3/5): The closing segment promotes Slack and the hosts’ use of private or semi-private Slack communities as a more civil alternative to public Twitter conversations, with a plug for a guide to Slack basics and administration.

Key Arguments: Apple’s security flaw was severe because rendering a malicious image could trigger memory corruption and code execution without user intent beyond viewing the content. Mac/iOS security is not absolute immunity; it is partly a function of Apple’s strong update culture and the smaller incentive for mass malware authors to target Apple platforms. False equivalence in reporting distorts security stories when unpatched, actively exploited Android issues are compared to patched Apple flaws with no known exploits in the wild. DRM law and Section 1201 of the DMCA can suppress legitimate reverse engineering and repair, harming consumers and innovators more than it protects rights holders. Amazon’s trust problem is structural: commingled inventory and weak seller vetting make it hard to know whether a listing is authentic, counterfeit, or merely priced via an opaque third party. Twitter’s core problem is not merely offensive opinions but organized, mass, targeted harassment that makes the platform hostile for many users, especially public women and minorities. Verification and better abuse controls can help reduce asymmetrical harassment, but the platform must distinguish between offensive speech and abusive conduct. Slack’s appeal is that it enables controlled, semi-private discourse with administrative moderation, which is increasingly attractive as public platforms become more toxic.

Data Points: Apple security flaws discovered: 5 - Cisco Talos researcher found five previously undiscovered image-format vulnerabilities. Major severe flaws among them: 3 or 4 - Most of the discovered bugs were described as reasonably to fairly severe. Affected Apple OSes: iOS, OS X/macOS, tvOS, watchOS - The TIFF/image parsing bug was described as affecting Apple’s current OS family. Apple support window mentioned: many years - Apple was described as supporting systems back many years, reducing fragmentation. Mac update lag examples: Yosemite and El Capitan - The speaker noted that older Mac systems may still be vulnerable if not updated. Stage Fright comparison: hundreds of millions - Android Stage Fright was cited as affecting a very large number of devices, possibly hundreds of millions still vulnerable. Ransomware variant count: 6 million unique variants - One speaker cited F-Secure research on the scale of ransomware variants. Average ransomware demand: about $600 - The discussion noted that ransomware demands have risen from a few hundred dollars to around this level. Ransomware negotiation example: $17,000 - A hospital reportedly paid this amount to restore access after an infection. Amazon price examples: $80, $100, $67 - Cuisinart kettle pricing varied by seller and fulfillment source, illustrating marketplace opacity. Birkenstock pullout timing: January - Birkenstock was said to be exiting Amazon after counterfeit concerns, with timing constrained by contracts/inventory. Gift-card/charge fraud example: $160,000 - A speaker mentioned a case of bank-account theft after a home sale that took six months to resolve. Casper warranty period: 100 nights - Casper’s home trial and refund policy were highlighted. Casper price examples: $750 / $850 / $950 - Listed mattress prices for full, queen, and king sizes in the ad read. Apple Pay rollout note: roughly 10 days - The speaker observed Apple Pay becoming newly available at some Starbucks locations in the previous days. Twitter account deletion behavior: permanent - A permanently suspended Twitter account was described as never becoming usable again. Retweet counts for notable tweets: 3,100 and 3,834 - Two highly shared tweets about Obama/Clinton family hypotheticals were referenced. Other tweet performance: 6,000 retweets - A Brexit-related tweet was described as receiving thousands of retweets.

Pivotal Quotes: "“We’ve just been really lucky. It’s just the target’s been small.”" — Speaker discussing Mac security: Explaining why Macs historically saw less malware than Windows rather than being inherently immune. "“Merely by rendering the preview, it would have to parse the file enough that this condition could be exploited.”" — Speaker discussing the TIFF flaw: Describing why the image-parsing bug was so dangerous and insidious. "“Twitter is more and more getting a reputation as a place where if you participate, you have a very good chance of being abused.”" — Speaker discussing platform safety: Summarizing the problem of harassment and the need for stronger moderation tools.

Implications: Users should update aggressively, distrust marketplace listings, and expect more conflict over repair rights and platform moderation. Platforms and lawmakers face pressure to balance openness with safety, authenticity, and consumer trust.

🔓 Sign Up for Unlimited Episode Search

About The Talk Show with John Gruber

The director’s commentary track for Daring Fireball. Long digressions on Apple, technology, design, movies, and more.

View all episodes from The Talk Show with John Gruber