Live data from Hacker News

Million Dollar iOS9 Bug Bounty

zerodium.com

11–20 of 80 posts

Re: Million Dollar iOS9 Bug Bounty

#11
post #2

I for one actually feel much more secure knowing that iOS is so secure that $1 million is considered the public value of an exploit. Vupen bought flash zero days for $30,000 in the past so knowing that iOS exploits are now valued enough to attract this kind of bounty makes me much more confident script kiddies and scammers will not be able afford to attack me. And lets face it, we were never secure from the NSA in th…

This is purely market value. If iOS simply had less users, the price would be lower. So I think your conclusion of it being more secure because of this is incorrect. About less people being able to afford it - this again depends on what ZERODIUM intends to do with it. They may sell it for cheap and count on a large number of sales because, again, iOS is so popular.

Hacking Team: a zero-day market case study [1] seems to support the idea that iOS exploits are scarce. Especially compared to Android (when using your "less users" perspective).

"Mobile: VUPEN offered several different remote code execution and local privilege escalation exploits for Android; however, not all of them were 0day and Hacking Team deemed that the prices were too high to purchase. Though there was interest in purchasing exploits for iOS, VUPEN said they were limited to certain customers, presumably high-paying government agencies." [1]

"iOS exploit pricing: Adriel stated he was supply-constrained for iOS RCE exploits because exploit developers frequently had their own connections to sell them, and that he believed that such exploits were overpriced. An exclusive exploit sale could cost over a million dollars, [...]." [1]

[1] https://news.ycombinator.com/item?id=9949818

Re: Million Dollar iOS9 Bug Bounty

#13
Is this a Zerodium ad masquing the politically incorrect PR of "zerodium has 0day exploits available for sale"? I mean how else would anyone advertise availability of 0day without compromising their credibility? $1M per exploit would sure get you lots of press.

Re: Million Dollar iOS9 Bug Bounty

#14
post #2

I for one actually feel much more secure knowing that iOS is so secure that $1 million is considered the public value of an exploit. Vupen bought flash zero days for $30,000 in the past so knowing that iOS exploits are now valued enough to attract this kind of bounty makes me much more confident script kiddies and scammers will not be able afford to attack me. And lets face it, we were never secure from the NSA in th…

This is purely market value. If iOS simply had less users, the price would be lower. So I think your conclusion of it being more secure because of this is incorrect. About less people being able to afford it - this again depends on what ZERODIUM intends to do with it. They may sell it for cheap and count on a large number of sales because, again, iOS is so popular.

Did you read the announcement?

> Apple iOS, like all operating system, is often affected by critical security vulnerabilities, however due to the increasing number of security improvements and the effectiveness of exploit mitigations in place, Apple's iOS is currently the most secure mobile OS. But don't be fooled, secure does not mean unbreakable, it just means that iOS has currently the highest cost and complexity of vulnerability exploitation and here's where the Million Dollar iOS 9 Bug Bounty comes into play.

BTW, I guess Flash is as popular as iOS9 (the Steam hardware survey used to show that 99.9% of the Steam users had Flash installed), yet, as stirlo says, they only paid up to $30k for Flash exploits.

Re: Million Dollar iOS9 Bug Bounty

#16

I have to wonder: what stops someone from selling the "exclusive" rights to an exploit, waiting for the check to clear, and then disclosing it privately to the vendor to get fixed?

Trust. That sounds funny, given that it's a grey market, but there were excerpts from the Hacking Team email dump where they talked extensively about which exploit providers were high quality, reliable, etc.

Someone absolutely can try and play games, but the people they sell to will do their best to determine whether that's happening and penalize them.

Re: Million Dollar iOS9 Bug Bounty

#17
post #14

Earlier quoted context omitted.

This is purely market value. If iOS simply had less users, the price would be lower. So I think your conclusion of it being more secure because of this is incorrect. About less people being able to afford it - this again depends on what ZERODIUM intends to do with it. They may sell it for cheap and count on a large number of sales because, again, iOS is so popular.

Did you read the announcement? > Apple iOS, like all operating system, is often affected by critical security vulnerabilities, however due to the increasing number of security improvements and the effectiveness of exploit mitigations in place, Apple's iOS is currently the most secure mobile OS. But don't be fooled, secure does not mean unbreakable, it just means that iOS has currently the highest cost and complexity…

I was replying to stirlo's deduction, which I felt was wrong, not the original announcement.

You do make a great point with that Flash comparison, though.

Re: Million Dollar iOS9 Bug Bounty

#18

Sounds like ios8 will be the last jailbreakable version. Shame.

If the last 8 versions were jailbreakable I think this one will be too - eventually - but it is certainly the case that devices are becoming more secure both for and against their owners. The tension between freedom and security is definitely increasing.

Re: Million Dollar iOS9 Bug Bounty

#19
I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria?

It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all security checks to allow full root access.

Re: Million Dollar iOS9 Bug Bounty

#20

I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…

You used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.
Post reply on HN