Sounds like ios8 will be the last jailbreakable version. Shame.
Million Dollar iOS9 Bug Bounty
61–70 of 80 posts
Re: Million Dollar iOS9 Bug Bounty
#62And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.
If I had a bug that met the criteria I'd give Apple first dibs. That way the bug would get fixed, and I'd still get my $1M.
Re: Million Dollar iOS9 Bug Bounty
#63Has anyone tried a really long password ;-)
Re: Million Dollar iOS9 Bug Bounty
#64Earlier quoted context omitted.
If the last 8 versions were jailbreakable I think this one will be too - eventually - but it is certainly the case that devices are becoming more secure both for and against their owners. The tension between freedom and security is definitely increasing.
But who's going to release one publically when they can get $1 million for not doing so?
Re: Million Dollar iOS9 Bug Bounty
#65Earlier quoted context omitted.
Stagefright (Remote Android code execution) does exactly that http://arstechnica.com/security/2015/07/950-million-android-...
Stagefright was not a rootable exploit.
Re: Million Dollar iOS9 Bug Bounty
#66Re: Million Dollar iOS9 Bug Bounty
#67Re: Million Dollar iOS9 Bug Bounty
#68Sounds like ios8 will be the last jailbreakable version. Shame.
(Further, I will point out that most jailbreaks don't even involve a remote and silent deployment: while there are tons of possible exploitable bugs found in WebKit all the time, Apple has sandboxed the living daylights out of that process, and a lot of the kernel bugs people find don't work even in processes that have the lightest of sandboxes. The standard stack for a jailbreak is usually something that requires the device to be pincode unlocked and plugged into a computer that the device has been told to "trust", in order to take advantage of the attack surface provided by the protocols iTunes and Xcode use to talk to the device over USB, which often will touch the filesystem in complex ways, at least indirectly if not directly as part of something like "restore a backup". If you find this kind of limited stack, you usually don't just "throw it back" and keep fishing ;P.)
Re: Million Dollar iOS9 Bug Bounty
#69Earlier quoted context omitted.
Seems to just be a list of iOS 9 supported devices...
iPhone 4s can run iOS 9 and is not on the list.
they always give users the 'last' iOS version but I highly doubt any work will go into patching it in future.
Re: Million Dollar iOS9 Bug Bounty
#70And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.
It's a win-win for Zerodium. They are getting free publicity for having the biggest bug bounty ever, and if somebody actually does submit a working exploit, they sell it to their clients for a hefty profit. I'm sure there are government agencies that would pay well over a million for the ability to infect any IOS device silently and easily.