Live data from Hacker News

Million Dollar iOS9 Bug Bounty

zerodium.com

71–80 of 80 posts

Re: Million Dollar iOS9 Bug Bounty

#71
post #60
post #44

Earlier quoted context omitted.

The stagefright bugs gave control over the media-player daemon of Android. This daemon is not running as root, it's even jailed with SELinux, but it has some interesting permissions like microphone-access. Despite the media hype you can't root your phone with the stagefright bugs and so it wouldn't qualify for the bounty.

> Despite the media hype you can't root your phone with the stagefright bugs and so it wouldn't qualify for the bounty. Alone? No. As part of a "chain" of exploits, which is what this bounty is calling for, in concert with a privilege escalation? Yes. That bug allowed for remote and silent (due to executing in a way which would allow it to suppress notifications of the incoming message) arbitrary code execution as a…

> I presume the second bug they were using was an already-fixed kernel bug That's true, @jduck confirmed that on twitter. It's an old, fixed, bug that has nothing to do with stagefright and could be exploited by every app on the phone or every rce in any app on the phone.

> Regardless, the question you were responding to was more about how most of the exploits people put together do not satisfy the "remote" and "silent" parts, as opposed to the "I got root" part; the latter is comparatively easy

FWIW, "throughout the whole chain" was part of the question.

Re: Million Dollar iOS9 Bug Bounty

#73
post #58

Earlier quoted context omitted.

But who's going to release one publically when they can get $1 million for not doing so?

You can only get a million for a really impressive jailbreak. If it involves plugging the phone into your computer and downloading something, or even just pushing a button, it doesn't qualify for this bounty.

Fair enough; but if you're a hacker looking for exploits, what do you search for first?

Re: Million Dollar iOS9 Bug Bounty

#74
post #2

I for one actually feel much more secure knowing that iOS is so secure that $1 million is considered the public value of an exploit. Vupen bought flash zero days for $30,000 in the past so knowing that iOS exploits are now valued enough to attract this kind of bounty makes me much more confident script kiddies and scammers will not be able afford to attack me. And lets face it, we were never secure from the NSA in th…

Does anybody know if ZERODIUM is not the government/nsa?

Re: Million Dollar iOS9 Bug Bounty

#75

Sounds like ios8 will be the last jailbreakable version. Shame.

If the objective is (and correct me if it isn't) to be able to install arbitrary software on iOS, isn't that possible now with Xcode 7 and free provisioning? Personally I am hoping Github will be the new way through which to install non-store apps.

Re: Million Dollar iOS9 Bug Bounty

#76

Sounds like ios8 will be the last jailbreakable version. Shame.

I wonder if we will now see more hardware-based jailbreaks. It's a bit like with oil drilling. Once the easily accessible options are gone, people reconsider options that used to be considered too expensive to exploit or too damaging for the environment. Like fracking, oil sands, oil wells that are very deep or far up in the arctic, ... In the case of iOS explots, maybe you'll be able to jailbreak it over the lightni…

Heck, maybe it'll become economic for criminals to bribe and/or blackmail Apple engineers to put a backdoor into iOS, or to leak keys?

Or just become Apple engineers... I'm sure there's people out there who would be absolutely thrilled at the idea of working for Apple and writing code for iDevices while at the same time secretly subverting them.

Re: Million Dollar iOS9 Bug Bounty

#77
post #37
post #36

And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.

So, let me get this straight, this company is in the business of buying zero-day exploits and selling them to corporations and government organizations. How does this even exist? Is it legal? Can anyone buy and sell zero day exploits with total impunity?

An exploit is just an input to a bug that someone else put there. The idea of it being illegal fundamentally makes no sense.

Re: Million Dollar iOS9 Bug Bounty

#78
post #68

Sounds like ios8 will be the last jailbreakable version. Shame.

I am under the impression that the large companies in China (the equivalents of Google, Microsoft, and Ebay/PayPal), who have essentially been funding the jailbreaks of iOS 7 and 8, have been paying quite hefty sums as well (if not a million dollars, then I would argue "close enough" that even people who only see "sort of a problem" with selling weaponized exploits to arms dealers might still value the ethical advant…

Yeah, totally missed that they want silent deployment, and they lose the benefit of the owner unlocking the device. So this probably isn't actually a game changer at all.

Re: Million Dollar iOS9 Bug Bounty

#79

A million bucks for a iOS 9 vulnerability sounds nice. But is that worth having the death, imprisonment, or torture of possibly innocent people on your conscience? If a government is buying these vulns, there is no telling what they will do with them.

If you live in the US or Canada and voted for a recent government, this is already on your conscience.

The realization that there's a dirty, dirty underside to our standard of living seems to polarize people. Some dedicate themselves to helping. Some conclude that the world is run by gangsters, so they might as well pick a gang and profit. Most, either never realize or just decide that the problem is too big and they should focus on their own little islands of comfort.

Re: Million Dollar iOS9 Bug Bounty

#80

I have to wonder: what stops someone from selling the "exclusive" rights to an exploit, waiting for the check to clear, and then disclosing it privately to the vendor to get fixed?

If you're dealing with bad people, do you really want to screw them over?
Post reply on HN