Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
1–10 of 308 posts
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#2Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#3I wonder how they're going to manage this. I could easily see some less than ethical researchers applying for this program and selling all the 0 days they find to the usual suspects rather than informing Apple.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#4>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#5Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-rem... ?
> The full $1 million will go to researchers who can find a
> hack of the kernel—the core of iOS—with zero clicks required
> by the iPhone owner.
Which one of the vulnerabilities discovered met that criteria?Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#6>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…
By vetting applications, presumably. I would imagine it's mostly professors in well known universities and corporations closely affiliated with Apple getting access.
I’d say that the researchers have a pretty strong incentive not to screw around with Apple.
It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#7Earlier quoted context omitted.
By vetting applications, presumably. I would imagine it's mostly professors in well known universities and corporations closely affiliated with Apple getting access.
No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#8>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…
I wish I remembered the specifics of the comment, but selling a 0day on the black market is not something a casual person can easily do, and even if someone figures out how, there's a lot that can go wrong, with many of those outcomes leading to jailtime.
It's vastly superior to participate in a bug bounty program legitimately, from a risk standpoint, especially if you're standing to make $1M. 0days are (and I'm not an expert on this) not generally going for enough more to justify all that extra risk.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#9Earlier quoted context omitted.
By vetting applications, presumably. I would imagine it's mostly professors in well known universities and corporations closely affiliated with Apple getting access.
No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#10>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…
I don't work in the security field nor am I a business number cruncher, but that was the gist I had of what these programs achieved.
Edit: see Despegar's reply, I should have RTFA! However worth pointing out that there would be some incentive for researchers to go to Apple instead of a third party, which might tip the scales in their favour.