Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

1–10 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#3
>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year.

I wonder how they're going to manage this. I could easily see some less than ethical researchers applying for this program and selling all the 0 days they find to the usual suspects rather than informing Apple.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#4
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

By vetting applications, presumably. I would imagine it's mostly professors in well known universities and corporations closely affiliated with Apple getting access.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#5
post #2

Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-rem... ?

From the article:

  > The full $1 million will go to researchers who can find a
  > hack of the kernel—the core of iOS—with zero clicks required
  > by the iPhone owner.
Which one of the vulnerabilities discovered met that criteria?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#6
post #4
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

By vetting applications, presumably. I would imagine it's mostly professors in well known universities and corporations closely affiliated with Apple getting access.

No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days.

I’d say that the researchers have a pretty strong incentive not to screw around with Apple.

It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#7
post #4

Earlier quoted context omitted.

By vetting applications, presumably. I would imagine it's mostly professors in well known universities and corporations closely affiliated with Apple getting access.

No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.

You really think Apple is just going to gives special dev devices to random hackers from the Internet?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#8
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

I forget who, but someone made a comment about this a long time ago that stuck with me. We often say, "They'll just sell all these 0 days on the black market." but honestly that's not like a literal market, and you have to make a lot of compromises to not only your own integrity, but also to your safety and ability to stay out of jail if you do something like that.

I wish I remembered the specifics of the comment, but selling a 0day on the black market is not something a casual person can easily do, and even if someone figures out how, there's a lot that can go wrong, with many of those outcomes leading to jailtime.

It's vastly superior to participate in a bug bounty program legitimately, from a risk standpoint, especially if you're standing to make $1M. 0days are (and I'm not an expert on this) not generally going for enough more to justify all that extra risk.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#9
post #4

Earlier quoted context omitted.

By vetting applications, presumably. I would imagine it's mostly professors in well known universities and corporations closely affiliated with Apple getting access.

No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.

The point is apple is likely to only aim for researchers for this program as the hackers could just resell most 0days, letting apple know about a small fraction to maintain reputation. It would make sense for apple to not allow hackers access to the program for this reason.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#10
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else.

I don't work in the security field nor am I a business number cruncher, but that was the gist I had of what these programs achieved.

Edit: see Despegar's reply, I should have RTFA! However worth pointing out that there would be some incentive for researchers to go to Apple instead of a third party, which might tip the scales in their favour.

Post reply on HN