Earlier quoted context omitted.
No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.
The point is apple is likely to only aim for researchers for this program as the hackers could just resell most 0days, letting apple know about a small fraction to maintain reputation. It would make sense for apple to not allow hackers access to the program for this reason.
Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
21–30 of 308 posts
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#22Earlier quoted context omitted.
From the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?
She has a list at https://twitter.com/natashenka/status/1155940732084973568 (recall that "remote, interaction-less" means "do not require any physical interaction from the target to be exploited, and work in real time", according to the Project Zero blog post). Edit: As the posters below said, those aren't kernel bugs. Thanks for the correction!
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#23"Another $500,000 will be given to those who can find a "network attack requiring no user interaction."" The implication of this conditional reward is that interactive use presents more/easier attack opportunities than non-interactive use. To clarify terminology, it is arguable that "non-interactive" can be a synonym for "automated" in this context. Further, we might argue that canonical examples of "interactive" use…
Doesn't this mean the opposite?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#24"Another $500,000 will be given to those who can find a "network attack requiring no user interaction."" The implication of this conditional reward is that interactive use presents more/easier attack opportunities than non-interactive use. To clarify terminology, it is arguable that "non-interactive" can be a synonym for "automated" in this context. Further, we might argue that canonical examples of "interactive" use…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#25Earlier quoted context omitted.
No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.
You really think Apple is just going to gives special dev devices to random hackers from the Internet?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#26Earlier quoted context omitted.
Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…
From the article: >Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone. So that's already more than what Apple offers. I tend to think they'll always be outbid.
I forget the influence until I see things like this.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#27Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#28>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…
Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#29Earlier quoted context omitted.
Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…
Worth adding that clean money is worth more than dirty money
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#30Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-rem... ?
From the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?
> Another $500,000 will be given to those who can find a “network attack requiring no user interaction.”
which I believe many of her vulnerabilities are definitely eligible for. I read that article from https://news.ycombinator.com/item?id=20639999 yesterday, and she had this paragraph as her second
> Vulnerabilities are considered ‘remote’ when the attacker does not require any physical or network proximity to the target to be able to use the vulnerability. Remote vulnerabilities are described as ‘fully remote’, ‘interaction-less’ or ‘zero click’ when they do not require any physical interaction from the target to be exploited, and work in real time. I focused on the attack surfaces of the iPhone that can be reached remotely, do not require any user interaction and immediately process input. [0]
The full $1 million is for that level of fully remote attack, but against the kernel. I'd have to look up to see if any of the code she found vulnerabilities in are part of the iOS kernel.
[0] https://googleprojectzero.blogspot.com/2019/08/the-fully-rem...