Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

41–50 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#41

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

From the article: >Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone. So that's already more than what Apple offers. I tend to think they'll always be outbid.

I don't know many people here who believe Zerodium's price list, and while I can't speak to Zerodium's payment terms, the norm appears to be tranched payments, apparently ofter over a year; selling the same bug on the grey market for "more" money (whatever it is brokers actually pay) is a gamble that the bug you've sold isn't going to die.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#42
How feasible would it be to find bugs in the iPhone kernel’s network stack? I imagine this is pretty battle-tested stuff, but it would tick all the boxes for remote and no interaction.

Edit: Since it's XNU, and it's open-source, and it's been around for a really long time, this seems unlikely. But if something was found in here, for instance, everything would be practically compromised: https://github.com/apple/darwin-xnu/blob/master/bsd/netinet/...

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#43
post #30
post #5

Earlier quoted context omitted.

From the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?

The article also had > Another $500,000 will be given to those who can find a “network attack requiring no user interaction.” which I believe many of her vulnerabilities are definitely eligible for. I read that article from https://news.ycombinator.com/item?id=20639999 yesterday, and she had this paragraph as her second > Vulnerabilities are considered ‘remote’ when the attacker does not require any physical or netwo…

> Another

Surely this is an additional $500,000 if she finds a kernel exploit (which would net her $1 million)?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#44
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Another thing to keep in mind is that these devices already exist (used by Apple internally), only on the black market. A lot of these development fused devices are stolen from the factory and sold to black hat/gray hat hackers (and companies) already.

I think one of the intentions here is to lessen the demand for black market dev-fused phones, which is already a huge problem for Apple. This is similar to the idea of officially allowing Linux on the PlayStation — give hackers no legitimate reason to pwn your console

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#46
post #40

Earlier quoted context omitted.

Worth adding that clean money is worth more than dirty money

Are there any laws you bump into selling 0-days? Honest question, I know their are laws about the actual hacking part but is it illegal to sell the payload? Obviously this is ethically dirty money I just was curious if it's actually dirty money in a criminal sense.

If you sell a bug to someone you know is going to break the law with it, you're getting close to the line for liability. People who sell bugs to the western IC are, as I understand it, virtually always selling to broker firms designated by governments which offer a veneer of plausible deniability; selling to a well-known broker is probably not legally all that risky.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#47
post #29

Earlier quoted context omitted.

Worth adding that clean money is worth more than dirty money

If the money is directly from the government, is it really dirty money?

Depends which government, I would think.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#48
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

I would imagine the publicity a researcher would get from wining the 1 million is also very valuable.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#49
This is great. Every company should be responsible for paying market price for security vulnerabilities in their own products. If you make something that carries significant market value, you should be paying the security tax in the form of a security team or bug bounties.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#50
post #44
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Another thing to keep in mind is that these devices already exist (used by Apple internally), only on the black market. A lot of these development fused devices are stolen from the factory and sold to black hat/gray hat hackers (and companies) already. I think one of the intentions here is to lessen the demand for black market dev-fused phones, which is already a huge problem for Apple. This is similar to the idea of…

I wonder how loose the "application" will be.
Post reply on HN