Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

61–70 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#61
post #56

Earlier quoted context omitted.

> Another Surely this is an additional $500,000 if she finds a kernel exploit (which would net her $1 million)?

I found a photo of a table here which hopefully makes things clearer: https://cdn.macrumors.com/article-new/2019/08/applebugbounty... . 'dang and/or 'scbt: This link and title is probably better: https://www.macrumors.com/2019/08/08/apple-bug-bounty-progra... | Apple Ups Bug Bounty Payouts, Expands Access to All Researchers and Launches macOS Program.

Thanks, that does make things clearer.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#62
post #2

Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-rem... ?

If Natalie Silvanovich finds a vulnerability that meets Apple's high-payout bounty criteria, they will pay her; nobody is going to mess with Silvanovich, least of all Apple ProdSec, who I have to assume exists in a relatively constant state of trying to recruit her out of P0 (good luck, ivan).

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#63
post #12
post #5

Earlier quoted context omitted.

From the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?

At the end of their Black Hat talk they showed one. Anyway, Project Zero doesn't accept bounties.

Well, sort of. They ask that the bounties be donated to charity.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#64
post #57

Earlier quoted context omitted.

> Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors. Are independent discoveries of bugs common?

Yes, but also bugs "overlap" in multiple different ways; the most obvious is that a "similar" bug in a different code path will, at a company like Apple, Microsoft, or Google, result in a hunt for the same pattern on other code paths, but also the fix for one bug can kill multiple bugs elsewhere. So even though people do sometimes find exactly the same bug --- I'm fond of pointing out that at Matasano, Vitaly McLain…

In addition, real exploits often involve exploiting multiple bugs in order to be really useful

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#65
post #20

"Another $500,000 will be given to those who can find a "network attack requiring no user interaction."" The implication of this conditional reward is that interactive use presents more/easier attack opportunities than non-interactive use. To clarify terminology, it is arguable that "non-interactive" can be a synonym for "automated" in this context. Further, we might argue that canonical examples of "interactive" use…

This seems backwards.... they are offering more money for attacks that don't require user interaction because they are HARDER, not easier, to accomplish.

Oops. I apologise. Indeed I framed that statement backwards.

If non-interactive use makes attacks "harder" then terms and conditions should not seek to prohibit non-interactive use.

That is the argument in one sentence.

Another phrasing is that if interactive use makes attacks easier then users should not be discouraged or prohibited from engaging in non-interactive use.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#66
post #55

Earlier quoted context omitted.

> The implication of this conditional reward is that non-interactive use presents more/easier attack opportunities than interactive use. Doesn't this mean the opposite?

It means that, once you've found the vulnerability, it's more valuable because it's easier to use. Not that they're easier to find.

[deleted]

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#67
post #46
post #40

Earlier quoted context omitted.

Are there any laws you bump into selling 0-days? Honest question, I know their are laws about the actual hacking part but is it illegal to sell the payload? Obviously this is ethically dirty money I just was curious if it's actually dirty money in a criminal sense.

If you sell a bug to someone you know is going to break the law with it, you're getting close to the line for liability. People who sell bugs to the western IC are, as I understand it, virtually always selling to broker firms designated by governments which offer a veneer of plausible deniability; selling to a well-known broker is probably not legally all that risky.

As has happened disappointingly in the past - there aren't any actual laws offering safe harbor for ethical hacking, companies just tend not to prosecute responsible disclosure... if your disclosure required you to break interstate commerce laws, run afoul of the CFAA[1] or even just violate a TOS - or even if they can convincingly argue that discovering your disclosure might have - then you can be prosecuted.

Now, people who prosecute white hacks that practice responsible disclosure are technically known as "asshole"s but the end result is that there are a ton of laws even innocent computer usage breaks so your liability for any damage to end users usually doesn't need to be considered, there's enough book to throw at people already.

[1] Essentially if you touch a computer or computing device it's quite likely you've somehow violated the CFAA, it's _stuuupid_. https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#68

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

Worth adding that clean money is worth more than dirty money

Bug bounties merely needed market pressure for the bounties to rise.

Corporations had been unilaterally deciding what the payment for a reported bug would be. They were constantly undervaluing and wasting everyone's time. People would say the same rationale "low liability and clean money is more valuable than dirty money and needing to launder it".

Yeah, but not that much more valuable.

So now the bounties are reaching their market price.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#69
post #44
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Another thing to keep in mind is that these devices already exist (used by Apple internally), only on the black market. A lot of these development fused devices are stolen from the factory and sold to black hat/gray hat hackers (and companies) already. I think one of the intentions here is to lessen the demand for black market dev-fused phones, which is already a huge problem for Apple. This is similar to the idea of…

I thought that the Linux-on-PlayStation was actually a tax dodge? Something like it let them claim the devices were not just games consoles and so their import duties could be reduced in some regions.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#70
post #44

Earlier quoted context omitted.

Another thing to keep in mind is that these devices already exist (used by Apple internally), only on the black market. A lot of these development fused devices are stolen from the factory and sold to black hat/gray hat hackers (and companies) already. I think one of the intentions here is to lessen the demand for black market dev-fused phones, which is already a huge problem for Apple. This is similar to the idea of…

I wonder how loose the "application" will be.

Doesn't really matter. It's a formality at this point. It's basically public once they do this and they're aware of that.
Post reply on HN