Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

71–80 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#72
This is an area that's always been fascinating to me, but that I've never dived into. I'm not overly interested in this particular program, just exploits in general and perhaps examples of how and why they work. Anyone have any resources that they've found useful?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#73
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

I wonder how they're going to manage this. I could easily see some less than ethical researchers applying for this program and selling all the 0 days they find to the usual suspects rather than informing Apple.

My guess is that they're not going to let just any rando h4xx0r into the program. They'll take on well-known security researchers and academics who have something to lose by leaking zero days.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#74
post #72

This is an area that's always been fascinating to me, but that I've never dived into. I'm not overly interested in this particular program, just exploits in general and perhaps examples of how and why they work. Anyone have any resources that they've found useful?

There's a ton of info out there in various websites and blogs. I like the RPISEC Modern Binary Exploitation class as a great introduction. The lectures and materials (and a VM!) are on github: https://github.com/RPISEC/MBE

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#75
post #72

This is an area that's always been fascinating to me, but that I've never dived into. I'm not overly interested in this particular program, just exploits in general and perhaps examples of how and why they work. Anyone have any resources that they've found useful?

Microcorruption is a CTF which is a very nice introduction to buffer overflows and the like: https://microcorruption.com/login

Also search for "15-213 Bomb Lab" - it's from a CMU systems programming class and teaches use of the debugger and some common vulnerabilities.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#76
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

[deleted]

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#77
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

But they also pushed up the price in black market, and if someone in the black market is willing to pay $2mil, $500k ahead, and then the rest over a period of time. Someone might take that payments in bitcoin over Apples $1m which you will have to pay tax on.

We should also remember that there are tons of people outside the US who are into this. Africa, Asian, Eastern Europe. They don't have to worry about the legality of selling an exploit.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#78

Just noting: This isn't nearly enough money to stop North Korea, Israel, Russia, US, UK, France etc. Pretty sure a zero-day would be 10-100x more valuable to them than this $1 million reward. (Why is this even controversial?)

No, but it would be enough money for someone unaffiliated with those states who would otherwise consider selling it to them (through a third-party or whatever) instead.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#80

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

Worth adding that clean money is worth more than dirty money

No it's not. Money is money.
Post reply on HN