I'd like to see what what prevents double dipping, first report to unethical places, wait a bit, then report to Apple.
Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
81–90 of 308 posts
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#82Just noting: This isn't nearly enough money to stop North Korea, Israel, Russia, US, UK, France etc. Pretty sure a zero-day would be 10-100x more valuable to them than this $1 million reward. (Why is this even controversial?)
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#83This is great. Every company should be responsible for paying market price for security vulnerabilities in their own products. If you make something that carries significant market value, you should be paying the security tax in the form of a security team or bug bounties.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#84Earlier quoted context omitted.
You really think Apple is just going to gives special dev devices to random hackers from the Internet?
I don’t think they will, I know they will. But maybe it depends on how you define “hacker” and what you call “random”. I’m saying that folks in the jailbreaking scene are some of the primary targets for this. It wouldn’t be worth launching if the plan was to exclude them. Some are already part of Apple’s bounty program. “Apple Calls In Rock Star iPhone And Mac Hackers For Secret Bug Bounty Bash” https://www.forbes.co…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#85I'd like to see what what prevents double dipping, first report to unethical places, wait a bit, then report to Apple.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#86What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.
But they also pushed up the price in black market, and if someone in the black market is willing to pay $2mil, $500k ahead, and then the rest over a period of time. Someone might take that payments in bitcoin over Apples $1m which you will have to pay tax on. We should also remember that there are tons of people outside the US who are into this. Africa, Asian, Eastern Europe. They don't have to worry about the legali…
isn't that the point? sure, it makes selling on the black market more valuable for the hackers willing to do that, but it also makes purchasing an iPhone exploit less accessible for anybody else. that's a good thing.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#87Earlier quoted context omitted.
Yes, but also bugs "overlap" in multiple different ways; the most obvious is that a "similar" bug in a different code path will, at a company like Apple, Microsoft, or Google, result in a hunt for the same pattern on other code paths, but also the fix for one bug can kill multiple bugs elsewhere. So even though people do sometimes find exactly the same bug --- I'm fond of pointing out that at Matasano, Vitaly McLain…
In addition, real exploits often involve exploiting multiple bugs in order to be really useful
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#88What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.
But they also pushed up the price in black market, and if someone in the black market is willing to pay $2mil, $500k ahead, and then the rest over a period of time. Someone might take that payments in bitcoin over Apples $1m which you will have to pay tax on. We should also remember that there are tons of people outside the US who are into this. Africa, Asian, Eastern Europe. They don't have to worry about the legali…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#89What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.
But they also pushed up the price in black market, and if someone in the black market is willing to pay $2mil, $500k ahead, and then the rest over a period of time. Someone might take that payments in bitcoin over Apples $1m which you will have to pay tax on. We should also remember that there are tons of people outside the US who are into this. Africa, Asian, Eastern Europe. They don't have to worry about the legali…
This move from Apple makes people like me, working with human rights defenders and journalists, happy.
Why?
Because it drives up the costs for the NSO Groups, Hacking Teams and Gammas of this world. They either pass on (and take a hit reducing their revenue/internal capacity) or drive up their costs (making it harder for crappier regimes to afford / reducing the frequency that high end exploits will be used.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#90>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…
Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…