Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

81–90 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#81

I'd like to see what what prevents double dipping, first report to unethical places, wait a bit, then report to Apple.

I think that's why the amount is so high. If you sell it for less to bad guys, someone else might find the same exploit (or a connected one) and swoop in and claim the big amount from Apple, and you lose out.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#82

Just noting: This isn't nearly enough money to stop North Korea, Israel, Russia, US, UK, France etc. Pretty sure a zero-day would be 10-100x more valuable to them than this $1 million reward. (Why is this even controversial?)

Cool... Go negotiate with one of those entities if you have a death wish. I'd rather hand over to Apple, make a name for myself and get clean cash then deal with the underbelly of the modern world.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#83
post #49

This is great. Every company should be responsible for paying market price for security vulnerabilities in their own products. If you make something that carries significant market value, you should be paying the security tax in the form of a security team or bug bounties.

So who will be responsible for all the open source software security vulnerabilities?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#84

Earlier quoted context omitted.

You really think Apple is just going to gives special dev devices to random hackers from the Internet?

I don’t think they will, I know they will. But maybe it depends on how you define “hacker” and what you call “random”. I’m saying that folks in the jailbreaking scene are some of the primary targets for this. It wouldn’t be worth launching if the plan was to exclude them. Some are already part of Apple’s bounty program. “Apple Calls In Rock Star iPhone And Mac Hackers For Secret Bug Bounty Bash” https://www.forbes.co…

That alone suggests that they are already acquainted with every one of the people they'll accept for the program? They might have a "loose" vetting process, but I doubt they have a lack of one.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#85

I'd like to see what what prevents double dipping, first report to unethical places, wait a bit, then report to Apple.

These unethical places would of course never consider reporting the bug to Apple to get a million dollar rebate on their purchase price... that would be unethical.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#86
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

But they also pushed up the price in black market, and if someone in the black market is willing to pay $2mil, $500k ahead, and then the rest over a period of time. Someone might take that payments in bitcoin over Apples $1m which you will have to pay tax on. We should also remember that there are tons of people outside the US who are into this. Africa, Asian, Eastern Europe. They don't have to worry about the legali…

>But they also pushed up the price in black market

isn't that the point? sure, it makes selling on the black market more valuable for the hackers willing to do that, but it also makes purchasing an iPhone exploit less accessible for anybody else. that's a good thing.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#87
post #57

Earlier quoted context omitted.

Yes, but also bugs "overlap" in multiple different ways; the most obvious is that a "similar" bug in a different code path will, at a company like Apple, Microsoft, or Google, result in a hunt for the same pattern on other code paths, but also the fix for one bug can kill multiple bugs elsewhere. So even though people do sometimes find exactly the same bug --- I'm fond of pointing out that at Matasano, Vitaly McLain…

In addition, real exploits often involve exploiting multiple bugs in order to be really useful

You're conflating an exploit for a narrow bug target class with a malware package which likely contains one or more exploits and probably a payload. The act of exploiting requires much more than an exploit alone to have the desired effect.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#88
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

But they also pushed up the price in black market, and if someone in the black market is willing to pay $2mil, $500k ahead, and then the rest over a period of time. Someone might take that payments in bitcoin over Apples $1m which you will have to pay tax on. We should also remember that there are tons of people outside the US who are into this. Africa, Asian, Eastern Europe. They don't have to worry about the legali…

They do have to pay tax; that they choose not to is a crime in most countries.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#89
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

But they also pushed up the price in black market, and if someone in the black market is willing to pay $2mil, $500k ahead, and then the rest over a period of time. Someone might take that payments in bitcoin over Apples $1m which you will have to pay tax on. We should also remember that there are tons of people outside the US who are into this. Africa, Asian, Eastern Europe. They don't have to worry about the legali…

Yeah but that cost has to be passed on at some point to an end consumer.

This move from Apple makes people like me, working with human rights defenders and journalists, happy.

Why?

Because it drives up the costs for the NSO Groups, Hacking Teams and Gammas of this world. They either pass on (and take a hit reducing their revenue/internal capacity) or drive up their costs (making it harder for crappier regimes to afford / reducing the frequency that high end exploits will be used.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#90
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

I wonder how a company investigates black market to that levels.
Post reply on HN