Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

91–100 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#91

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

From the article: >Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone. So that's already more than what Apple offers. I tend to think they'll always be outbid.

I’d rather a legitimate 1 million I can declare and put in my bank than 2 million from the underworld delivered in instalments in bitcoin.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#92
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability."

The reality is that they only pay that much for bugs in the kernel that do not require a user interaction.

Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order to compromise almost all iPhones. Apple seems to pay "only" $100k for those problems.

I just scanned through the comments and clicked on some links so correct me if what I wrote is not accurate.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#94
post #72

This is an area that's always been fascinating to me, but that I've never dived into. I'm not overly interested in this particular program, just exploits in general and perhaps examples of how and why they work. Anyone have any resources that they've found useful?

There's a ton of info out there in various websites and blogs. I like the RPISEC Modern Binary Exploitation class as a great introduction. The lectures and materials (and a VM!) are on github: https://github.com/RPISEC/MBE

This is awesome. Thanks for the resource.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#95
post #44

Earlier quoted context omitted.

Another thing to keep in mind is that these devices already exist (used by Apple internally), only on the black market. A lot of these development fused devices are stolen from the factory and sold to black hat/gray hat hackers (and companies) already. I think one of the intentions here is to lessen the demand for black market dev-fused phones, which is already a huge problem for Apple. This is similar to the idea of…

I thought that the Linux-on-PlayStation was actually a tax dodge? Something like it let them claim the devices were not just games consoles and so their import duties could be reduced in some regions.

You'd think someone would have dug up a citation for this, but Wikipedia says (for the PS2):

>Some incorrectly speculate it was used as an attempt to help classify the PS2 as a computer to achieve tax exempt status from certain EU taxes that apply to game consoles and not computers (It was the Yabasic included with EU units that was intended to do that).[citation needed]

and Linux on the PS3 was used as a marketing point.

https://en.wikipedia.org/wiki/OtherOS - both these pages are really bad :/

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#96

Earlier quoted context omitted.

But they also pushed up the price in black market, and if someone in the black market is willing to pay $2mil, $500k ahead, and then the rest over a period of time. Someone might take that payments in bitcoin over Apples $1m which you will have to pay tax on. We should also remember that there are tons of people outside the US who are into this. Africa, Asian, Eastern Europe. They don't have to worry about the legali…

Yeah but that cost has to be passed on at some point to an end consumer. This move from Apple makes people like me, working with human rights defenders and journalists, happy. Why? Because it drives up the costs for the NSO Groups, Hacking Teams and Gammas of this world. They either pass on (and take a hit reducing their revenue/internal capacity) or drive up their costs (making it harder for crappier regimes to affo…

That seems like a pretty valid viewpoint. The higher the cost, the less people with access, and the more likely people go with Apple’s offer.

Besides that, earning a 1 million dollar reward for cracking the iOS kernel is probably a nice ticket to a pretty well paying gig at some security firm.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#97
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

No, this is not a PR stunt.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#100
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell exploits is for the money. Take away that variable and suddenly there's no reason to sell exploits to bad actors, just sell them straight to the source at Apple and get a fat paycheck.
Post reply on HN