Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

111–120 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#112
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

> Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors. Are independent discoveries of bugs common?

Yes - if you go by the iOS 12.1.1 security notes, for instance https://support.apple.com/en-us/HT209340 , it appears that CVE-2018-4435 was discovered independently (on the same day, even!) by TrendMicro / ZDI https://www.zerodayinitiative.com/advisories/ZDI-18-1365/ and Google Project Zero https://crbug.com/project-zero/1671 , whose reports don't mention each other. CVE-2018-4438 is also credited separately to both Qihoo and Project Zero, and the P0 report https://crbug.com/project-zero/1649 again doesn't mention Qihoo. I've seen this sort of thing with some frequency in previous update reports.

Also, somewhat famously, both Spectre and Meltdown were discovered independently by multiple teams in the same timeframe, who all coordinated disclosure with the CPU vendors etc. https://meltdownattack.com

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#113

Earlier quoted context omitted.

In addition, real exploits often involve exploiting multiple bugs in order to be really useful

You're conflating an exploit for a narrow bug target class with a malware package which likely contains one or more exploits and probably a payload. The act of exploiting requires much more than an exploit alone to have the desired effect.

What's meant is that real exploits require one to get RCE, another to break sandbox, another for privilege escalation.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#114
post #67
post #46

Earlier quoted context omitted.

If you sell a bug to someone you know is going to break the law with it, you're getting close to the line for liability. People who sell bugs to the western IC are, as I understand it, virtually always selling to broker firms designated by governments which offer a veneer of plausible deniability; selling to a well-known broker is probably not legally all that risky.

As has happened disappointingly in the past - there aren't any actual laws offering safe harbor for ethical hacking, companies just tend not to prosecute responsible disclosure... if your disclosure required you to break interstate commerce laws, run afoul of the CFAA[1] or even just violate a TOS - or even if they can convincingly argue that discovering your disclosure might have - then you can be prosecuted. Now, p…

None of this seems particularly relevant to the scenario of selling to zerodium.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#115
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Apple is making bid for an underappreciated employees of a companies who sell software that can hack iPhones

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#116
post #41

Earlier quoted context omitted.

From the article: >Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone. So that's already more than what Apple offers. I tend to think they'll always be outbid.

I don't know many people here who believe Zerodium's price list, and while I can't speak to Zerodium's payment terms, the norm appears to be tranched payments, apparently ofter over a year; selling the same bug on the grey market for "more" money (whatever it is brokers actually pay) is a gamble that the bug you've sold isn't going to die.

With those terms, they can buy a bug, report it to Apple, collect the $1m, and be off the hook to pay out the remaining payments. It seems to me this makes it much riskier to go to the black market than people here realize.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#117
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

I don't think it's a PR stunt. The typical layperson doesn't know what's a kernel, so the difference between a drive-by kernel exploit and an app exploit couldn't easily be summarized and made understood. Yes a layperson will understand the difference after you give them a five-minute primer of operating system theory, but in this age of social media who still has the attention span to sit through that, if their interest isn't in computer science?

So to me, this isn't a PR stunt. It's a necessary "dumbing down" we see all too often. It's no different from journalists digesting and simplifying the content of an advancement in biology or physics.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#119
Does anyone know if these types of bug bounties are negotiable?

As several people have mentioned, hackers can sell to the highest bidder and having proof that you have an exploit is probably sufficient, but what if Apple was willing to pay as much as the highest bidder?

This may also likely convince people who have sold bugs to reach out to Apple.

It probably costs them a fraction of the PR spend or risk of data breach/user exposure etc.

Post reply on HN