Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

121–130 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#121

Earlier quoted context omitted.

Money is not a problem to Nation state actors. Not even $10M will stop any country. Even an African dictator motivated will easily pay $50M if that means getting what it takes to stay in power.

African dictators care for mobile OS hacks for staying in power?

https://www.youtube.com/watch?v=rStL7niR7gs is a pretty well done video on the rules to be a dictator.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#122
post #83
post #49

This is great. Every company should be responsible for paying market price for security vulnerabilities in their own products. If you make something that carries significant market value, you should be paying the security tax in the form of a security team or bug bounties.

So who will be responsible for all the open source software security vulnerabilities?

End users. Integrators. Developers in terms of reputation. Thanks to disclaimers not at all too different from closed source software.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#126
post #115
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Apple is making bid for an underappreciated employees of a companies who sell software that can hack iPhones

Yeah, I think this is what they're doing. It's clever.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#127
post #96

Earlier quoted context omitted.

Yeah but that cost has to be passed on at some point to an end consumer. This move from Apple makes people like me, working with human rights defenders and journalists, happy. Why? Because it drives up the costs for the NSO Groups, Hacking Teams and Gammas of this world. They either pass on (and take a hit reducing their revenue/internal capacity) or drive up their costs (making it harder for crappier regimes to affo…

That seems like a pretty valid viewpoint. The higher the cost, the less people with access, and the more likely people go with Apple’s offer. Besides that, earning a 1 million dollar reward for cracking the iOS kernel is probably a nice ticket to a pretty well paying gig at some security firm.

Right. Being able to claim (with proof) that you collected on a $1,000,000 bounty, from Apple no less, makes you massively more employable no matter where in the world you live.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#128
post #108
post #105

OT, but if you have showdead on, you can see beeschlenker's weird comment. It seems that he hears "things" in his own security cameras, and also thinks he is in a "Truman show" setup. Just a heads up if someone in the area could possibly help him. https://www.gofundme.com/f/to-keep-brian-schlenker-alive

Can you contact gofundme. He probably needs help and some of these larger companies have ways of informing local authorities if someone is at risk of harming themselves or others.

I sent a report to GoFund.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#129

Earlier quoted context omitted.

You really think Apple is just going to gives special dev devices to random hackers from the Internet?

I don’t think they will, I know they will. But maybe it depends on how you define “hacker” and what you call “random”. I’m saying that folks in the jailbreaking scene are some of the primary targets for this. It wouldn’t be worth launching if the plan was to exclude them. Some are already part of Apple’s bounty program. “Apple Calls In Rock Star iPhone And Mac Hackers For Secret Bug Bounty Bash” https://www.forbes.co…

Apple could use these devices to track the hackers...

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#130
post #117

Earlier quoted context omitted.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

I don't think it's a PR stunt. The typical layperson doesn't know what's a kernel, so the difference between a drive-by kernel exploit and an app exploit couldn't easily be summarized and made understood. Yes a layperson will understand the difference after you give them a five-minute primer of operating system theory, but in this age of social media who still has the attention span to sit through that, if their inte…

It could be explained to people ... But look at the titles that the press is putting out.
Post reply on HN