Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

131–140 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#131
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Another benefit of this is that researchers are no longer incentivised to hold onto bugs. Currently, you need to find a vulnerability just to get onto the device to do further research. If the researcher reported that bug then they would lose that access. Now they are free to report any bugs they find without jeopardising future research activity.

I am not sure. Not everybody is driven by money. I know a few people that turned down insane job offers because, as they said, "they are not interested about money." I see the "good guys" saying "I would have report this bug even for free" and the "bad guys" "If I hold on this in the long term, I could be able to keep (or eventually) [put your mad science plan here]"

I guess on average it will reduce those holding on. But it will not eliminate them.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#132

Does anyone know if these types of bug bounties are negotiable? As several people have mentioned, hackers can sell to the highest bidder and having proof that you have an exploit is probably sufficient, but what if Apple was willing to pay as much as the highest bidder? This may also likely convince people who have sold bugs to reach out to Apple. It probably costs them a fraction of the PR spend or risk of data brea…

The press release specifies that the $1000000 quoted figures are minimum payments for the given category of bug, so the actual amount paid could be anywhere upwards from that.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#133
For the naive guy that do not know how the trade of exploits really works and keep hearing of "black markets," do you care to explain in realistic terms how these things work?

Where are the trades happening? Is it the exploiter putting out something like "kernel exploit for iOS xx.x" ? Or the exploiter bids on people offering money? How is the seeker of exploits going to be sure that the exploit is working? How do the people keep their anonimity? And how does the money is exchanged? Crypto currencies? And how was it working before crypto?

Are governments bidding but they also want to convict the exploiter so they get the exploit for free? I remember watching one or two movies where the hacker was caught and was sentenced to jail. Government stepped in and said: "You can either be in jail for n years or work with the good guys for n/2 years" Is it just science fiction?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#134
post #62
post #2

Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-rem... ?

If Natalie Silvanovich finds a vulnerability that meets Apple's high-payout bounty criteria, they will pay her; nobody is going to mess with Silvanovich, least of all Apple ProdSec, who I have to assume exists in a relatively constant state of trying to recruit her out of P0 (good luck, ivan).

To be clear, she doesn't want the money, she's paid by Google, but I believe they've said the companies can give the money to charities. Now we see if Apple will payout her prize to charity. She may not have found a $1m exploit, but a lot of those 10 she found are pretty serious.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#135

For the naive guy that do not know how the trade of exploits really works and keep hearing of "black markets," do you care to explain in realistic terms how these things work? Where are the trades happening? Is it the exploiter putting out something like "kernel exploit for iOS xx.x" ? Or the exploiter bids on people offering money? How is the seeker of exploits going to be sure that the exploit is working? How do th…

There are exploit brokers. The biggest public one I know of is https://zerodium.com/ .

Before zerodium existed I think it was a bit more personal. Here's an article about the Grugq acting as a broker.

https://www.forbes.com/sites/andygreenberg/2012/03/21/meet-t...

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#136

Earlier quoted context omitted.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell expl…

On these marketplaces, how do people demonstrate PoC without giving away the intellectual property? Or is it unproven and completely reputation based

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#137

Earlier quoted context omitted.

Another benefit of this is that researchers are no longer incentivised to hold onto bugs. Currently, you need to find a vulnerability just to get onto the device to do further research. If the researcher reported that bug then they would lose that access. Now they are free to report any bugs they find without jeopardising future research activity.

I am not sure. Not everybody is driven by money. I know a few people that turned down insane job offers because, as they said, "they are not interested about money." I see the "good guys" saying "I would have report this bug even for free" and the "bad guys" "If I hold on this in the long term, I could be able to keep (or eventually) [put your mad science plan here]" I guess on average it will reduce those holding on…

Yes it may not eliminate them but if they hold on too long, someone else may find the same vulnerability and get the reward first. So holding on carries some risk of loss... not just loss of the money, if they really don’t care about that, but also they risk losing the exploit anyway despite holding on.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#138
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Isn't it much simpler and cheaper for apple to buy the same exploit through the same brokers anonymously?
Post reply on HN