Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

141–150 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#141
post #67
post #46

Earlier quoted context omitted.

If you sell a bug to someone you know is going to break the law with it, you're getting close to the line for liability. People who sell bugs to the western IC are, as I understand it, virtually always selling to broker firms designated by governments which offer a veneer of plausible deniability; selling to a well-known broker is probably not legally all that risky.

As has happened disappointingly in the past - there aren't any actual laws offering safe harbor for ethical hacking, companies just tend not to prosecute responsible disclosure... if your disclosure required you to break interstate commerce laws, run afoul of the CFAA[1] or even just violate a TOS - or even if they can convincingly argue that discovering your disclosure might have - then you can be prosecuted. Now, p…

This has nothing to do with hacking, so none of that applies. You're conflating attacking someone else's computer or network.

You don't need safe harbor because analyzing your own property is not a crime. Neither is telling people what you found. Also, please stop using the term responsible disclosure!

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#142
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

When I read the article my first reaction was "Only a million?" Considering the importance of a bug like this to Apple's business and the size of their cash hoard, this sounds like they don't actually care that much.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#143

For the naive guy that do not know how the trade of exploits really works and keep hearing of "black markets," do you care to explain in realistic terms how these things work? Where are the trades happening? Is it the exploiter putting out something like "kernel exploit for iOS xx.x" ? Or the exploiter bids on people offering money? How is the seeker of exploits going to be sure that the exploit is working? How do th…

Speaking about exploits in general, at least the old method was to go to cracking forums and say you have the crack available. Usually you would then get into discussions via an IM and finally broker a price.

It used to be done via payment services like PayPal, but I imagine BitCoin would play a large part in the modern world.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#144

For the naive guy that do not know how the trade of exploits really works and keep hearing of "black markets," do you care to explain in realistic terms how these things work? Where are the trades happening? Is it the exploiter putting out something like "kernel exploit for iOS xx.x" ? Or the exploiter bids on people offering money? How is the seeker of exploits going to be sure that the exploit is working? How do th…

It is not illegal to sell that type of software. It is not a black market, it is a grey market.

There is no way you will ever hear authentic answers to your questions. The only time anyone tried to explain that the resulting article backfired on the interviewee. (Disclaimer, it was me)

Governments do not buy from developers. The paperwork would be insane. They buy from businesses like Raytheon. How Raytheon gets them is opaque. But they do employ hundreds of exploit developers. Read the r/netsec job postings and notice how many require having a TS clearance. Every interesting job that says “work on vulnerability discovery and exploit development” requires TS.

Governments generally speaking do not cheat on business deals where they want to continue having access to that market. It is like stiffing the company that sells you replacement parts for your government vehicles. You save money now, but in the future your planes can’t fly and no one will do business with you.

All of this I explained during the interview, but the objective of the article was not what I assumed it would be, which was to address the dynamics of how the market works. I was naive to think that, but in my defense I was genuinely shocked that people were unaware of the market (it has existed forever). Literally everyone who is an infosec rockstar has been involved with exploit sales [0]. Many still are because It allows them to work on what they enjoy — bugs and exploits — and remunerates for their expertise. They get paid a living wage to do what they want. Like any freelance developer. They are just smart enough to keep their mouths shut.

I haven’t been involved with the market for almost a decade now but you’ll still hear people saying shit like “how does it feel to sell weapons to dictators??” (Even On here there are a number of such comments.) I can truthfully answer that I have no idea. I only ever sold software to western governments who had a hard on for terrorists.

I’m still angry about it, but I have no one but myself to blame. You can’t unfuck the goat. C’est la vie. People want sensational stories about evil people, they don’t want stories about the dynamics of a grey market software industry. No one will ever speak about it again (lessons learned analysis! Protip, don’t be the lesson others learn from).

The market has changed massively over the years. It is nothing like the one I was involved in back then. However, as I said, no one will ever discuss it again. They saw what happened and they won’t speak in public about it.

What was, is, and will continue to be, the legitimate sale of vulnerabilities is now closed forever.

As a thought experiment, think of this. Let’s take it for granted that the IC counter terrorist units and the legal authorities hunting for child abusers are acting in good faith. That is, not every single person at NSA is desperate to see what you are doing on the Internet (literally, you are noise obscuring their signal). There are people who are going after child sex abusers, do you want them to have the capability to exploit a web browser or do you want web browsers to be safe tools for child abusers. This is not hypothetical [1].

There cannot be a discussion about a market where there is so much hysteria about fringe cases of abuse. Rather than trying to find ways of mitigating against abuse, the reaction has been to advocate for prohibition. Prohibition does not work, it simply drives reputable operators out of the market.

The conversation about vulnerability sales has been as even handed and rational as the conversation about marijuana in the 50s. Instead of marijuana madness you get “the FBI can hack your computer!!” ...I guess the upside is that at least this time the topic is not a proxy for racism [edit: I retract that statement. Pretty much every rationalization about banning vulnerability sales talks about African or Arabian buyers.]

And again, I have said too much. Try to explain something, get called a baby killer. I’ll bet there will be accusations of enabling dictators to spy on civil rights activists. To preempt the “you don’t know what happens after you sell it!” I say simply this — the point of having a middleman to handle the transaction is to ensure that you sell to the right end users. Exploit developers don’t want to sell to dictators, they find someone who can get them access to a market where their work will be used ethically. That can’t be said for all, of course. The jailbreak community in particular is essentially a vendor to the Chinese government.

But there you go. The most you’ll hear about it from someone that actually knows what they’re talking about.

[edit: haha, see? It was brought up before I even posted a response! [2] There is no accurate information. Literally every single paper on the topic cites newspaper articles rather than academic research. This is actually unique. It is the outlier case. Mara did a review of the literature and found that the majority of citations were to articles, far in excess of other topics)

[0] https://www.econinfosec.org/archive/weis2007/papers/29.pdf [PDF] — a paper from Charlie Miller talking about how difficult it was for him to sell exploits without a trusted third party to act as an impartial party to the sale. That TTP is called an “exploit broker” because that sounds far scarier than “trusted third party.” Incidentally, this is the environment I was operating in, and it was clear that no one involved in security considered it abnormal.

[1]: https://www.wired.com/2014/01/tormail/ ... look at the framing of the article. It is not “FBI screws up their operation and mistakenly collects data that is irrelevant to their investigation.” It is “if you used this secure email provider [hosted on the same infrastructure as a massive child sex abuse web site] the FBI has your inbox!!!!”

[2] https://news.ycombinator.com/item?id=20651348 .. feel free to read the article and think what you like. Andy Greenberg is a good journalist. I was an idiot. ¯\_(ツ)_/¯

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#145
post #93

Earlier quoted context omitted.

Different definition of “dirty”.

Yeah. I'll give you that. It's the same sort of "dirty" as a paycheck from Palantir or Facebook...

So not dirty. “Dirty” money in the traditional sense has to be “laundered” because it comes from an illegal activity.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#146

I'd like to see what what prevents double dipping, first report to unethical places, wait a bit, then report to Apple.

According to other comments here, the unethical places spread payment over a period of time; payment stops if it gets patched.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#147
post #41

Earlier quoted context omitted.

I don't know many people here who believe Zerodium's price list, and while I can't speak to Zerodium's payment terms, the norm appears to be tranched payments, apparently ofter over a year; selling the same bug on the grey market for "more" money (whatever it is brokers actually pay) is a gamble that the bug you've sold isn't going to die.

With those terms, they can buy a bug, report it to Apple, collect the $1m, and be off the hook to pay out the remaining payments. It seems to me this makes it much riskier to go to the black market than people here realize.

Yes, because that is exactly the sort of behavior that a business would engage in. Screwing over their suppliers and demonstrating that they offer no value whatsoever.

How would that make any sense? It is ludicrous.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#148
post #15

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

Depends who’s buying I imagine. Not sure about everyone else but I always picture the entities buying on the black market as singular people for some reason When you consider it could be the likes of the three digit shoe inspectors over there in the US it could be a fair chunk of change

Who are these individuals that will pay millions of dollars for an exploit? Cyber criminals rely almost exclusively on dead bugs, frequently using exploits from the metasploit framework. That gives then sufficient access to a broad range of victims so they can generate revenue through volume.

0days are used against hardened targets. Think “Iranian nuclear facilities” rather than “grandma’s PC”

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#150
post #4

Earlier quoted context omitted.

By vetting applications, presumably. I would imagine it's mostly professors in well known universities and corporations closely affiliated with Apple getting access.

No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.

The jailbreak community will not be getting these. They make more money continuing to sell to China than they will make selling to Apple.
Post reply on HN