Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

151–160 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#151

Earlier quoted context omitted.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

When I read the article my first reaction was "Only a million?" Considering the importance of a bug like this to Apple's business and the size of their cash hoard, this sounds like they don't actually care that much.

Yeah, right? Considering they were about to buy Greece[0] at some point, one would assume that they would hand more budget for something that potentially saves their own business.

[0]: https://www.independent.co.uk/news/business/news/should-appl...

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#152

Earlier quoted context omitted.

I forget who, but someone made a comment about this a long time ago that stuck with me. We often say, "They'll just sell all these 0 days on the black market." but honestly that's not like a literal market, and you have to make a lot of compromises to not only your own integrity, but also to your safety and ability to stay out of jail if you do something like that. I wish I remembered the specifics of the comment, bu…

Selling bugs and exploits is not illegal just about everywhere, so there is really no risk. Plus, law enforcement and intelligence agencies, or their contractors, are the ones buying on the “black market”. Nobody has to worry about jail for knowing about a mistake that Apple made in their code and telling someone else.

+1

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#153
post #143

For the naive guy that do not know how the trade of exploits really works and keep hearing of "black markets," do you care to explain in realistic terms how these things work? Where are the trades happening? Is it the exploiter putting out something like "kernel exploit for iOS xx.x" ? Or the exploiter bids on people offering money? How is the seeker of exploits going to be sure that the exploit is working? How do th…

Speaking about exploits in general, at least the old method was to go to cracking forums and say you have the crack available. Usually you would then get into discussions via an IM and finally broker a price. It used to be done via payment services like PayPal, but I imagine BitCoin would play a large part in the modern world.

It does not.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#154
post #105

OT, but if you have showdead on, you can see beeschlenker's weird comment. It seems that he hears "things" in his own security cameras, and also thinks he is in a "Truman show" setup. Just a heads up if someone in the area could possibly help him. https://www.gofundme.com/f/to-keep-brian-schlenker-alive

Yeah there is nothing in those videos. Absolutely nothing even looking at the waveforms just white noise, clicking, him(?) talking. Trump, Obama, Dorsey aren't in any of these videos and if they were why in the hell are they videos and not just the parts with them talking?

What a waste of time. The dude needs mental help there isn't anything there. If there is it's unconvincing going through 20 of these.

However there was the few of him getting evicted that were real.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#155

Earlier quoted context omitted.

I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell expl…

On these marketplaces, how do people demonstrate PoC without giving away the intellectual property? Or is it unproven and completely reputation based

I imagine that a remote exploit should be pretty easy to demonstrate without giving away how you did it?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#156
post #144

For the naive guy that do not know how the trade of exploits really works and keep hearing of "black markets," do you care to explain in realistic terms how these things work? Where are the trades happening? Is it the exploiter putting out something like "kernel exploit for iOS xx.x" ? Or the exploiter bids on people offering money? How is the seeker of exploits going to be sure that the exploit is working? How do th…

It is not illegal to sell that type of software. It is not a black market, it is a grey market. There is no way you will ever hear authentic answers to your questions. The only time anyone tried to explain that the resulting article backfired on the interviewee. (Disclaimer, it was me) Governments do not buy from developers. The paperwork would be insane. They buy from businesses like Raytheon. How Raytheon gets them…

> the resulting article was a hatchet job

Was that the forbes article linked above?

> You can’t unfuck the goat. C’est la vie.

That goat laid you golden eggs though. It takes me over 15 years to earn a $1m paycheck, and I wouldn't mind dealing with some people moaning at me for it. People always find something to complain about anyway, so I wouldn't be too concerned about it.

> The conversation about vulnerability sales has been as even handed and rational as the conversation about marijuana in the 50s.

Sure, you're right, but this is true for many new things, you're just smack in the middle of this discussion. It's good to have these discussions though, because it makes people aware that otherwise weren't. Comparable hysteria is currently happening with 'company X is listening to your conversations' and 'self driving cars might kill you to save a baby'. People in the field have been discussing the ethics of these things for a long time, but now it's becoming a public discussion. This happens when things grow.

Personally, I prefer the black/grey zero day market over back doors being proposed by some. Those would be permanent vulnerabilities, while zero days are (usually) temporary and probably only used while absolutely necessary, opposed to just eavesdropping on anybody. I also see the need, because the internet gives bad people too many places to hide.

So, from me, thanks for your services, you probably helped keep us safe from bad actors.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#157
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

Did your comment just refer to non hackers as "standard people"?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#158
Apple salaries aren’t much of a secret, see: levels.fyi.

1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive.

It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned.

This just seems like good business. They could make it 5M, and it would still be worth it to them in the medium to long term.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#159
post #144

For the naive guy that do not know how the trade of exploits really works and keep hearing of "black markets," do you care to explain in realistic terms how these things work? Where are the trades happening? Is it the exploiter putting out something like "kernel exploit for iOS xx.x" ? Or the exploiter bids on people offering money? How is the seeker of exploits going to be sure that the exploit is working? How do th…

It is not illegal to sell that type of software. It is not a black market, it is a grey market. There is no way you will ever hear authentic answers to your questions. The only time anyone tried to explain that the resulting article backfired on the interviewee. (Disclaimer, it was me) Governments do not buy from developers. The paperwork would be insane. They buy from businesses like Raytheon. How Raytheon gets them…

Damn this is an awesome break down of the industry, and it's hilarious to me that lo and behold someone suggests the Greenberg article and yeh does grugq himself turn up to settle the score.

I can't think my way around your point about prohibition though - I think someone saying "selling exploits is bad" is also someone that would say "the government shouldn't be monitoring us, pedophile or not," and that's part of why they don't think exploits should be sold to governments. Could be wrong.

But, we all generally seem to feel that the government shouldn't be given back doors into our devices that only they get to use, yeah? So instead the alternative is an endless arms race as chrome or whoever tries to out engineer the FBI? Why not just give them the backdoor at that point? (I.e., why not just support them having the backdoor, I'm not implying those in your wheelhouse have the power to legislate or anything)

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#160

Earlier quoted context omitted.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

Did your comment just refer to non hackers as "standard people"?

Well it's true. The Hacker News audience is so specific it is not similar to any specific country's population, let alone world population (ie "people" in the general sense).

That's certainly not to say the HN audience is an elite (it's not) but it is comprised of outliers in the sense of people having abnormal jobs and/or abnormal interests compared to the average population in any city-sized slice taken pretty much anywhere in the real world.

Post reply on HN