Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

171–180 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#171
post #168

Earlier quoted context omitted.

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

Out of interest how do you get to know the market price or the market in general for this sort of thing? If I were to discover a vulnerability is there a legal way I could cash in on it (aside from this case with Apple)?

I don’t know this market well, but I do know what a 3% dip in Apple’s stock price means, so it seems rather obvious that Apple’s incentive to know of vulnerabilities prior to their sale in an alternative market is worth a lot more than 1M.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#172

Earlier quoted context omitted.

Another benefit of this is that researchers are no longer incentivised to hold onto bugs. Currently, you need to find a vulnerability just to get onto the device to do further research. If the researcher reported that bug then they would lose that access. Now they are free to report any bugs they find without jeopardising future research activity.

I am not sure. Not everybody is driven by money. I know a few people that turned down insane job offers because, as they said, "they are not interested about money." I see the "good guys" saying "I would have report this bug even for free" and the "bad guys" "If I hold on this in the long term, I could be able to keep (or eventually) [put your mad science plan here]" I guess on average it will reduce those holding on…

The change here is that it reduces the "good guys" saying "I would have reported this bug even for free, but if I did I would lose my access to continue researching".

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#173
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'd like to propose a new form of Betteridge's Law that states any time a monetary figure is given in reference to a large company the top comment will always be a form of "That's nothing. It should be at least 10x that number!"

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#174
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

And even your estimates are way higher than that of typical "warez forum."

100k exploits most likely what has been resold few times over before it reached the "professional infosec" space

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#175
post #168

Earlier quoted context omitted.

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

Out of interest how do you get to know the market price or the market in general for this sort of thing? If I were to discover a vulnerability is there a legal way I could cash in on it (aside from this case with Apple)?

Some stuff on the internet: https://zerodium.com/program.html

Also I heard in person, so I cannot quote.

Not sure how legal this is, but there are even vulnerabilities brokers, who set you up with buyers.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#176
post #168

Earlier quoted context omitted.

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

Out of interest how do you get to know the market price or the market in general for this sort of thing? If I were to discover a vulnerability is there a legal way I could cash in on it (aside from this case with Apple)?

[deleted]

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#177
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

Bounties on security vulns have difficult dynamics on incentives though. At these levels you start running the risk of an insider subtly introducing a vulnerability and share it with a secret aquaintance.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#178
post #144

Earlier quoted context omitted.

It is not illegal to sell that type of software. It is not a black market, it is a grey market. There is no way you will ever hear authentic answers to your questions. The only time anyone tried to explain that the resulting article backfired on the interviewee. (Disclaimer, it was me) Governments do not buy from developers. The paperwork would be insane. They buy from businesses like Raytheon. How Raytheon gets them…

Damn this is an awesome break down of the industry, and it's hilarious to me that lo and behold someone suggests the Greenberg article and yeh does grugq himself turn up to settle the score. I can't think my way around your point about prohibition though - I think someone saying "selling exploits is bad" is also someone that would say "the government shouldn't be monitoring us, pedophile or not," and that's part of w…

Think of it like GMO. There are two sides with legitimate concerns. But only one side can speak publicly.

As for backdoored Chrome, what is to prevent China using a modified version of Firefox that removes the backdoor? It would blind NSA to collection on the Chinese target.

There is no way you can use backdoors against hard targets. Hard targets are why they need 0day. It is an arms race because it is a conflict between states.

Whatever fears people have about 0day being used against them are, as I’ve said before, like worrying about ninjas rather than cardio vascular disease. One is something you have no control over, but almost no exposure to as a risk. The other requires regular work to stay safe.

Years ago I wrote “free security advice” and the basic concept is still relevant. I should update it now though. Android 9 is a much harder target that 4.4 was. I would actually rate Android as safer than iOS because all of these ridiculous articles about million dollar pay outs have driven most developers towards iOS, and iOS is a monoculture.

A hardened Android device (disclaimer, I’m making one for retail sale) is safer than a stock iOS.

Literally everything in the media is complete garbage. No one who knows how things work would ever discuss them again.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#179

Earlier quoted context omitted.

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

And even your estimates are way higher than that of typical "warez forum." 100k exploits most likely what has been resold few times over before it reached the "professional infosec" space

Eh, I think that’s a bit presumptuous. There can be honor among thieves.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#180
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

The NSA or any other agency would pay you 10x that if you go to them instead of report it.
Post reply on HN