Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

181–190 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#181
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

Bounties on security vulns have difficult dynamics on incentives though. At these levels you start running the risk of an insider subtly introducing a vulnerability and share it with a secret aquaintance.

I’ll say it once more. This isn’t that big of a bounty when you consider what Apple’s iPhone security crew make on average/year.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#184
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'd like to propose a new form of Betteridge's Law that states any time a monetary figure is given in reference to a large company the top comment will always be a form of "That's nothing. It should be at least 10x that number!"

I don’t know the law of which you speak, but the risk of not catching an ugly vulnerability after posturing themselves as a secure platform all over the media could easily cost them a lot more than 1M. That’s why their bounty is actually a lowball. It’s not that they’re a big company, it’s that they have a lot to lose. Does that make sense?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#185
post #180

Earlier quoted context omitted.

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

The NSA or any other agency would pay you 10x that if you go to them instead of report it.

I’m assuming you know from experience.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#186
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

Bounties on security vulns have difficult dynamics on incentives though. At these levels you start running the risk of an insider subtly introducing a vulnerability and share it with a secret aquaintance.

I would hope there is sufficient discouragement for that sort of behavior - that's definitely breaking at least two federal laws.

Maybe I'm naive, but I would think that any programmer skilled and privileged enough to be able to insert a vulnerability into a mainline product, get it past code review, and make it look like an innocent mistake during the inevitable root-cause analysis would not only know better, but would also value their career enough that whatever payout they got from the bounty wouldn't be worth jeopardizing all they've worked for.

And anyway, how's that conversation supposed to play out? "Sorry about that bug boss, yeah could've happened to anyone. Anyway, about my retirement in two weeks..."

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#187
post #163

Earlier quoted context omitted.

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.

So the question is, assuming you have a valid exploit, could you not convince Apple to pay more than $1m?

If you found an unfound gaping crater of an exploit somewhere -- how much would that be worth to them? Likely a lot more than $1m. I'm sure you could negotiate that number up, a lot.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#188
post #171
post #168

Earlier quoted context omitted.

Out of interest how do you get to know the market price or the market in general for this sort of thing? If I were to discover a vulnerability is there a legal way I could cash in on it (aside from this case with Apple)?

I don’t know this market well, but I do know what a 3% dip in Apple’s stock price means, so it seems rather obvious that Apple’s incentive to know of vulnerabilities prior to their sale in an alternative market is worth a lot more than 1M.

Valuing something in terms of its short-term impact on stock doesn't make any sense. An iOS vulnerability is worth a lot, but that the stock price dipped 3% is more of a sign of the market being fickle and reacting to any bad/good news about the company on a given day than 3% of Apple's worth being lost in any meaningful sense.

Following this line of thinking leads to some pretty absurd conclusions, like 7% of Tesla's value being predicated on Elon Musk not smoking a joint[1].

1. https://www.cnbc.com/2018/09/07/tesla-sinks-8percent-after-b...

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#189
Given I know "stuff" but compared to anybody who really "knows" I am a noob in exploit engineering. I just know basic inner workings of a computer and a little reverse engineering.

Would it even make sense for me to try? It seems like the probability I find something, especially without user interaction, seems so far off that it would be hard for me to find a constant motivation.

Imagine one year where I dedicate two days a week learning, understanding and trying. Do I would have any chance at all to find something worth the $1M?

Thank you!

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#190
post #178

Earlier quoted context omitted.

Damn this is an awesome break down of the industry, and it's hilarious to me that lo and behold someone suggests the Greenberg article and yeh does grugq himself turn up to settle the score. I can't think my way around your point about prohibition though - I think someone saying "selling exploits is bad" is also someone that would say "the government shouldn't be monitoring us, pedophile or not," and that's part of w…

Think of it like GMO. There are two sides with legitimate concerns. But only one side can speak publicly. As for backdoored Chrome, what is to prevent China using a modified version of Firefox that removes the backdoor? It would blind NSA to collection on the Chinese target. There is no way you can use backdoors against hard targets. Hard targets are why they need 0day. It is an arms race because it is a conflict bet…

Your argument is limited to technical and political science concepts, and by limiting itself so, is correct. It is inapplicable to the real world.

Governments have used zero days. Most famously to use a zero day unlock an iPhone against a terrorist (whose house was ransacked by the news media). Less famously was to botch a legal case against a pedophile (amazingly, it would be possible to find and arrest nearly all pedophiles on Tor by burning half a million dollars in zero days). But the government didn’t want to release the zero day for Play Pen and Mozilla got involved in the case.

But Freedom Hosting’s zero day was discovered while it was being used. I think the government still uses zero days, but parallel constructs the evidence from them. This is policy making by mismanagement.

On face value, the government is involved in abhorrently irrational decision making. The government cannot be considered responsible enough to have zero days, but that’s an argument that will lead nowhere.

Post reply on HN