Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…
Bounties on security vulns have difficult dynamics on incentives though. At these levels you start running the risk of an insider subtly introducing a vulnerability and share it with a secret aquaintance.
Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
181–190 of 308 posts
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#182Oh great, the creator of that bitfrost junk. Time to short Apple.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#183Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#184Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…
I'd like to propose a new form of Betteridge's Law that states any time a monetary figure is given in reference to a large company the top comment will always be a form of "That's nothing. It should be at least 10x that number!"
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#185Earlier quoted context omitted.
I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.
The NSA or any other agency would pay you 10x that if you go to them instead of report it.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#186Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…
Bounties on security vulns have difficult dynamics on incentives though. At these levels you start running the risk of an insider subtly introducing a vulnerability and share it with a secret aquaintance.
Maybe I'm naive, but I would think that any programmer skilled and privileged enough to be able to insert a vulnerability into a mainline product, get it past code review, and make it look like an innocent mistake during the inevitable root-cause analysis would not only know better, but would also value their career enough that whatever payout they got from the bounty wouldn't be worth jeopardizing all they've worked for.
And anyway, how's that conversation supposed to play out? "Sorry about that bug boss, yeah could've happened to anyone. Anyway, about my retirement in two weeks..."
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#187Earlier quoted context omitted.
I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.
Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.
If you found an unfound gaping crater of an exploit somewhere -- how much would that be worth to them? Likely a lot more than $1m. I'm sure you could negotiate that number up, a lot.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#188Earlier quoted context omitted.
Out of interest how do you get to know the market price or the market in general for this sort of thing? If I were to discover a vulnerability is there a legal way I could cash in on it (aside from this case with Apple)?
I don’t know this market well, but I do know what a 3% dip in Apple’s stock price means, so it seems rather obvious that Apple’s incentive to know of vulnerabilities prior to their sale in an alternative market is worth a lot more than 1M.
Following this line of thinking leads to some pretty absurd conclusions, like 7% of Tesla's value being predicated on Elon Musk not smoking a joint[1].
1. https://www.cnbc.com/2018/09/07/tesla-sinks-8percent-after-b...
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#189Would it even make sense for me to try? It seems like the probability I find something, especially without user interaction, seems so far off that it would be hard for me to find a constant motivation.
Imagine one year where I dedicate two days a week learning, understanding and trying. Do I would have any chance at all to find something worth the $1M?
Thank you!
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#190Earlier quoted context omitted.
Damn this is an awesome break down of the industry, and it's hilarious to me that lo and behold someone suggests the Greenberg article and yeh does grugq himself turn up to settle the score. I can't think my way around your point about prohibition though - I think someone saying "selling exploits is bad" is also someone that would say "the government shouldn't be monitoring us, pedophile or not," and that's part of w…
Think of it like GMO. There are two sides with legitimate concerns. But only one side can speak publicly. As for backdoored Chrome, what is to prevent China using a modified version of Firefox that removes the backdoor? It would blind NSA to collection on the Chinese target. There is no way you can use backdoors against hard targets. Hard targets are why they need 0day. It is an arms race because it is a conflict bet…
Governments have used zero days. Most famously to use a zero day unlock an iPhone against a terrorist (whose house was ransacked by the news media). Less famously was to botch a legal case against a pedophile (amazingly, it would be possible to find and arrest nearly all pedophiles on Tor by burning half a million dollars in zero days). But the government didn’t want to release the zero day for Play Pen and Mozilla got involved in the case.
But Freedom Hosting’s zero day was discovered while it was being used. I think the government still uses zero days, but parallel constructs the evidence from them. This is policy making by mismanagement.
On face value, the government is involved in abhorrently irrational decision making. The government cannot be considered responsible enough to have zero days, but that’s an argument that will lead nowhere.