Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

191–200 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#191
post #163

Earlier quoted context omitted.

Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.

So the question is, assuming you have a valid exploit, could you not convince Apple to pay more than $1m? If you found an unfound gaping crater of an exploit somewhere -- how much would that be worth to them? Likely a lot more than $1m. I'm sure you could negotiate that number up, a lot.

The problem is that technically finding the exploit at all is in violation of the CFAA. Once you approach Apple with the exploit, you're then skating on their goodwill. Trying to play hardball probably won't go well for you.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#192
post #148
post #15

Earlier quoted context omitted.

Depends who’s buying I imagine. Not sure about everyone else but I always picture the entities buying on the black market as singular people for some reason When you consider it could be the likes of the three digit shoe inspectors over there in the US it could be a fair chunk of change

Who are these individuals that will pay millions of dollars for an exploit? Cyber criminals rely almost exclusively on dead bugs, frequently using exploits from the metasploit framework. That gives then sufficient access to a broad range of victims so they can generate revenue through volume. 0days are used against hardened targets. Think “Iranian nuclear facilities” rather than “grandma’s PC”

They are made up, in my head, figments of my imagination. Hence “for some reason”.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#193
post #163

Earlier quoted context omitted.

Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.

So the question is, assuming you have a valid exploit, could you not convince Apple to pay more than $1m? If you found an unfound gaping crater of an exploit somewhere -- how much would that be worth to them? Likely a lot more than $1m. I'm sure you could negotiate that number up, a lot.

Well how would you otherwise monetize the exploit? You could sell it on the black market, but I doubt you'd be able to make 1M off of it. Then again I don't know the black market so you could?

But bug bounties like this are competing with the shadier markets. I suspect they found out the shady companies are offering more than their existing bug bounty program did.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#194
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

I think that not all companies are the same.

Some companies put a lot of effort in security (Apple, Google, Facebook, etc). Usually they have engineering driven cultures.

The other majority of companies see security just as a cost center that needs to be covered in order to reduce legal liabilities.

The second kind of companies do not have a bug bounty programs because they know that they have too many holes and prefer not to attract too much interest.

For those companies that may have huge capitalization and profits, paying $1M for a vulnerability is not practical.

I expect that in general all companies (including those in the first group) detect compromised accounts and services from time to time but unless they have to disclosed because the laws demand it, they prefer to avoid the bad PR and potential lawsuits.

But while I expect the first kind of companies doing a root cause analysis and improving the systems, the companies in the second group of companies usually just clean up the detected compromised systems and avoid to look too much deep because either they do not have the skills or they are afraid to find things they will have to disclose and be liable for.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#195
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

It depends on how an exploit is monetized; the devils is in the terms: exclusivity, duration, scope and level of access. A non-exclusively-licensed exploit that can be sold 50x for $50k/year is bank ($2.5m/yr). If I were to spend 6-9 months developing a good exploit, I wouldn't give it Apple if and only if money were the primary and sole motivation. However, it makes sense to blog about it, turn it in to Apple and leverage such a discovery into outside Angel funding for a startup... that is if Apple doesn't require onerous NDAs. If the terms from Apple weren't favorable (they're likely to be terrible), then reselling it makes sense if you were really broke or going nonprofit security disclosure route at least parlays it into cred.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#196
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

> bUt 1M dOLlArS iS nOt tHaT mUcH

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#197
post #188
post #171

Earlier quoted context omitted.

I don’t know this market well, but I do know what a 3% dip in Apple’s stock price means, so it seems rather obvious that Apple’s incentive to know of vulnerabilities prior to their sale in an alternative market is worth a lot more than 1M.

Valuing something in terms of its short-term impact on stock doesn't make any sense. An iOS vulnerability is worth a lot, but that the stock price dipped 3% is more of a sign of the market being fickle and reacting to any bad/good news about the company on a given day than 3% of Apple's worth being lost in any meaningful sense. Following this line of thinking leads to some pretty absurd conclusions, like 7% of Tesla'…

First paragraph:

> Shares of Tesla plunge after news of a pair of C-suite executive resignations and a bizarre video showing CEO Elon Musk smoking pot on a podcast.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#198

Earlier quoted context omitted.

On these marketplaces, how do people demonstrate PoC without giving away the intellectual property? Or is it unproven and completely reputation based

Reputation plays a big part in it on both sides. Most buys are not Zerodium and putting themselves out there as buyers. So, there is a certain degree of vouching that happens as someone introduces a buyer to a seller. So, when either party violates the agreement, it reflects poorly on that person who made the introduction, making it harder for them to make those connections in the future. And, these introductions mat…

What's interesting to me about this --- and I've got no firsthand knowledge of the markets --- is that Apple doesn't have to outbid brokers; a broker could offer 50% more than Apple, but that comes with an X% uncertainty penalty. You can sell to Apple and pocket $1MM, or try to structure a deal for $1.5MM and gamble that the bug will survive. I'm betting that's often not a good deal; the lump sum payment is the better option.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#199
post #168

Earlier quoted context omitted.

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

Out of interest how do you get to know the market price or the market in general for this sort of thing? If I were to discover a vulnerability is there a legal way I could cash in on it (aside from this case with Apple)?

[deleted]

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#200
post #163

Earlier quoted context omitted.

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.

This is silly. Apple is going to have bugs almost no matter what they do, as will Google and Microsoft.

It makes sense to invest way over the top if you can kill bug classes outright --- and Apple does this, too. For example, people that were doing DMA hardware attacks against macOS a couple years ago are now on Apple's payroll, designing hardware to defend against those attacks. That's a meaningful serious investment in defense. Rewriting their kernel in a memory safe language would be another example (one they haven't done yet).

Massively outbidding the current spot price for a bug doesn't accomplish anything like that. Think about who they're really bidding against. They can drive the price of bugs way up, and they are doing that gradually, but there will still be a price and people selling them.

The important thing they're doing on this is making unlocked devices available for researchers, and lowering the bar for research for people who would never sell to brokers.

Post reply on HN