Earlier quoted context omitted.
Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.
So the question is, assuming you have a valid exploit, could you not convince Apple to pay more than $1m? If you found an unfound gaping crater of an exploit somewhere -- how much would that be worth to them? Likely a lot more than $1m. I'm sure you could negotiate that number up, a lot.
Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
191–200 of 308 posts
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#192Earlier quoted context omitted.
Depends who’s buying I imagine. Not sure about everyone else but I always picture the entities buying on the black market as singular people for some reason When you consider it could be the likes of the three digit shoe inspectors over there in the US it could be a fair chunk of change
Who are these individuals that will pay millions of dollars for an exploit? Cyber criminals rely almost exclusively on dead bugs, frequently using exploits from the metasploit framework. That gives then sufficient access to a broad range of victims so they can generate revenue through volume. 0days are used against hardened targets. Think “Iranian nuclear facilities” rather than “grandma’s PC”
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#193Earlier quoted context omitted.
Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.
So the question is, assuming you have a valid exploit, could you not convince Apple to pay more than $1m? If you found an unfound gaping crater of an exploit somewhere -- how much would that be worth to them? Likely a lot more than $1m. I'm sure you could negotiate that number up, a lot.
But bug bounties like this are competing with the shadier markets. I suspect they found out the shady companies are offering more than their existing bug bounty program did.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#194Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…
I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.
Some companies put a lot of effort in security (Apple, Google, Facebook, etc). Usually they have engineering driven cultures.
The other majority of companies see security just as a cost center that needs to be covered in order to reduce legal liabilities.
The second kind of companies do not have a bug bounty programs because they know that they have too many holes and prefer not to attract too much interest.
For those companies that may have huge capitalization and profits, paying $1M for a vulnerability is not practical.
I expect that in general all companies (including those in the first group) detect compromised accounts and services from time to time but unless they have to disclosed because the laws demand it, they prefer to avoid the bad PR and potential lawsuits.
But while I expect the first kind of companies doing a root cause analysis and improving the systems, the companies in the second group of companies usually just clean up the detected compromised systems and avoid to look too much deep because either they do not have the skills or they are afraid to find things they will have to disclose and be liable for.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#195Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…
I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#196Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#197Earlier quoted context omitted.
I don’t know this market well, but I do know what a 3% dip in Apple’s stock price means, so it seems rather obvious that Apple’s incentive to know of vulnerabilities prior to their sale in an alternative market is worth a lot more than 1M.
Valuing something in terms of its short-term impact on stock doesn't make any sense. An iOS vulnerability is worth a lot, but that the stock price dipped 3% is more of a sign of the market being fickle and reacting to any bad/good news about the company on a given day than 3% of Apple's worth being lost in any meaningful sense. Following this line of thinking leads to some pretty absurd conclusions, like 7% of Tesla'…
> Shares of Tesla plunge after news of a pair of C-suite executive resignations and a bizarre video showing CEO Elon Musk smoking pot on a podcast.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#198Earlier quoted context omitted.
On these marketplaces, how do people demonstrate PoC without giving away the intellectual property? Or is it unproven and completely reputation based
Reputation plays a big part in it on both sides. Most buys are not Zerodium and putting themselves out there as buyers. So, there is a certain degree of vouching that happens as someone introduces a buyer to a seller. So, when either party violates the agreement, it reflects poorly on that person who made the introduction, making it harder for them to make those connections in the future. And, these introductions mat…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#199Earlier quoted context omitted.
I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.
Out of interest how do you get to know the market price or the market in general for this sort of thing? If I were to discover a vulnerability is there a legal way I could cash in on it (aside from this case with Apple)?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#200Earlier quoted context omitted.
I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.
Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.
It makes sense to invest way over the top if you can kill bug classes outright --- and Apple does this, too. For example, people that were doing DMA hardware attacks against macOS a couple years ago are now on Apple's payroll, designing hardware to defend against those attacks. That's a meaningful serious investment in defense. Rewriting their kernel in a memory safe language would be another example (one they haven't done yet).
Massively outbidding the current spot price for a bug doesn't accomplish anything like that. Think about who they're really bidding against. They can drive the price of bugs way up, and they are doing that gradually, but there will still be a price and people selling them.
The important thing they're doing on this is making unlocked devices available for researchers, and lowering the bar for research for people who would never sell to brokers.