Will this be the end of rooted iPhones?
Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
221–230 of 308 posts
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#222Earlier quoted context omitted.
Reputation plays a big part in it on both sides. Most buys are not Zerodium and putting themselves out there as buyers. So, there is a certain degree of vouching that happens as someone introduces a buyer to a seller. So, when either party violates the agreement, it reflects poorly on that person who made the introduction, making it harder for them to make those connections in the future. And, these introductions mat…
What's interesting to me about this --- and I've got no firsthand knowledge of the markets --- is that Apple doesn't have to outbid brokers; a broker could offer 50% more than Apple, but that comes with an X% uncertainty penalty. You can sell to Apple and pocket $1MM, or try to structure a deal for $1.5MM and gamble that the bug will survive. I'm betting that's often not a good deal; the lump sum payment is the bette…
Not all brokers are alike though, exploit survival is a gamble, but sensible end-buyers usually don't want to burn the exploits either so will use them sensibly. There are some brokers that don't sell exclusively (despite their claims), they have a reputation for exploits getting burned early.
I have not been involved with any iOS exploits, not really my area of interest, but lets say I was. Would I consider selling it off to Apple, yeah, it would be something to consider. I'd consider the market rates too of course, 1MM vs 1.5MM, sure Apple is enticing, 1MM vs 2MM, maybe not. Not sure where I would actually draw a line, but you are right that Apple doesn't need to compete directly with the market rate, just close enough.
I'm sure there are those that would rather just go for the bigger profits regardless.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#223Earlier quoted context omitted.
It is not illegal to sell that type of software. It is not a black market, it is a grey market. There is no way you will ever hear authentic answers to your questions. The only time anyone tried to explain that the resulting article backfired on the interviewee. (Disclaimer, it was me) Governments do not buy from developers. The paperwork would be insane. They buy from businesses like Raytheon. How Raytheon gets them…
> What was, is, and will continue to be, the legitimate sale of vulnerabilities is now closed forever. So in past, present and future, the legitimate sale of vulnerabilities is now closed forever. When was legitimate? Are you saying that since it is not legit, exploits should never be sold? What are you advocating for ?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#224Given I know "stuff" but compared to anybody who really "knows" I am a noob in exploit engineering. I just know basic inner workings of a computer and a little reverse engineering. Would it even make sense for me to try? It seems like the probability I find something, especially without user interaction, seems so far off that it would be hard for me to find a constant motivation. Imagine one year where I dedicate two…
> Imagine one year where I dedicate two days a week learning, understanding and trying. Do I would have any chance at all to find something worth the $1M? Yes...but probably not the way you're thinking. Most issues are discovered these days through fuzzing first. So there is always a chance your fuzzer will find an issue worth $1M, its much less likely that you'll realize its worth or be able to demonstrate and begin…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#225Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…
I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.
I think this has a lot to do with government agencies buying any exploit they can get their hands and there is basically no market besides that. I don't know if that is illegal in the US, but it seems that government is the only buyer.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#226> Apple’s head of security engineering Ivan Krstić Oh great, the creator of that bitfrost junk. Time to short Apple.
What’s wrong with Bitfrost?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#227Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#228"The full $1 million will go to researchers who can find a hack of the kernel—the core of iOS—with zero clicks required by the iPhone owner. Another $500,000 will be given to those who can find a “network attack requiring no user interaction." Ehhh, whats the point in this exactly? Apple only considers bugs to be significant if the penetration can happen without help from the end user? Thats not how this works in the…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#229Earlier quoted context omitted.
It is not illegal to sell that type of software. It is not a black market, it is a grey market. There is no way you will ever hear authentic answers to your questions. The only time anyone tried to explain that the resulting article backfired on the interviewee. (Disclaimer, it was me) Governments do not buy from developers. The paperwork would be insane. They buy from businesses like Raytheon. How Raytheon gets them…
> What was, is, and will continue to be, the legitimate sale of vulnerabilities is now closed forever. So in past, present and future, the legitimate sale of vulnerabilities is now closed forever. When was legitimate? Are you saying that since it is not legit, exploits should never be sold? What are you advocating for ?
There is so much bullshit about the “highly lucrative black market” it is staggering. The market is not big. There is significant risk which gets factored into the payment structure, so the payments are lower than people imagine.
The market is not very liquid. If you have a Chrome capability for sale but your client already has a Chrome capability, they won’t buy it. If their capability dies, then they’ll want yours, but by then yours might be dead as well. Gross oversimplification, but that is generally how things work. The demand is very specific, the supply is very limited, and the product is very fragile (particularly time sensitive.) It is lucrative like making a startup is lucrative. You invest a lot of time and resources and sometimes, with luck, you win big, but the odds are not in your favor for a million dollar payday.
Most articles treat it like some sort of open market drugs bazaar. It is nothing like that at all. It is more like a handcrafted goods faire with a few wealthy customers looking for exactly the thing they need. Only they won’t tell you what they need, they simply want to see what is on display. Lots of window shoppers, as it were.
The product has an unknown shelf life.
The customer cannot tell you what they need, they will only look at what you have and possibly choose something.
For the developer they need to ensure that they provide sufficient information about the capability so the customer can make an informed decision. But they have to avoid revealing sufficient details that it can be reproduced from the ad copy.
Part of what a broker does is actually translating between two parties who don’t speak the same language. The customer needs a tor browser Bundle capability. The developer has written a UAF RCE Firefox that relying on JIT spraying for reliability. Someone has to translate from exploit dev speak into IC language.
For the IC, that TBB capability is a replaceable part in a larger program that enables them to achieve their mission objectives. For the exploit dev, that bug is a labor of love that they spent months working on. They have completely different views on the value of the capability. One side sees it as a component they need for a machine they want to use. The other side sees it as weeks of frustration and pain invested into a unique masterpiece.
They have different expectations, don’t speak the same language, and don’t trust each other. Things have changed a lot from when I was involved. It’s all very fascinating but, as I said, no one who knows about it will discuss it.
I’m being stupid and talking about it, again. But hopefully this will clear up some of the stupid myths about the vulnerability market.
For example all those “wow, a way to read a someone’s private messages on Facebook? That’s got to be worth millions!!” No, it is not. If a legitimate client wants to read someone’s messages on Facebook, they get a warrant. There is no ROI for cyber criminals, and whatever it might be worth to North Korea the risks associated with that sale are not worth it. That bug is worth whatever Facebook says it is worth. Dropping the 0day would make for some news, but mostly it would be negative. So the only rational way for a security researcher to make money from a Facebook bug is through the bug bounty system. (I’m not addressing cyber criminals discovering such a bug, because that is not relevant to the issue of vulnerability sales.)
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#230Earlier quoted context omitted.
Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.
So the question is, assuming you have a valid exploit, could you not convince Apple to pay more than $1m? If you found an unfound gaping crater of an exploit somewhere -- how much would that be worth to them? Likely a lot more than $1m. I'm sure you could negotiate that number up, a lot.
As Warren Buffet says there is plenty of money to be made in the centre