Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

231–240 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#231
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

>>I'm surprised by how cheap the vulnerabilities market is.

I presume that it is a legal minefield, selling 0days and extortion are first cousins, at least. If you could hold a bid, no doubt an Arab country would pay $50 Mil for one...but they buy them from companies that sell "software" and services.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#232
post #178

Earlier quoted context omitted.

Think of it like GMO. There are two sides with legitimate concerns. But only one side can speak publicly. As for backdoored Chrome, what is to prevent China using a modified version of Firefox that removes the backdoor? It would blind NSA to collection on the Chinese target. There is no way you can use backdoors against hard targets. Hard targets are why they need 0day. It is an arms race because it is a conflict bet…

>Years ago I wrote “free security advice” and the basic concept is still relevant. I should update it now though. It looks like you DID update it: https://gist.github.com/grugq/353b6fc9b094d5700c70 And from that gist: > Use an iPod or an iPad without a SIM card > Use an iPhone How can you then says: > A hardened Android device (disclaimer, I’m making one for retail sale) is safer than a stock iOS. ? Is Android (and i…

As I said, I should update it.

When I wrote it Android devices never got patched (hence the advice to switch to a FOSS rom that would be updated, rather than a frozen in time factory ROM.)

Security involves a lot more than just access to the source code. That is simply a factor in the ease of some techniques for vulnerability discovery. Back then Android had poor process isolation, significant problems with its sandbox, lax SELinux configurations, insecure software architecture (eg not using “least privilege”)

For a regular user, a stock iOS device is safer than an Android device because there is very little iOS malware in the wild. For a user at risk, then they are safer using a secured device, which by default means modified Android.

Security is not a generic “thing”. It is a continuous process that provides countermeasures against threats by mitigating risks.

If you want a device that is safe by default, will always be patched, and is not vulnerable to indiscriminate exploitation or malware embedded in apps — use iOS.

You can achieve that with a Google Android device (starting with about v8 or so). Of course you still have to be vigilant against malware laden apps.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#233

Will this be the end of rooted iPhones?

This looks to be a rooted iPhone.

Yes, but immediately patched by Apple. It seems to me that in the future you simply can't own a rooted iPhone, because Apple put a $1M bounty on making that impossible.

(If you don't see where this is going: after a while all the security holes will be patched, and thus no more rooted iPhones.)

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#234

Earlier quoted context omitted.

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

> I'm surprised by how cheap the vulnerabilities market is I think this has a lot to do with government agencies buying any exploit they can get their hands and there is basically no market besides that. I don't know if that is illegal in the US, but it seems that government is the only buyer.

I'm wondering if hedge funds would buy something that would allow access to private data. I heard insider trading is not an unusual thing, so a polished series of exploites wrapped up as a tool with clear interface might be taken seriously.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#235
post #170

Earlier quoted context omitted.

Yeah, that’s part of the hatchet job. I said I was projecting sales of $1M over the year. At 15% commission that would be $150k. You can make a lot more money than that, I’m sure. Also, don’t predict your sales funnel in February when you have no historical data to compare it with. I was off by about $900k. So yeah, that $15k golden egg. ¯\_(ツ)_/¯ At thetime I did not know about phrases like “off the record” or that…

> I was projecting sales of $1M over the year. At 15% commission that would be $150k. That's a pretty big difference indeed, that's more like a normal SV salary than a 'live for ever in Thailand' amount of money.

Yes. It is less than any salary I could make at a company if I could get a job. But that article was a career limiting move. C’est la vie. Never talk to reporters unless you have a specific reason to. Definitely don’t talk to reporters who burn their sources.

I understand that he is writing a book now, and I doubt many insiders will speak to him. I don’t expect it to be very accurate.

I had a lot of problems because of that article. Not just the death threats and such, but ... do not ever become interesting to states. They have a lot of resources.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#236
post #153

Earlier quoted context omitted.

It does not.

Anonymous coins then? Or since they are companies, they are ok to revel their identity?

In the Greenberg article, he's photographed with a good old bag of cash...

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#237
post #153

Earlier quoted context omitted.

It does not.

Anonymous coins then? Or since they are companies, they are ok to revel their identity?

In the real world where people do transactions for money they send invoices and do bank transfers.

I believe some companies offer cash in hand or bitcoin payments, but by no means is that “the way it is done”

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#238

Earlier quoted context omitted.

I imagine that a remote exploit should be pretty easy to demonstrate without giving away how you did it?

Harder than you might think. Who gets to control the server being compromised? 1. The buyer or someone the buyer trusts, then the buyer can log all the network traffic and find the incoming attack traffic and work out the exploit from there. 2. The seller or someone the seller trusts, can backdoor the software to fake it. 3. Someone they both trust, that would require they have some mutual contacts which while possib…

> Who gets to control the server being compromised?

I was thinking about phones, not servers.

> then the buyer can log all the network traffic and find the incoming attack traffic and work out the exploit from there.

Is it really that easy? I'm not a security researcher, but I imagine that most exploits aren't just a magic byte sequence you send to the victim -- so I assumed that just a single observation of a successful attack is not enough to understand it easily.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#239
post #236

Earlier quoted context omitted.

Anonymous coins then? Or since they are companies, they are ok to revel their identity?

In the Greenberg article, he's photographed with a good old bag of cash...

Yup. About $20k USD that I had withdrawn. It was a payment to a developer.

If you look closely you can see all the paper towels the photog stuffed into the bag. (He also tried to steal one of the stacks, lol. It was his bag, and when he gave me the money back it was short. He accidentally “missed” one of the stacks.)

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#240

Earlier quoted context omitted.

> What was, is, and will continue to be, the legitimate sale of vulnerabilities is now closed forever. So in past, present and future, the legitimate sale of vulnerabilities is now closed forever. When was legitimate? Are you saying that since it is not legit, exploits should never be sold? What are you advocating for ?

I think (though I can't be sure), what they're trying to say is that it's still legitimate, but it's opaque, because nobody wants to talk about it. Because of that, it seems, to outsiders, like it's an evil black market, even though many people involved in it, believe that they're doing the right thing.

Exactly so.
Post reply on HN