Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

241–250 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#241

Earlier quoted context omitted.

> I'm surprised by how cheap the vulnerabilities market is I think this has a lot to do with government agencies buying any exploit they can get their hands and there is basically no market besides that. I don't know if that is illegal in the US, but it seems that government is the only buyer.

I'm wondering if hedge funds would buy something that would allow access to private data. I heard insider trading is not an unusual thing, so a polished series of exploites wrapped up as a tool with clear interface might be taken seriously.

A major vuln can probably pretty reliably blip a share price, with FAANG and similar companies' shares that's going to be a chance to make fast bucks.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#242
post #190
post #178

Earlier quoted context omitted.

Think of it like GMO. There are two sides with legitimate concerns. But only one side can speak publicly. As for backdoored Chrome, what is to prevent China using a modified version of Firefox that removes the backdoor? It would blind NSA to collection on the Chinese target. There is no way you can use backdoors against hard targets. Hard targets are why they need 0day. It is an arms race because it is a conflict bet…

Your argument is limited to technical and political science concepts, and by limiting itself so, is correct. It is inapplicable to the real world. Governments have used zero days. Most famously to use a zero day unlock an iPhone against a terrorist (whose house was ransacked by the news media). Less famously was to botch a legal case against a pedophile (amazingly, it would be possible to find and arrest nearly all p…

I’m sorry, I don’t understand.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#243
post #192
post #148

Earlier quoted context omitted.

Who are these individuals that will pay millions of dollars for an exploit? Cyber criminals rely almost exclusively on dead bugs, frequently using exploits from the metasploit framework. That gives then sufficient access to a broad range of victims so they can generate revenue through volume. 0days are used against hardened targets. Think “Iranian nuclear facilities” rather than “grandma’s PC”

They are made up, in my head, figments of my imagination. Hence “for some reason”.

Yeah. They don’t exist. People don’t think about things rationally, they see phrases like “black market” and assume it is some sort of criminal transaction with armed guards and meetings at midnight and shit.

It is nothing like that. It is the same as freelance development work, except there are very few customers and the developer writes something that may or may not have any value.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#245

Earlier quoted context omitted.

Harder than you might think. Who gets to control the server being compromised? 1. The buyer or someone the buyer trusts, then the buyer can log all the network traffic and find the incoming attack traffic and work out the exploit from there. 2. The seller or someone the seller trusts, can backdoor the software to fake it. 3. Someone they both trust, that would require they have some mutual contacts which while possib…

> Who gets to control the server being compromised? I was thinking about phones, not servers. > then the buyer can log all the network traffic and find the incoming attack traffic and work out the exploit from there. Is it really that easy? I'm not a security researcher, but I imagine that most exploits aren't just a magic byte sequence you send to the victim -- so I assumed that just a single observation of a succes…

> I was thinking about phones, not servers.

that doesn't change things too much, it does introduce some potential difficulties with intercepting certain types of traffic/input to the phone. The question just becomes who controls the hardware being compromised.

> but I imagine that most exploits aren't just a magic byte sequence you send to the victim

Its not, and its not like you can just replay those very same bytes, but its not magic, it all has a meaning and a purpose. While its not easy, you can work out plenty from logs. The entire exploit necessarily is there, things will change, but all the instructions[0] that get injected to do later stages necessarily needs to be sent, or the instructions to generate/cause them.

Its not an easy skill, but its not unheard of.

[0] I'm simplifying a bit to avoid getting into various code execution techniques

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#247
post #181

Earlier quoted context omitted.

Bounties on security vulns have difficult dynamics on incentives though. At these levels you start running the risk of an insider subtly introducing a vulnerability and share it with a secret aquaintance.

I’ll say it once more. This isn’t that big of a bounty when you consider what Apple’s iPhone security crew make on average/year.

Don't know why you got downvoted. I think that's a pretty good argument against the particular scenario OP mentionned.

Why would an apple employee take the risk to loose his 300k+ / year salary for a 1M bounty (he'll have to share with the acquaintance) ?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#249
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

> Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability."

¿Porque no los dos? Security and PR.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#250

Earlier quoted context omitted.

Money is not a problem to Nation state actors. Not even $10M will stop any country. Even an African dictator motivated will easily pay $50M if that means getting what it takes to stay in power.

African dictators care for mobile OS hacks for staying in power?

If it makes it easier to spy on the competition, why not?
Post reply on HN