Earlier quoted context omitted.
What is the probability of an Apple developer introducing a hard to catch bug and sharing the information with third-party so that they share the bounty?
I don't know. But I do know that the way to prevent that is to handcuff all the developers with crushing process heaviness. Then they won't introduce anything malicious, because they won't introduce anything at all.
Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
261–270 of 308 posts
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#262Earlier quoted context omitted.
This has nothing to do with hacking, so none of that applies. You're conflating attacking someone else's computer or network. You don't need safe harbor because analyzing your own property is not a crime. Neither is telling people what you found. Also, please stop using the term responsible disclosure!
> You don't need safe harbor because analyzing your own property is not a crime. Do you own the OS you’re breaking into?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#263Earlier quoted context omitted.
Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.
This is silly. Apple is going to have bugs almost no matter what they do, as will Google and Microsoft. It makes sense to invest way over the top if you can kill bug classes outright --- and Apple does this, too. For example, people that were doing DMA hardware attacks against macOS a couple years ago are now on Apple's payroll, designing hardware to defend against those attacks. That's a meaningful serious investmen…
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#264If anyone found a way to bypass iCloud Activation Lock it would allow people like me, who run donation programs, to reuse the hundreds of cosmetically and functionally perfect Apple products that come in each year.
Apple can't allow that. It would be good for the planet and good for the impoverished inner-city people that our program serves.
"Fuck 'em all, and fuck the planet too", says Apple. "You can all go to hell when the sea levels rise and people die en masse from heat stroke. So long, suckers. We're moving to our fortress in the hills of New Zealand."
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#265Earlier quoted context omitted.
> I'm surprised by how cheap the vulnerabilities market is I think this has a lot to do with government agencies buying any exploit they can get their hands and there is basically no market besides that. I don't know if that is illegal in the US, but it seems that government is the only buyer.
I'm wondering if hedge funds would buy something that would allow access to private data. I heard insider trading is not an unusual thing, so a polished series of exploites wrapped up as a tool with clear interface might be taken seriously.
Extremely unlikely. The risk/reward if found out is too lopsided. Conviction for insider trading has you pay a penalty and transform your fund into a family office -- Raj Rajaratnam going to prison for a decade is a unique exception not the rule.
Conviction for insider trading in combination with wire fraud, espionage, and all the other exploit-related charges will send everyone involved to prison for 10-20 years, pretty much guaranteed. What use is a bigger hedge fund if you have that sword of Damocles hanging over you?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#266Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#267Earlier quoted context omitted.
It is not illegal to sell that type of software. It is not a black market, it is a grey market. There is no way you will ever hear authentic answers to your questions. The only time anyone tried to explain that the resulting article backfired on the interviewee. (Disclaimer, it was me) Governments do not buy from developers. The paperwork would be insane. They buy from businesses like Raytheon. How Raytheon gets them…
I appreciate your honesty and taking responsibility. The time I spent in security research had me putting blame pretty far away from middle-people: (a) the users and buyers who almost exclusively go with insecure crap, even if secure ones are highly-usable and/or free; (b) the developers who do nothing to make their software secure. On (b), some vulnerabilities could've been prevented with push-button tools like AFL…
It is a fatal character flaw I have. When people want to know about something I try to help them.
> You mention that everyone is doing it with no citations of academic sources. I'd be interested in reading any recent research you believe is high quality
There was one by RAND which is good.
https://www.rand.org/content/dam/rand/pubs/research_reports/...
> represents the current market.
There is nothing that I am aware of that discusses the current market. The RAND paper is closest.
> acting in good faith.
I should not have used a blanket statement. My point is that there are people in IC who are legitimately going after terrorists and child abusers. They have a legitimate need for capabilities that enable them to do that.
I am not saying that the IC is a benign and wonderful government organ. I am saying that within IC there are people who are actually hunting terrorists and pedophiles. I didn't want to explain all of that because it is obvious that it is true. Hence, "lets take it for granted". Rather than discussing the history of the IC, I wanted to explain that there are legitimate uses for 0day and that is the issue being discussed.
The rest is not relevant to explaining how the vulnerability market operates. (Well, how it did in 2011.) When someone asks "how do shares work?" you don't start off by talking about boom and bust markets and macroeconomics. Same thing here. "How does the market work?" is not a question about the IC. It is about how the market works. If you're talking about the vulnerability market you talk about the vulnerability market. You have to assume that there are legitimate players who are acting in good faith.
This entire post is why I abridged it to "lets assume good faith."
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#268What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.
What is the probability of an Apple developer introducing a hard to catch bug and sharing the information with third-party so that they share the bounty?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#269What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.
Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…
Now, by keeping these 0days off the market, Apple also gets to further burnish their reputation. It's a good play no matter how you look at it.
Of course, first Apple needed to be fairly certain that there aren't tens of thousands of vulns left to patch!