Earlier quoted context omitted.
I appreciate your honesty and taking responsibility. The time I spent in security research had me putting blame pretty far away from middle-people: (a) the users and buyers who almost exclusively go with insecure crap, even if secure ones are highly-usable and/or free; (b) the developers who do nothing to make their software secure. On (b), some vulnerabilities could've been prevented with push-button tools like AFL…
> I appreciate your honesty and taking responsibility. It is a fatal character flaw I have. When people want to know about something I try to help them. > You mention that everyone is doing it with no citations of academic sources. I'd be interested in reading any recent research you believe is high quality There was one by RAND which is good. https://www.rand.org/content/dam/rand/pubs/research_reports/... > represen…
Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
281–290 of 308 posts
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#282Earlier quoted context omitted.
I'm wondering if hedge funds would buy something that would allow access to private data. I heard insider trading is not an unusual thing, so a polished series of exploites wrapped up as a tool with clear interface might be taken seriously.
> if hedge funds would buy something that would allow access to private data Extremely unlikely. The risk/reward if found out is too lopsided. Conviction for insider trading has you pay a penalty and transform your fund into a family office -- Raj Rajaratnam going to prison for a decade is a unique exception not the rule. Conviction for insider trading in combination with wire fraud, espionage, and all the other expl…
Lots and lots of other charges but if no insider is giving you info then it wouldn’t be insider trading.
What would be 100% legal would be if you bought an exploit and then traded on the release of that exploit. Depending on the severity of the exploit it could move the stock price a bit. And, even though people wouldn’t like it, that’s kind of the point of the market. You get rewarded for helping with information and price discovery.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#283Earlier quoted context omitted.
I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell expl…
> I'd imagine this is to combat marketplaces like Zerodium Zerodium already pays double what Apple does. Where's the incentive?
https://law.stackexchange.com/questions/502/is-it-legal-to-s...
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#284What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.
What is the probability of an Apple developer introducing a hard to catch bug and sharing the information with third-party so that they share the bounty?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#285Earlier quoted context omitted.
I don't know. But I do know that the way to prevent that is to handcuff all the developers with crushing process heaviness. Then they won't introduce anything malicious, because they won't introduce anything at all.
Yeah, what is not clear is if they would catch and fire developer/team who introduced $1M bug.
“The Cupertino, California-based company said in a lengthy memo posted to its internal blog that it "caught 29 leakers," last year and noted that 12 of those were arrested. "These people not only lose their jobs, they can face extreme difficulty finding employment elsewhere," Apple added.”
https://www.bloomberg.com/amp/news/articles/2018-04-13/apple...
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#286Earlier quoted context omitted.
I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell expl…
>The only reason people go underground to sell exploits is for the money. Not reputation? Not the thrill of it? Not hatred of Apple? Not plain maliciousness?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#287Earlier quoted context omitted.
Damn this is an awesome break down of the industry, and it's hilarious to me that lo and behold someone suggests the Greenberg article and yeh does grugq himself turn up to settle the score. I can't think my way around your point about prohibition though - I think someone saying "selling exploits is bad" is also someone that would say "the government shouldn't be monitoring us, pedophile or not," and that's part of w…
Think of it like GMO. There are two sides with legitimate concerns. But only one side can speak publicly. As for backdoored Chrome, what is to prevent China using a modified version of Firefox that removes the backdoor? It would blind NSA to collection on the Chinese target. There is no way you can use backdoors against hard targets. Hard targets are why they need 0day. It is an arms race because it is a conflict bet…
Any more information on this? I'm more than a little depressed by the current options in phones - I don't relish the idea of moving to ios - but at the same time I'm a bit worried about the direction Android is taking...
What kind of marked/price range are you aiming for?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#288I remember the days of jailbreak-me.org when you could just visit that website, your iDevice would be rooted, and Cydia would be installed on your iDevice. You could install all sorts of tweaks, mods, and apps through Cydia. I remember installing a Pandora tweak that gave unlimited skips, gave it a black theme, and removed ads (because I was a poor student) and got freaked out because if tweaks could modify apps like that, then they could probably phish banking passwords. Anyone else remember those days?
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#289Earlier quoted context omitted.
No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.
The jailbreak community will not be getting these. They make more money continuing to sell to China than they will make selling to Apple.
How much do they make selling to China?
Aside from the Chinese part of the jb scene, it’s kind of disheartening to know that the rest of them are selling that capability to a hostile adversary (if that’s true). I’m surprised the five eyes aren’t offering enough to keep them out of China’s hands.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#290Earlier quoted context omitted.
> What was, is, and will continue to be, the legitimate sale of vulnerabilities is now closed forever. So in past, present and future, the legitimate sale of vulnerabilities is now closed forever. When was legitimate? Are you saying that since it is not legit, exploits should never be sold? What are you advocating for ?
Sorry, to clarify I was referring to the voice of industry insiders. I mean that no one who knows is willing to speak about it. There is so much bullshit about the “highly lucrative black market” it is staggering. The market is not big. There is significant risk which gets factored into the payment structure, so the payments are lower than people imagine. The market is not very liquid. If you have a Chrome capability…