Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

281–290 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#281
post #267

Earlier quoted context omitted.

I appreciate your honesty and taking responsibility. The time I spent in security research had me putting blame pretty far away from middle-people: (a) the users and buyers who almost exclusively go with insecure crap, even if secure ones are highly-usable and/or free; (b) the developers who do nothing to make their software secure. On (b), some vulnerabilities could've been prevented with push-button tools like AFL…

> I appreciate your honesty and taking responsibility. It is a fatal character flaw I have. When people want to know about something I try to help them. > You mention that everyone is doing it with no citations of academic sources. I'd be interested in reading any recent research you believe is high quality There was one by RAND which is good. https://www.rand.org/content/dam/rand/pubs/research_reports/... > represen…

Leaving it out because it was mostly irrelevant makes sense. There's definitely folks doing good with these capabilities. I'm a big fan of their work and grateful for their sacrifices. And thanks for the RAND link. I'll check it out later.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#282

Earlier quoted context omitted.

I'm wondering if hedge funds would buy something that would allow access to private data. I heard insider trading is not an unusual thing, so a polished series of exploites wrapped up as a tool with clear interface might be taken seriously.

> if hedge funds would buy something that would allow access to private data Extremely unlikely. The risk/reward if found out is too lopsided. Conviction for insider trading has you pay a penalty and transform your fund into a family office -- Raj Rajaratnam going to prison for a decade is a unique exception not the rule. Conviction for insider trading in combination with wire fraud, espionage, and all the other expl…

Well, for what it’s worth, if you purchase an exploit and use it to hack phones and then trade on the info you steal, I don’t think there would be any insider trading charges involved.

Lots and lots of other charges but if no insider is giving you info then it wouldn’t be insider trading.

What would be 100% legal would be if you bought an exploit and then traded on the release of that exploit. Depending on the severity of the exploit it could move the stock price a bit. And, even though people wouldn’t like it, that’s kind of the point of the market. You get rewarded for helping with information and price discovery.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#283
post #273

Earlier quoted context omitted.

I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell expl…

> I'd imagine this is to combat marketplaces like Zerodium Zerodium already pays double what Apple does. Where's the incentive?

There is no question on the legality of accepting money from Apple. Accepting money from Zerodium comes with some risk for some people.

https://law.stackexchange.com/questions/502/is-it-legal-to-s...

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#284
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

What is the probability of an Apple developer introducing a hard to catch bug and sharing the information with third-party so that they share the bounty?

I think the probability is very low. Apple pays developers very well, and you're asking them to risk all future salary and their freedom. That’s going to cost a lot. Much more than $1M, I would think.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#285

Earlier quoted context omitted.

I don't know. But I do know that the way to prevent that is to handcuff all the developers with crushing process heaviness. Then they won't introduce anything malicious, because they won't introduce anything at all.

Yeah, what is not clear is if they would catch and fire developer/team who introduced $1M bug.

Given the published corporate policy on leaking I think it’s safe to conclude they would be fired, and most likely prosecuted when possible.

“The Cupertino, California-based company said in a lengthy memo posted to its internal blog that it "caught 29 leakers," last year and noted that 12 of those were arrested. "These people not only lose their jobs, they can face extreme difficulty finding employment elsewhere," Apple added.”

https://www.bloomberg.com/amp/news/articles/2018-04-13/apple...

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#286
post #259

Earlier quoted context omitted.

I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell expl…

>The only reason people go underground to sell exploits is for the money. Not reputation? Not the thrill of it? Not hatred of Apple? Not plain maliciousness?

I don't know anyone who hates apple that much. This way, you still get the reputation and thrill. The only people left are malicious actors, like state sponsored attacks.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#287
post #178

Earlier quoted context omitted.

Damn this is an awesome break down of the industry, and it's hilarious to me that lo and behold someone suggests the Greenberg article and yeh does grugq himself turn up to settle the score. I can't think my way around your point about prohibition though - I think someone saying "selling exploits is bad" is also someone that would say "the government shouldn't be monitoring us, pedophile or not," and that's part of w…

Think of it like GMO. There are two sides with legitimate concerns. But only one side can speak publicly. As for backdoored Chrome, what is to prevent China using a modified version of Firefox that removes the backdoor? It would blind NSA to collection on the Chinese target. There is no way you can use backdoors against hard targets. Hard targets are why they need 0day. It is an arms race because it is a conflict bet…

> A hardened Android device (disclaimer, I’m making one for retail sale)

Any more information on this? I'm more than a little depressed by the current options in phones - I don't relish the idea of moving to ios - but at the same time I'm a bit worried about the direction Android is taking...

What kind of marked/price range are you aiming for?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#288
This is fantastic news from Apple! I use an iPhone and I can sleep a little better at night knowing that someone would now have to risk burning a $1Million exploit if they wanted to hack me! I’m not worth near that much yet so I’m probably not worth spending $1M on.

I remember the days of jailbreak-me.org when you could just visit that website, your iDevice would be rooted, and Cydia would be installed on your iDevice. You could install all sorts of tweaks, mods, and apps through Cydia. I remember installing a Pandora tweak that gave unlimited skips, gave it a black theme, and removed ads (because I was a poor student) and got freaked out because if tweaks could modify apps like that, then they could probably phish banking passwords. Anyone else remember those days?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#289
post #150

Earlier quoted context omitted.

No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.

The jailbreak community will not be getting these. They make more money continuing to sell to China than they will make selling to Apple.

Some are already in the “vetted” bounty program. That doesn’t necessarily mean they will sell Apple the bugs though.

How much do they make selling to China?

Aside from the Chinese part of the jb scene, it’s kind of disheartening to know that the rest of them are selling that capability to a hostile adversary (if that’s true). I’m surprised the five eyes aren’t offering enough to keep them out of China’s hands.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#290
post #229

Earlier quoted context omitted.

> What was, is, and will continue to be, the legitimate sale of vulnerabilities is now closed forever. So in past, present and future, the legitimate sale of vulnerabilities is now closed forever. When was legitimate? Are you saying that since it is not legit, exploits should never be sold? What are you advocating for ?

Sorry, to clarify I was referring to the voice of industry insiders. I mean that no one who knows is willing to speak about it. There is so much bullshit about the “highly lucrative black market” it is staggering. The market is not big. There is significant risk which gets factored into the payment structure, so the payments are lower than people imagine. The market is not very liquid. If you have a Chrome capability…

Based on their recent acquisition, it seems like Azimuth made something of a working de-risked business model relative to the uncertainty of the broker days, no?
Post reply on HN