Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

291–300 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#291

Earlier quoted context omitted.

I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell expl…

On these marketplaces, how do people demonstrate PoC without giving away the intellectual property? Or is it unproven and completely reputation based

I can imagine it being pretty easy.

Hacker: I have a no user-interaction RCE

Apple: ok yeah

Hacker: gimme a phone number

Apple: here you go

Hacker: …

iPhone: I am pwned

Apple: ok lets do the deal

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#293
post #285

Earlier quoted context omitted.

Yeah, what is not clear is if they would catch and fire developer/team who introduced $1M bug.

Given the published corporate policy on leaking I think it’s safe to conclude they would be fired, and most likely prosecuted when possible. “The Cupertino, California-based company said in a lengthy memo posted to its internal blog that it "caught 29 leakers," last year and noted that 12 of those were arrested. "These people not only lose their jobs, they can face extreme difficulty finding employment elsewhere," Ap…

Apple does not have an "internal blog".

Bloomberg.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#294
post #153
post #143

Earlier quoted context omitted.

Speaking about exploits in general, at least the old method was to go to cracking forums and say you have the crack available. Usually you would then get into discussions via an IM and finally broker a price. It used to be done via payment services like PayPal, but I imagine BitCoin would play a large part in the modern world.

It does not.

I'm talking about game exploits, I spoke to some people still in that scene and they say they typically still use PayPal for the protection. According to them, exploits for modern games typically vary from $10 USD to $100 USD, although they go through tonnes of steam accounts in the development process, generally meaning profits are not great. They say it's more for the technical challenge of it.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#295
post #204
post #117

Earlier quoted context omitted.

I don't think it's a PR stunt. The typical layperson doesn't know what's a kernel, so the difference between a drive-by kernel exploit and an app exploit couldn't easily be summarized and made understood. Yes a layperson will understand the difference after you give them a five-minute primer of operating system theory, but in this age of social media who still has the attention span to sit through that, if their inte…

> I don't think it's a PR stunt. I don't get this it is either A or B reasoning. Why can't it be also a PR stunt? Or also contain PR?

PR stunt implies that it was cooked up by PR people as something to be in the media. It’s either that or it’s not.

If a company wants to do something and PR gets involved and makes sure the messaging is good, that’s not a PR “stunt” anymore.

A stunt is a trick.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#297
I think it's a cheap offer. If you are a professional well introduced in the business of selling 0days, for a gem like that, you can charge even a single customer of the same amount. Indeed there are private companies offering even more (https://www.securityweek.com/zerodium-offers-2-million-ios-h... )! Ok, companies involved in this business have some "safeguard" clauses in case the hole is discovered too soon (see for example the Hacking Team e-mails), but you can sell this kind of vulnerability practically to everyone. So the offer IMHO is a public relation move.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#299
Plz dont delete my comment, Ive contacted Apple over 3 times about exploits. I can provide almost every known exploit on iphone. ALMOST EVERY SINGLE EXPLOIT. Changing the trust certificate to gain control of privileges such as implanting a keylogger, exploiting arm for total log data. THERE ARE MANY WAYS. I have all. APPLE IS IGNORING ME ON PURPOSE. KEEP PROMOTING THE PR STUNT

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#300

Plz dont delete my comment, Ive contacted Apple over 3 times about exploits. I can provide almost every known exploit on iphone. ALMOST EVERY SINGLE EXPLOIT. Changing the trust certificate to gain control of privileges such as implanting a keylogger, exploiting arm for total log data. THERE ARE MANY WAYS. I have all. APPLE IS IGNORING ME ON PURPOSE. KEEP PROMOTING THE PR STUNT

Oh, you can just obtain a signed iOS image with law enforcement features enabled.

I assume all law enforcement features are enabled independent of the investigation, as some of them may be solely for investigating crimes involving non-consensual photography.

Post reply on HN