Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

1–10 of 318 posts

Re: We Hacked Apple for 3 Months

#2
Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that.

Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?

Re: We Hacked Apple for 3 Months

#3
July 6 - August 6 - September 6 -- that's 2 months elapsed, not three.

Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions.

I'd say Apple got an amazing bargain.

Re: We Hacked Apple for 3 Months

#4
I sorted exploits by date, it made a fun short headline summary of how productive they were. Short answer: very.

I know it’s hard for senior management to want to really commit to bug bounty programs like this because it feels embarrassing and vulnerable, but posts like this should be sent around the boardroom when discussing — apple rented an AMAZING security team here.

Sam, can you disclose what you got paid for all this?

Re: We Hacked Apple for 3 Months

#5
"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)."

Wow. I would think it's just impossible to secure all that, and that's not even everything.

Re: We Hacked Apple for 3 Months

#7

Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?

> Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?

And Russia, and Iran, and so on... It seems safe to assume someone else out there found at least one of these and got in to the Apple internal network and has been quietly doing their job, whatever it may be.

Re: We Hacked Apple for 3 Months

#8
post #4

I sorted exploits by date, it made a fun short headline summary of how productive they were. Short answer: very. I know it’s hard for senior management to want to really commit to bug bounty programs like this because it feels embarrassing and vulnerable, but posts like this should be sent around the boardroom when discussing — apple rented an AMAZING security team here. Sam, can you disclose what you got paid for al…

End of the post it says 51k so far. I'd expect the price to go up a LOT more, because otherwise the sane (monetary) advice becomes "report some vulnerabilities to apple, and then keep finding them and sell them to third parties".

Re: We Hacked Apple for 3 Months

#9

Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?

> Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have? And Russia, and Iran, and so on... It seems safe to assume someone else out there found at least one of these and got in to the Apple internal network and has been quietly doing their job, whatever it may be.

"Our proof of concept for this report was demonstrating we could read and access Apple’s internal maven repository which contained the source code for what appeared to be hundreds of different applications, iOS, and macOS."

This itself is massive. How many 0-days could emerge from something like that?!

Re: We Hacked Apple for 3 Months

#10
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

As of October 6th, 2020, the vast majority of these findings have been fixed and credited.

3 months as I think they added the extra month as part of the responsible disclosure and remediation phase.

Post reply on HN