We Hacked Apple for 3 Months
21–30 of 318 posts
Re: We Hacked Apple for 3 Months
#22Re: We Hacked Apple for 3 Months
#23Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?
> Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have? And Russia, and Iran, and so on... It seems safe to assume someone else out there found at least one of these and got in to the Apple internal network and has been quietly doing their job, whatever it may be.
Re: We Hacked Apple for 3 Months
#24July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.
The amount of effort put into finding multiple critical - high vulnerabilities of a $1TN+ company and the result is $51k + taxes to possibly share between 5 hackers for 4 qualifying bugs for that bounty sounds like Apple took them for a cheap ride through their campus.
Compared to 1 hacker, 1 month, JWT signature check failure = 100k from Apple [0]:
[0] https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-a...
Re: We Hacked Apple for 3 Months
#25https://securityboulevard.com/2020/09/def-con-28-safe-mode-r...
Re: We Hacked Apple for 3 Months
#26Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?
Re: We Hacked Apple for 3 Months
#27Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?
> Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have? And Russia, and Iran, and so on... It seems safe to assume someone else out there found at least one of these and got in to the Apple internal network and has been quietly doing their job, whatever it may be.
Re: We Hacked Apple for 3 Months
#28July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.
If they actually did get paid so little, why did they do it? This seems like a terrible use of their time.
Developing exploits that are acknowledged by major targets--even if done freelance or as a hobby--is one of the few ways to gain lines on your resume that everyone in the security field will pay attention to.
Re: We Hacked Apple for 3 Months
#29Earlier quoted context omitted.
> Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have? And Russia, and Iran, and so on... It seems safe to assume someone else out there found at least one of these and got in to the Apple internal network and has been quietly doing their job, whatever it may be.
Any of those countries could just get someone hired at Apple for that
Re: We Hacked Apple for 3 Months
#30July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.