Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

31–40 of 318 posts

Re: We Hacked Apple for 3 Months

#31
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

If they actually did get paid so little, why did they do it? This seems like a terrible use of their time.

If you wanted to get hired as a bank robber, how would you do it? Gotta rob a few banks first.

Re: We Hacked Apple for 3 Months

#32

Earlier quoted context omitted.

If they actually did get paid so little, why did they do it? This seems like a terrible use of their time.

Qualifying people for highly paid info security positions is shockingly broken right now. No one who knows what they are doing cares about credentials you can get from a training program or school, but they also complain constantly about how hard it is to find and hire qualified people. The result is: there is a lot of salary out there for people who can figure out how to get it. Developing exploits that are acknowle…

It's the whole "you need to volunteer for a year before we'll hire you" hiring method typically seen in low paid positions in the arts, but this time for high paid infosec positions...

Re: We Hacked Apple for 3 Months

#34
post #24
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

Exactly. The amount of effort put into finding multiple critical - high vulnerabilities of a $1TN+ company and the result is $51k + taxes to possibly share between 5 hackers for 4 qualifying bugs for that bounty sounds like Apple took them for a cheap ride through their campus. Compared to 1 hacker, 1 month, JWT signature check failure = 100k from Apple [0]: [0] https://bhavukjain.com/blog/2020/05/30/zeroday-signin-w…

The 4 exploits they got paid for don't seem like the biggest ones though.

I would expect Apple to pay $500k - $1M for this session in the end, and it would be in the best interest of all parties if this happened. Apple would encourage responsible disclosure (and attract more white-hat bug hunters) this way. The amount of vulnerabilities found is a proof by itself that team work does pay off, if the team is strong. Also, this is a drop in the bucket for Apple. It would probably cost them much more to have them on the payroll for the same amount of time.

Re: We Hacked Apple for 3 Months

#38
post #35

$6k for an internal perimiter SSRF that led to source code access? What a joke.

Is that not the "XML External Entity processing to Blind SSRF on Java Management API" SSRF? As that would make sense to match that payment. I really struggle to believe that the $6k is for the maven access one, that's a billion dollar vulnerability.

Re: We Hacked Apple for 3 Months

#39

Am I being hyperbolic or is this an absolutely enormous compromise of trust in Apple? XSS in iCloud Email allowing for data exfiltration of emails, pictures, videos??? That's absolutely insane. It just comes to show how vulnerable we all are to exploits like this, especially if you're a notable person of interest.

Imagine how many thousands of exploits Apple has found and fixed internally, that weren’t found by outside researchers.

Bug bounty programs aren’t a replacement for internal security, and they have the potential to be very expensive compared to paying someone a salary.

Is it an enormous compromise of trust? Dunno. With an average fix time of a single business day, I’m inclined towards “no”: that’s an awfully rapid response for incompetence to deliver.

Re: We Hacked Apple for 3 Months

#40

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

7,000 unique domains seems insane, what could they possibly need all of those for? Unless that includes subdomains, I guess.
Post reply on HN