Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

41–50 of 318 posts

Re: We Hacked Apple for 3 Months

#41
I think what might not be immediately obvious to people outside of the bug bounty scene is that Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes represent some of the best bug bounty hunters out there which is definitely one of the reasons they absolutely pwnd Apple here.

I would be genuinely shocked if Apple doesn't end up paying out much more for all the bugs found. Frankly, it would be genuinely concerning if they didn't acknowledge the severity of the bugs and the time invested by this particularly skilled team.

To Sam and the others involved. Fantastic job and amazing write up. 10/10

Re: We Hacked Apple for 3 Months

#42

Earlier quoted context omitted.

Qualifying people for highly paid info security positions is shockingly broken right now. No one who knows what they are doing cares about credentials you can get from a training program or school, but they also complain constantly about how hard it is to find and hire qualified people. The result is: there is a lot of salary out there for people who can figure out how to get it. Developing exploits that are acknowle…

It's the whole "you need to volunteer for a year before we'll hire you" hiring method typically seen in low paid positions in the arts, but this time for high paid infosec positions...

It's effectively a screen for skills that are very, very difficult to validate with credentials.

Yes, it also is effectively a screen for people with the spare resources to invest in a career without getting paid for it.

Re: We Hacked Apple for 3 Months

#43
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

If they actually did get paid so little, why did they do it? This seems like a terrible use of their time.

Bug bounties are not generally considered a good source of income. It's a way to hone your skills, gain experience, develop a bit of industry cachet and get paid a little in the process.

Re: We Hacked Apple for 3 Months

#44
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

It doesn't sound like they were working on this 8h a day of every day.

Re: We Hacked Apple for 3 Months

#45
post #4

I sorted exploits by date, it made a fun short headline summary of how productive they were. Short answer: very. I know it’s hard for senior management to want to really commit to bug bounty programs like this because it feels embarrassing and vulnerable, but posts like this should be sent around the boardroom when discussing — apple rented an AMAZING security team here. Sam, can you disclose what you got paid for al…

End of the post it says 51k so far. I'd expect the price to go up a LOT more, because otherwise the sane (monetary) advice becomes "report some vulnerabilities to apple, and then keep finding them and sell them to third parties".

That's only true if you have no way to be put in (financial) risk by the vulnerability you're not disclosing to Apple.

Re: We Hacked Apple for 3 Months

#46
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

If they actually did get paid so little, why did they do it? This seems like a terrible use of their time.

For one they did not only get the money but also the exposure that comes with anything Apple. A lot of people will probably want to hire these researchers.

Re: We Hacked Apple for 3 Months

#47

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

> I would think it's just impossible to secure all that

You can make sure your village have no spies, you cannot ensure the same for a city. I bet every large enough network is compromised to some degree.

Re: We Hacked Apple for 3 Months

#49

Earlier quoted context omitted.

Qualifying people for highly paid info security positions is shockingly broken right now. No one who knows what they are doing cares about credentials you can get from a training program or school, but they also complain constantly about how hard it is to find and hire qualified people. The result is: there is a lot of salary out there for people who can figure out how to get it. Developing exploits that are acknowle…

It's the whole "you need to volunteer for a year before we'll hire you" hiring method typically seen in low paid positions in the arts, but this time for high paid infosec positions...

The art world might not be a bad comparison. In both security and art, established people with money are looking for new people who have the ability to make an impact.

But the established folks don't know in advance what exactly that will be... if they did, they'd already be paying someone to do it.

As a new person, there's no better way to demonstrate your ability to make an impact than to just do it.

Re: We Hacked Apple for 3 Months

#50
Bug bounties have always been mispriced. Either the damage estimates for a given bug are wildly over-estimated by risk analysts, or the price paid to find them is based on some kind of stupidity-arbitrage play. I think it's the latter.

Consulting firms bill between $1500-$2500/day for senior staff. 2 hackers for 10 days could be the $50k they got paid. Instead, this crew used 5 hackers for say 45 days, or 225 person days. Napkin arithmetic suggests that's somewhere between $240k and $560k.

I could say it's consulting firms who are overpriced, as a group of amateurs will do better work for for %10-%20 of the cost, but over the years I've found that the difference in the security world is that you hire a small shop to discover the truth about risks, but you pay a big firm to lie about them. That's what costs extra, and given their transparency maybe this work wasn't mispriced at all.

Post reply on HN