It's that any network of enough complexity run by an organization of enough complexity is actually impossible to secure.
We Hacked Apple for 3 Months
51–60 of 318 posts
Re: We Hacked Apple for 3 Months
#52I’ve always been interested in this round of thing, but have no idea how or where to get started
when you build things you can understand the trade-offs people have to make which gives you an intuition for weak spots
Re: We Hacked Apple for 3 Months
#53July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.
It doesn't sound like they were working on this 8h a day of every day.
Re: We Hacked Apple for 3 Months
#54Bug bounties have always been mispriced. Either the damage estimates for a given bug are wildly over-estimated by risk analysts, or the price paid to find them is based on some kind of stupidity-arbitrage play. I think it's the latter. Consulting firms bill between $1500-$2500/day for senior staff. 2 hackers for 10 days could be the $50k they got paid. Instead, this crew used 5 hackers for say 45 days, or 225 person…
A security consulting firm would do more for you. They'd basically be telling you how to make your entire hull stronger. And one of the things they might tell you to do, is start a bug bounty program. And they would also likely put things in place for the real security problem in your org: social engineering. Among other things.
And more than that, spending x dollars on a security consulting firm demonstrates that you did some diligence in securing customer data. And that goes a long way in a courtroom.
Re: We Hacked Apple for 3 Months
#55Bug bounties have always been mispriced. Either the damage estimates for a given bug are wildly over-estimated by risk analysts, or the price paid to find them is based on some kind of stupidity-arbitrage play. I think it's the latter. Consulting firms bill between $1500-$2500/day for senior staff. 2 hackers for 10 days could be the $50k they got paid. Instead, this crew used 5 hackers for say 45 days, or 225 person…
I had another family member who worked in a big 4 accounting firm. These companies regularly pay in excess of $800 an hour for the most ridiculous consulting. $1500 a day for two people is robbery in the world of consulting.
Re: We Hacked Apple for 3 Months
#56July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.
If they actually did get paid so little, why did they do it? This seems like a terrible use of their time.
Re: We Hacked Apple for 3 Months
#57"As of now, October 4th, we have received four payments totaling $51,500" What a joke. That's an hourly rate of $20 (assuming 5 researchers working for 3 months). Just enough to buy a MacBook to do the research in the first place.
Re: We Hacked Apple for 3 Months
#58Re: We Hacked Apple for 3 Months
#59"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.
> I would think it's just impossible to secure all that You can make sure your village have no spies, you cannot ensure the same for a city. I bet every large enough network is compromised to some degree.
The comparison of the city is a really good one.
Re: We Hacked Apple for 3 Months
#60Earlier quoted context omitted.
"Our proof of concept for this report was demonstrating we could read and access Apple’s internal maven repository which contained the source code for what appeared to be hundreds of different applications, iOS, and macOS." This itself is massive. How many 0-days could emerge from something like that?!
Great, hard-shell/soft-centre. If anyone asks, why you should go to all the effort to secure the software in your internal-network, that's why.