Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

51–60 of 318 posts

Re: We Hacked Apple for 3 Months

#52
post #36

I’ve always been interested in this round of thing, but have no idea how or where to get started

one way to understand how to break things is to first build a couple

when you build things you can understand the trade-offs people have to make which gives you an intuition for weak spots

Re: We Hacked Apple for 3 Months

#53
post #44
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

It doesn't sound like they were working on this 8h a day of every day.

It is not about $/hour, it is about the knowledge they have learnt and that will help Apple protect against some bugs which would result in losses and other damages to consumers..

Re: We Hacked Apple for 3 Months

#54

Bug bounties have always been mispriced. Either the damage estimates for a given bug are wildly over-estimated by risk analysts, or the price paid to find them is based on some kind of stupidity-arbitrage play. I think it's the latter. Consulting firms bill between $1500-$2500/day for senior staff. 2 hackers for 10 days could be the $50k they got paid. Instead, this crew used 5 hackers for say 45 days, or 225 person…

A bug bounty program is aimed to find individual instances of a security hole in your technical architecture. Like finding a weak spot in a ship's hull, and punching a hole.

A security consulting firm would do more for you. They'd basically be telling you how to make your entire hull stronger. And one of the things they might tell you to do, is start a bug bounty program. And they would also likely put things in place for the real security problem in your org: social engineering. Among other things.

And more than that, spending x dollars on a security consulting firm demonstrates that you did some diligence in securing customer data. And that goes a long way in a courtroom.

Re: We Hacked Apple for 3 Months

#55

Bug bounties have always been mispriced. Either the damage estimates for a given bug are wildly over-estimated by risk analysts, or the price paid to find them is based on some kind of stupidity-arbitrage play. I think it's the latter. Consulting firms bill between $1500-$2500/day for senior staff. 2 hackers for 10 days could be the $50k they got paid. Instead, this crew used 5 hackers for say 45 days, or 225 person…

$1500 a day?!?! They are getting ripped off. I had a family member that worked for a large Fortune 500 company tech company. He got to take a look at the invoice for consulting on a project They pay consultants $1500 an HOUR for anything from QA to software engineering.

I had another family member who worked in a big 4 accounting firm. These companies regularly pay in excess of $800 an hour for the most ridiculous consulting. $1500 a day for two people is robbery in the world of consulting.

Re: We Hacked Apple for 3 Months

#56
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

If they actually did get paid so little, why did they do it? This seems like a terrible use of their time.

It is impossible to quantify what is a good use of their time without knowing them. Also not everyone does things in the pursuit of money. I sell eggs and could easily ask 5$ a dozen with the demand I have. Instead I only ask 4$ and have lots of clients I only charge 2$ and some I just give eggs to when I have extra. These are people with no money or means. I don’t expect to ever get anything from these people but every once in a while ‘oh my car breaks down and guess who has the knowledge or tool I need the guy I have been giving eggs’. I know the world will eat you up and take all you have but I personally “invest” my time and effort into a few of the things I enjoy even if the reward is low. These researchers now have an excellent start to a resume which is always a good thing.

Re: We Hacked Apple for 3 Months

#57

"As of now, October 4th, we have received four payments totaling $51,500" What a joke. That's an hourly rate of $20 (assuming 5 researchers working for 3 months). Just enough to buy a MacBook to do the research in the first place.

The big ones haven't been paid out yet it seems

Re: We Hacked Apple for 3 Months

#58
I once came up with a silly way of hijacking facebook accounts that were registered with @hotmail.com. I told both facebook and microsoft about this, never got even a thank you. I know that are some people who make a living out of bug bounty, but I felt very discouraged back then (I was still in college) and never bothered to try again.

Re: We Hacked Apple for 3 Months

#59
post #47

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

> I would think it's just impossible to secure all that You can make sure your village have no spies, you cannot ensure the same for a city. I bet every large enough network is compromised to some degree.

This is the truth. I've worked in large organizations and it really is impossible organizationally to be fully secure. People come and go. Responsibilities change.

The comparison of the city is a really good one.

Re: We Hacked Apple for 3 Months

#60
post #11

Earlier quoted context omitted.

"Our proof of concept for this report was demonstrating we could read and access Apple’s internal maven repository which contained the source code for what appeared to be hundreds of different applications, iOS, and macOS." This itself is massive. How many 0-days could emerge from something like that?!

Great, hard-shell/soft-centre. If anyone asks, why you should go to all the effort to secure the software in your internal-network, that's why.

If you are unable to secure your perimeter, what would lead you to believe that you had better security of your interior?
Post reply on HN