Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

61–70 of 318 posts

Re: We Hacked Apple for 3 Months

#61
post #44

Earlier quoted context omitted.

It doesn't sound like they were working on this 8h a day of every day.

It is not about $/hour, it is about the knowledge they have learnt and that will help Apple protect against some bugs which would result in losses and other damages to consumers..

>It is not about $/hour

It is when the thread kicked off by measuring how much they are being paid / man month...

Re: We Hacked Apple for 3 Months

#62
post #60
post #11

Earlier quoted context omitted.

Great, hard-shell/soft-centre. If anyone asks, why you should go to all the effort to secure the software in your internal-network, that's why.

If you are unable to secure your perimeter, what would lead you to believe that you had better security of your interior?

Less surface area?

Re: We Hacked Apple for 3 Months

#63
I really don't understand this whole "whining over how much I got paid for my bug bounty" thing.

1. Nobody is asking you to find exploits in the systems of a company you don't work for. If you want to use your time that way, then fine, but understand that is your own time-management decision. Don't go complaining about how you feel "undervalued". 2. Companies are under no obligation to pay bounties and companies are certainly under no obligation to pay headline grabbing bounties.

1+2 = Stop whining and be greatful for someone paying you a five-figure (or greater) sum for something you didn't have to do.

Frankly, I also think this whole bug-bounty thing is a little bit dangerous. Sooner or later its going to end with various attempts at blackmail. It strikes me as a very thin line.

(For the avoidance of doubt, I'm speaking in general here. Not about Apple and not about this particular person.)

Re: We Hacked Apple for 3 Months

#64

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich

edit: fixed the number of addresses

Re: We Hacked Apple for 3 Months

#65

I really don't understand this whole "whining over how much I got paid for my bug bounty" thing. 1. Nobody is asking you to find exploits in the systems of a company you don't work for. If you want to use your time that way, then fine, but understand that is your own time-management decision. Don't go complaining about how you feel "undervalued". 2. Companies are under no obligation to pay bounties and companies are…

The whole point of the bounty is to incentivize disclosure to the software/hardware maker instead of using it nefariously or selling it to someone who will. Companies can avoid being "blackmailed" by offering fair prices for bounties. If finding several high severity bugs results in a paltry bounty, there is little incentive to disclose.

Re: We Hacked Apple for 3 Months

#66
post #64

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich edit: fixed the number of addresses

You can use those IPs for something other than webservers.

But yeah, that a bit much for one company. I'll give hosting providers a pass on owning a million IPs, because they're for the lending out to customers.

Re: We Hacked Apple for 3 Months

#67
post #24
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

Exactly. The amount of effort put into finding multiple critical - high vulnerabilities of a $1TN+ company and the result is $51k + taxes to possibly share between 5 hackers for 4 qualifying bugs for that bounty sounds like Apple took them for a cheap ride through their campus. Compared to 1 hacker, 1 month, JWT signature check failure = 100k from Apple [0]: [0] https://bhavukjain.com/blog/2020/05/30/zeroday-signin-w…

Apple paid with public exposure. Anything Apple is a story of interest, which has a value especially in security circles where half the business is a pure PR exercise.

I’ve spent time in my career with a “big gorilla” employer whose business is very visible within its community. Companies will “pay” a lot to say “We solved FooCorp’s problems with ” or “FooCorp bought our ”

Lazy buyers assume that their peers have their shit together.

Re: We Hacked Apple for 3 Months

#68

I really don't understand this whole "whining over how much I got paid for my bug bounty" thing. 1. Nobody is asking you to find exploits in the systems of a company you don't work for. If you want to use your time that way, then fine, but understand that is your own time-management decision. Don't go complaining about how you feel "undervalued". 2. Companies are under no obligation to pay bounties and companies are…

Though bug bounties are more than that. At the end of the day they have revealed vulnerabilities that would have impacted users such as us. IMO we should value these people more.

Re: We Hacked Apple for 3 Months

#69

Am I being hyperbolic or is this an absolutely enormous compromise of trust in Apple? XSS in iCloud Email allowing for data exfiltration of emails, pictures, videos??? That's absolutely insane. It just comes to show how vulnerable we all are to exploits like this, especially if you're a notable person of interest.

Software is made by people and people are not perfect.

The bigger the project the more moving pieces there are and the more likelihood of flaws.

My experience in bug bounty programs has taught me that if you do start a bug bounty program you need to be serious about it and when a report comes in that is actually serious that you need to act on it quickly. And it seems Apple is doing that.

What would be more concerning is if they weren't acting on fixing issues quickly. Some take longer, that's to be expected depending on the problem, but what has been reported so far has been fixed in a timely manner.

Post reply on HN