"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.
Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich edit: fixed the number of addresses
We Hacked Apple for 3 Months
71–80 of 318 posts
Re: We Hacked Apple for 3 Months
#72The takeaway I have from this is really not related to Apple at all. It's that any network of enough complexity run by an organization of enough complexity is actually impossible to secure.
Re: We Hacked Apple for 3 Months
#73July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.
Re: We Hacked Apple for 3 Months
#74I’ve always been interested in this round of thing, but have no idea how or where to get started
Look at the Apple Distinguished Educators case. They went in with an immediate goal: get admin access. So they targeted the account admin pages. Once you know what technologies were used to build a service/site (in this case Jive), you can do a lot of due diligence looking for known vulnerabilities or common attack vectors with that software.
Re: We Hacked Apple for 3 Months
#75Earlier quoted context omitted.
Exactly. The amount of effort put into finding multiple critical - high vulnerabilities of a $1TN+ company and the result is $51k + taxes to possibly share between 5 hackers for 4 qualifying bugs for that bounty sounds like Apple took them for a cheap ride through their campus. Compared to 1 hacker, 1 month, JWT signature check failure = 100k from Apple [0]: [0] https://bhavukjain.com/blog/2020/05/30/zeroday-signin-w…
The 4 exploits they got paid for don't seem like the biggest ones though. I would expect Apple to pay $500k - $1M for this session in the end, and it would be in the best interest of all parties if this happened. Apple would encourage responsible disclosure (and attract more white-hat bug hunters) this way. The amount of vulnerabilities found is a proof by itself that team work does pay off, if the team is strong. Al…
Re: We Hacked Apple for 3 Months
#76"Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough.
That being said, I don't think anything can be secure, we must treat everything as potentially compromised and act accordingly. I diversify my emails/bank/HDD/etc... So if one gets hacked, I didn't lose everything. Edit- Also those Superstars may be known, but you bet there are experts that would take the money rather than prestige.
Re: We Hacked Apple for 3 Months
#77Earlier quoted context omitted.
Exactly. The amount of effort put into finding multiple critical - high vulnerabilities of a $1TN+ company and the result is $51k + taxes to possibly share between 5 hackers for 4 qualifying bugs for that bounty sounds like Apple took them for a cheap ride through their campus. Compared to 1 hacker, 1 month, JWT signature check failure = 100k from Apple [0]: [0] https://bhavukjain.com/blog/2020/05/30/zeroday-signin-w…
Apple paid with public exposure. Anything Apple is a story of interest, which has a value especially in security circles where half the business is a pure PR exercise. I’ve spent time in my career with a “big gorilla” employer whose business is very visible within its community. Companies will “pay” a lot to say “We solved FooCorp’s problems with ” or “FooCorp bought our ” Lazy buyers assume that their peers have the…
Re: We Hacked Apple for 3 Months
#78Data security is hard, I would rather trust someone who has shown good capability there, invests a lot in that and has more to lose. That's why for the foreseeable future, I would rather use Gmail, Google Drive over their alternatives. Also, why I prefer to use Amazon instead of individual storefronts which ask for contact and payment details.
Re: We Hacked Apple for 3 Months
#79The upside is that nobody needs atomic bombs to shutdown a whole country anymore ;-)
Re: We Hacked Apple for 3 Months
#80It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…