Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

71–80 of 318 posts

Re: We Hacked Apple for 3 Months

#71
post #64

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich edit: fixed the number of addresses

a /8 is actually 16M addresses, not 1M.

Re: We Hacked Apple for 3 Months

#72

The takeaway I have from this is really not related to Apple at all. It's that any network of enough complexity run by an organization of enough complexity is actually impossible to secure.

It's possible, but it requires investment, and it's likely to slow down productivity a little. The default approach in big traditional corps (not implying Apple is traditional) is to leave it up to IT, and maybe hire a Security Officer to signal virtue and assign blame.

Re: We Hacked Apple for 3 Months

#73
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

You are making the false assumption that these people are working fulltime, which they are not. At least 3 of them have full time jobs.

Re: We Hacked Apple for 3 Months

#74
post #36

I’ve always been interested in this round of thing, but have no idea how or where to get started

I've never hunted bugs, but you could start by picking a target website and inspecting traffic on register/login pages, user input screens, pages that load dynamic content (may lead you to API endpoints with methods to exploit), etc.

Look at the Apple Distinguished Educators case. They went in with an immediate goal: get admin access. So they targeted the account admin pages. Once you know what technologies were used to build a service/site (in this case Jive), you can do a lot of due diligence looking for known vulnerabilities or common attack vectors with that software.

Re: We Hacked Apple for 3 Months

#75
post #34
post #24

Earlier quoted context omitted.

Exactly. The amount of effort put into finding multiple critical - high vulnerabilities of a $1TN+ company and the result is $51k + taxes to possibly share between 5 hackers for 4 qualifying bugs for that bounty sounds like Apple took them for a cheap ride through their campus. Compared to 1 hacker, 1 month, JWT signature check failure = 100k from Apple [0]: [0] https://bhavukjain.com/blog/2020/05/30/zeroday-signin-w…

The 4 exploits they got paid for don't seem like the biggest ones though. I would expect Apple to pay $500k - $1M for this session in the end, and it would be in the best interest of all parties if this happened. Apple would encourage responsible disclosure (and attract more white-hat bug hunters) this way. The amount of vulnerabilities found is a proof by itself that team work does pay off, if the team is strong. Al…

10 person months would be 10/12ths of a programmer salary i Silicon Valley, which would probably be around $200k

Re: We Hacked Apple for 3 Months

#76
It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech.

"Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough.

That being said, I don't think anything can be secure, we must treat everything as potentially compromised and act accordingly. I diversify my emails/bank/HDD/etc... So if one gets hacked, I didn't lose everything. Edit- Also those Superstars may be known, but you bet there are experts that would take the money rather than prestige.

Re: We Hacked Apple for 3 Months

#77
post #24

Earlier quoted context omitted.

Exactly. The amount of effort put into finding multiple critical - high vulnerabilities of a $1TN+ company and the result is $51k + taxes to possibly share between 5 hackers for 4 qualifying bugs for that bounty sounds like Apple took them for a cheap ride through their campus. Compared to 1 hacker, 1 month, JWT signature check failure = 100k from Apple [0]: [0] https://bhavukjain.com/blog/2020/05/30/zeroday-signin-w…

Apple paid with public exposure. Anything Apple is a story of interest, which has a value especially in security circles where half the business is a pure PR exercise. I’ve spent time in my career with a “big gorilla” employer whose business is very visible within its community. Companies will “pay” a lot to say “We solved FooCorp’s problems with ” or “FooCorp bought our ” Lazy buyers assume that their peers have the…

While it's a great marketing and reputation building tool, it's still pretty poor to pay people in exposure; they could have taken each and every one of these exploits to the black market instead and they probably would have earned a lot more money.

Re: We Hacked Apple for 3 Months

#78
The work they have done here is amazing. Imagine a company like Apple being vulnerable to this extent. That's why when people bring up a new privacy safe/better UX alternative for a sensitive data service I am very skeptical to try them out. Like for email, fastmail or protonmail or Hey.

Data security is hard, I would rather trust someone who has shown good capability there, invests a lot in that and has more to lose. That's why for the foreseeable future, I would rather use Gmail, Google Drive over their alternatives. Also, why I prefer to use Amazon instead of individual storefronts which ask for contact and payment details.

Re: We Hacked Apple for 3 Months

#79
Computers made it into the furthest corners of our lives. They are controlling critical infrastructure or are a front-end for it. So IT security should really be a top priority in almost any software project or product.

The upside is that nobody needs atomic bombs to shutdown a whole country anymore ;-)

Re: We Hacked Apple for 3 Months

#80

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

I think that saying that Apple is especially bad at security would be wrong. But apple claiming they are the only ones who can protect users might be going a bit far....
Post reply on HN