Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

81–90 of 318 posts

Re: We Hacked Apple for 3 Months

#81
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

Something tells me the real money comes from future consulting contracts and that this PR will more than pay for itself. Just like how everyone on HN agrees writing a book isn't a great use of time besides what it allows you to put on your resume.

Just because Apple got an amazing bargain doesn't mean the payout for them won't be great as well.

Re: We Hacked Apple for 3 Months

#82
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

> However, it appears that Apple does payments in batches and will likely pay for more of the issues in the following months.

Annoying, but possibly more to come.

Re: We Hacked Apple for 3 Months

#83
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

That blog post alone is worth more than $52K in the long run.

Re: We Hacked Apple for 3 Months

#84
post #64

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich edit: fixed the number of addresses

They probably don't, but there are weirder cases. Ford was allocated 17.0.0.0/8, Prudential 48.0.0.0/8, USPS 56.0.0.0/8

Re: We Hacked Apple for 3 Months

#85

The takeaway I have from this is really not related to Apple at all. It's that any network of enough complexity run by an organization of enough complexity is actually impossible to secure.

I think it is very much related to Apple. There will be organisations because of their culture or approach to security that will fare better or worse than them.

Re: We Hacked Apple for 3 Months

#86

Bug bounties have always been mispriced. Either the damage estimates for a given bug are wildly over-estimated by risk analysts, or the price paid to find them is based on some kind of stupidity-arbitrage play. I think it's the latter. Consulting firms bill between $1500-$2500/day for senior staff. 2 hackers for 10 days could be the $50k they got paid. Instead, this crew used 5 hackers for say 45 days, or 225 person…

$1500 a day?!?! They are getting ripped off. I had a family member that worked for a large Fortune 500 company tech company. He got to take a look at the invoice for consulting on a project They pay consultants $1500 an HOUR for anything from QA to software engineering. I had another family member who worked in a big 4 accounting firm. These companies regularly pay in excess of $800 an hour for the most ridiculous co…

>$1500 an HOUR

To me, this is the real rip off.

Re: We Hacked Apple for 3 Months

#87
post #34

Earlier quoted context omitted.

The 4 exploits they got paid for don't seem like the biggest ones though. I would expect Apple to pay $500k - $1M for this session in the end, and it would be in the best interest of all parties if this happened. Apple would encourage responsible disclosure (and attract more white-hat bug hunters) this way. The amount of vulnerabilities found is a proof by itself that team work does pay off, if the team is strong. Al…

10 person months would be 10/12ths of a programmer salary i Silicon Valley, which would probably be around $200k

> 10 person months would be 10/12ths of a programmer salary i Silicon Valley, which would probably be around $200k

To my mind, this team deserves a higher salary than typical Silicon Valley programmers for this work.

Re: We Hacked Apple for 3 Months

#88
post #64

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich edit: fixed the number of addresses

This [0] is a really interesting page.

Companies that have an entire /8 block are AT&T, Apple, Ford, Cogent, Prudential Financial, USP and Comcast.

For some reason the US Department of Defense has 13 /8 blocks.

All others belong to regional internet registries (AFRINIC, ARIN, APNIC, LACNIC, RIPE NNC).

I really don't know why anyone other than the registries needs/deserves/got /8 blocks.

[0]: https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addre...

Re: We Hacked Apple for 3 Months

#89

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM)

From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you split a fiber line into 2 by using a crystal prism...

Re: We Hacked Apple for 3 Months

#90
post #60
post #11

Earlier quoted context omitted.

Great, hard-shell/soft-centre. If anyone asks, why you should go to all the effort to secure the software in your internal-network, that's why.

If you are unable to secure your perimeter, what would lead you to believe that you had better security of your interior?

The point is, at a certain scale you _are_ unable to secure your perimeter. Are you surprised that a handful of likely thousands external facing application can be hacked?

Especially, if most of your colleagues never have to bother with security, because they think, they are safe behind the perimeter, how can you expect a secure perimeter? With so many applications, there is bound to be one to have a hole.

The argument is more on the meta-level. Most of the shown ones are implementation issues. Hundreds of people have their hands in here. But being able to gain more privileges because you have managed to compromise a service, that is one of design. And here, only few should have a say in.

Expect failure, limit the impact.

Post reply on HN