Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

91–100 of 318 posts

Re: We Hacked Apple for 3 Months

#91

Earlier quoted context omitted.

Apple paid with public exposure. Anything Apple is a story of interest, which has a value especially in security circles where half the business is a pure PR exercise. I’ve spent time in my career with a “big gorilla” employer whose business is very visible within its community. Companies will “pay” a lot to say “We solved FooCorp’s problems with ” or “FooCorp bought our ” Lazy buyers assume that their peers have the…

While it's a great marketing and reputation building tool, it's still pretty poor to pay people in exposure; they could have taken each and every one of these exploits to the black market instead and they probably would have earned a lot more money.

Alternatively, the Apriso exploit alone apparently would have allowed them to create fake manufacturing-level employees with fake payroll going to arbitrary bank-account targets; so an unethical attacker probably could have collected an unbounded amount of money just from that (since it likely wouldn’t have been caught until after the first event; and payroll would happen all at once, paying out to as many different accounts as the attacker wished.)

Re: We Hacked Apple for 3 Months

#92
The most valuable vulnerability they found was some publicly exposed Spring Boot Actuator endpoints (https://docs.spring.io/spring-boot/docs/current/reference/ht...):

  $34,000 - Multiple eSign environments vulnerable to system memory leaks containing secrets and customer data due to public-facing actuator heapdump, env, and trace
I guess it goes to remind you if you are a developer, don't overlook the simple things like not exposing these endpoints in production (literally a line in a config file) or at least making them secured.

And if you are a bug bounty hunter, some of the simplest things can lead to the best ROI. I'm actually surprised something this basic was not already found and reported, but credit goes to their recon efforts for determining where to look.

Re: We Hacked Apple for 3 Months

#93

I really don't understand this whole "whining over how much I got paid for my bug bounty" thing. 1. Nobody is asking you to find exploits in the systems of a company you don't work for. If you want to use your time that way, then fine, but understand that is your own time-management decision. Don't go complaining about how you feel "undervalued". 2. Companies are under no obligation to pay bounties and companies are…

> Don't go complaining about how you feel "undervalued".

That's your interpretation, when I see that kind of complains, I don't see people that complains they feel undervalued, I see people complains that companies undervalue vulnerabilities, which is kind of a big deal.

I don't see anything in that article that make it feel like they believe that Apple undervalue vulnerabilities either, if anything it sound pretty positive for Apple. They answer quickly and fix the issues really really quickly (they said 4 hours for the most critical one).

The amounts may seems low, but they doesn't complains at all about it and even say that Apple may pay them more afterward, thus even if you personally believe theses amounts are low while reading it, may get out of that article believing that they will get paid enough afterward.

> 2. Companies are under no obligation to pay bounties and companies are certainly under no obligation to pay headline grabbing bounties.

Sure they aren't under any obligation, just like Nike is under no obligation to pay more than good wages to make their shoes oversea, thing is, their client may be interested in knowing theses facts and making a decision in relation to theses facts.

They found 55 vulnerabilities... that's 55 instances of negligence in Apple infrastructure. If you believe that's alright, then perfect, but don't complains that people try to make it known so that everyone can make an educated decision.

Personally, that article give me MORE confidence toward Apple.

> Sooner or later its going to end with various attempts at blackmail.

How does bug-bounties allow more blackmail? You can still blackmail with or without bug-bounties. If anything, I believe it reduce blackmail as you can go through the bug bounty program instead and get paid legally. I don't think many security researcher would put that they blackmailed Apple, but they will certainly say they got paid over their bug bounty program.

Re: We Hacked Apple for 3 Months

#94

Earlier quoted context omitted.

If they actually did get paid so little, why did they do it? This seems like a terrible use of their time.

Qualifying people for highly paid info security positions is shockingly broken right now. No one who knows what they are doing cares about credentials you can get from a training program or school, but they also complain constantly about how hard it is to find and hire qualified people. The result is: there is a lot of salary out there for people who can figure out how to get it. Developing exploits that are acknowle…

I work at a company that has an infosec division and I don't know how we got so lucky with the people there. They're seriously legit low level kernel type programmers who seem to be able to reverse engineer anything given enough time and are able to seriously reason about what's going on in security. The types of people who speak at and headline at the largest security conferences, etc. Again, no idea how we got so lucky to have a great crew.

I'm not an infosec person myself. But my experience is that upwards of 80% of the ones I interact with who aren't like the people I mentioned above are just hangers on because they like the group or being associated with "infosec" because it sounds cool or something. Maybe it's because you don't need to be an engineer to regurgitate OWASP vulnerabilities and tell people to use password managers, but perhaps that's enough to, after you look around the room of infosec people, feel like you're an "infosec person." To be clear, that stuff is important, but not anywhere close to sufficient. So a lot of applications for our roles come from these people, who just sit on twitter all day and retweet the Taylor Swift security person, but they're totally not technical and have done nothing of note other than write compliance plans.

My hypothesis is that it's all this noise that makes hiring good infosec people difficult. If I'm hiring a kernel programmer or SRE I seem to get much more signal in my applications, but hire someone for security or infosec and there's too much noise from people like above.

Re: We Hacked Apple for 3 Months

#95
> I had even tried emailing the company who provided the software asking how you were supposed to form these API calls, but they wouldn't respond to my email because I didn't have a subscription to the service.

We talk about the ethical responsibility (and common-sense practicality) of companies cooperating with white-hats who have found vulnerabilities in their systems.

But how does HN feel about this policy as it applies to third-party ISVs contacted for knowledge relevant to a vulnerability exploit?

Should there ideally be a framework in place where the company running the Bug Bounty program puts white-hats in contact with its upstream ISVs’ engineers; or perhaps even treats the white-hat as an employee in terms of eligibility to receive support from the ISV on the Bug Bounty hoster’s tab?

Or, to flip that around, maybe the ISVs themselves should be willing to help the white-hat for ethical/practical reasons as well (for the exploit might, in the end, be as much their problem as it is their customer’s.) But in that case, should there be a some sort of best-practice approach to authenticating that J. Random Hacker who emailed a question to you, is actually a white-hat—e.g. by validating that they’re registered with the bug-bounty program of your client? Or does it not even matter, and you should just answer even a black-hat hacker’s questions about your APIs, since “vulnerability research is vulnerability research and has a long-term result of hardening the ecosystem either way”, and then let the cards fall where they may?

Re: We Hacked Apple for 3 Months

#97

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

I think that saying that Apple is especially bad at security would be wrong. But apple claiming they are the only ones who can protect users might be going a bit far....

Does Apple make this claim?

Re: We Hacked Apple for 3 Months

#98
post #88
post #64

Earlier quoted context omitted.

Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich edit: fixed the number of addresses

This [0] is a really interesting page. Companies that have an entire /8 block are AT&T, Apple, Ford, Cogent, Prudential Financial, USP and Comcast. For some reason the US Department of Defense has 13 /8 blocks. All others belong to regional internet registries (AFRINIC, ARIN, APNIC, LACNIC, RIPE NNC). I really don't know why anyone other than the registries needs/deserves/got /8 blocks. [0]: https://en.wikipedia.org/…

Wow Prudential and Ford (if USP is supposed to be UPS, that too) are the odd ducks. At least the others have the internet as a core competency.

My guess as to the answer of “why” is power and leverage. It’s the same as nations claiming physical land. “Maybe we’ll need it, maybe we won’t. But either way, now it’s ours to decide.” Writing that out, do they own those? Can someone take those back?

Re: We Hacked Apple for 3 Months

#99

Earlier quoted context omitted.

End of the post it says 51k so far. I'd expect the price to go up a LOT more, because otherwise the sane (monetary) advice becomes "report some vulnerabilities to apple, and then keep finding them and sell them to third parties".

That's only true if you have no way to be put in (financial) risk by the vulnerability you're not disclosing to Apple.

If you're a security researcher, you probably know how to cover your tracks.

Re: We Hacked Apple for 3 Months

#100
post #90
post #60

Earlier quoted context omitted.

If you are unable to secure your perimeter, what would lead you to believe that you had better security of your interior?

The point is, at a certain scale you _are_ unable to secure your perimeter. Are you surprised that a handful of likely thousands external facing application can be hacked? Especially, if most of your colleagues never have to bother with security, because they think, they are safe behind the perimeter, how can you expect a secure perimeter? With so many applications, there is bound to be one to have a hole. The argume…

That's certainly one view of things. The other view is taken by the beyondcorp/zero-trust model. But the lesson I take from this article (and my own experience) is that if you allow commercial off-the-shelf and open-source software into your network the end result will always be an insecure mess. If you absolutely must adopt off-the-shelf software the only safe way to do it is to put a proxy in front of it that's completely integrated with your authn/authz systems such that the native protocol of the third-party system is completely hidden and inaccessible.

The Google model is frequently derided on HN as "not invented here" but at least you can say that they aren't getting rooted via some kind of toxic waste like Jive forums.

Post reply on HN