Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

121–130 of 318 posts

Re: We Hacked Apple for 3 Months

#121

"As of now, October 4th, we have received four payments totaling $51,500" What a joke. That's an hourly rate of $20 (assuming 5 researchers working for 3 months). Just enough to buy a MacBook to do the research in the first place.

In the article he says they invested "a few hundred hours"... I take that to be around 350 hours - $147/hr... still not a lot for speculative research

Re: We Hacked Apple for 3 Months

#122

Earlier quoted context omitted.

Where did you come up with that number? $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. The bugs here are good, but they're not "bug bounty black swan" good; they're what you'd expect from a sitewide pentest. I agree Apple got a great deal here (that's the point of bounties, and anyone who thinks they're a bad deal for strong researchers is... righ…

> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?

A classic false comparison: the four experienced security researchers working for multiple months covers 55 issues, not "that one issue".

If we're cherry picking a single one, the associated involvement and timeframe drops dramatically, to something much closer to one or two people, tops, over the course of just a few days, tops.

That's something a pentesting team can absolutely achieve for far less than $500,000 over the course of a few days, too.

Re: We Hacked Apple for 3 Months

#123
post #64

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich edit: fixed the number of addresses

They don’t, they just got in early.

Re: We Hacked Apple for 3 Months

#124
post #58

I once came up with a silly way of hijacking facebook accounts that were registered with @hotmail.com. I told both facebook and microsoft about this, never got even a thank you. I know that are some people who make a living out of bug bounty, but I felt very discouraged back then (I was still in college) and never bothered to try again.

Write about it! I’m sure somebody would appreciate reading it.

Re: We Hacked Apple for 3 Months

#125
post #97

Earlier quoted context omitted.

Does Apple make this claim?

No. The only people who make this claim are Apple critics who put words in Apple's mouth to justify whatever clickbait blog post they're putting out this week to pad their resumes and harvest echo chamber thumbs. But as we know from politics, if you tell a lie enough times it becomes the truth.

"I'm a Mac

And I'm a P----Error"-Apple ad year 200x

And as you mentioned, like politics, you can deny it and fanatics will believe you..

Re: We Hacked Apple for 3 Months

#126
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

If they really wanted money, they would have gone in a different direction.

With their abilities, they could still go in that direction.

Re: We Hacked Apple for 3 Months

#127
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

The thing is not all RCEs are the same. Apple paid the right amount here.

Re: We Hacked Apple for 3 Months

#128
post #97

Earlier quoted context omitted.

I think that saying that Apple is especially bad at security would be wrong. But apple claiming they are the only ones who can protect users might be going a bit far....

Does Apple make this claim?

Yes, this was their TV Advertising for a decade.

I don't watch TV much, but they seemed to have pivoted to the word "privacy"

Re: We Hacked Apple for 3 Months

#129
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

Off-by-one error, the irony! Jokes aside, I agree that the payout seems shockingly low.

Re: We Hacked Apple for 3 Months

#130

Earlier quoted context omitted.

No. The only people who make this claim are Apple critics who put words in Apple's mouth to justify whatever clickbait blog post they're putting out this week to pad their resumes and harvest echo chamber thumbs. But as we know from politics, if you tell a lie enough times it becomes the truth.

"I'm a Mac And I'm a P----Error"-Apple ad year 200x And as you mentioned, like politics, you can deny it and fanatics will believe you..

Apple making fun of BSOD is not what the parent comment posited. Let me recap for you: "the only ones who can protect users"
Post reply on HN