July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.
We Hacked Apple for 3 Months
131–140 of 318 posts
Re: We Hacked Apple for 3 Months
#132Earlier quoted context omitted.
> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?
A classic false comparison: the four experienced security researchers working for multiple months covers 55 issues, not "that one issue". If we're cherry picking a single one, the associated involvement and timeframe drops dramatically, to something much closer to one or two people, tops, over the course of just a few days, tops. That's something a pentesting team can absolutely achieve for far less than $500,000 ove…
Re: We Hacked Apple for 3 Months
#133Am I being hyperbolic or is this an absolutely enormous compromise of trust in Apple? XSS in iCloud Email allowing for data exfiltration of emails, pictures, videos??? That's absolutely insane. It just comes to show how vulnerable we all are to exploits like this, especially if you're a notable person of interest.
First, practically nobody uses iCloud Email. I'm honestly surprised it still exists. You can confirm with Google searchs the C.W. that iCloud Mail isn't a serious contender among email platforms. Second, you'd be a little naive if you thought Google Mail has never had XSS vulnerabilities.
Re: We Hacked Apple for 3 Months
#134July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.
Something tells me the real money comes from future consulting contracts and that this PR will more than pay for itself. Just like how everyone on HN agrees writing a book isn't a great use of time besides what it allows you to put on your resume. Just because Apple got an amazing bargain doesn't mean the payout for them won't be great as well.
This type of social proof, when executed well, is a boon to one’s career opportunities and credibility for getting future consulting jobs.
If they’re not hired by Apple, they’re going to move to the top of the list for info section recruiters everywhere. Being able to point to this blog post makes them an easy sell relative to some other person with a generic resume.
Re: We Hacked Apple for 3 Months
#135Earlier quoted context omitted.
Something tells me the real money comes from future consulting contracts and that this PR will more than pay for itself. Just like how everyone on HN agrees writing a book isn't a great use of time besides what it allows you to put on your resume. Just because Apple got an amazing bargain doesn't mean the payout for them won't be great as well.
One problem is this puts a downward pressure on others who demand fair compensation for their labor. Not everyone wants to play a long game of "maybe i'll get paid in the future from the 'experience'" This is the professional equivalent of having interns do a bunch of real work and throwing them a pizza party.
Re: We Hacked Apple for 3 Months
#136Earlier quoted context omitted.
Where did you come up with that number? $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. The bugs here are good, but they're not "bug bounty black swan" good; they're what you'd expect from a sitewide pentest. I agree Apple got a great deal here (that's the point of bounties, and anyone who thinks they're a bad deal for strong researchers is... righ…
That second bug they describe would have allowed them to mess with inventory in a warehouse. They could have easily "disappeared" millions of dollars of products. Some of these other bugs would have required apple to disclose PII leak disclosure which could do tens of millions of dollars of damage to their company valuation.
Re: We Hacked Apple for 3 Months
#137Earlier quoted context omitted.
> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?
A classic false comparison: the four experienced security researchers working for multiple months covers 55 issues, not "that one issue". If we're cherry picking a single one, the associated involvement and timeframe drops dramatically, to something much closer to one or two people, tops, over the course of just a few days, tops. That's something a pentesting team can absolutely achieve for far less than $500,000 ove…
Re: We Hacked Apple for 3 Months
#138Earlier quoted context omitted.
Where did you come up with that number? $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. The bugs here are good, but they're not "bug bounty black swan" good; they're what you'd expect from a sitewide pentest. I agree Apple got a great deal here (that's the point of bounties, and anyone who thinks they're a bad deal for strong researchers is... righ…
> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?
(This was not several months of full time work, but rather several months of part time work; but I'm stipulating the former condition.)
Re: We Hacked Apple for 3 Months
#139Earlier quoted context omitted.
Where did you come up with that number? $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. The bugs here are good, but they're not "bug bounty black swan" good; they're what you'd expect from a sitewide pentest. I agree Apple got a great deal here (that's the point of bounties, and anyone who thinks they're a bad deal for strong researchers is... righ…
> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?
Calc based on 3 months, 5 people, 600USD/md rate.
EDIT as I can't reply to tpaceck below: no, those 2000usd/day rates do not exists in projects in size of 300MD like here. In general they do not exist for big projects.
Yes, I agree, you have rates around 1200 in high cost countries, yet as I wrote earlier, you can have similar/the same skill level at 600 usd/md if you're willing to work with guys not from HCC.
As to the skills I'm talking this level: https://research.securitum.com/mutation-xss-via-mathml-mutat...
Re: We Hacked Apple for 3 Months
#140Earlier quoted context omitted.
That's only true if you have no way to be put in (financial) risk by the vulnerability you're not disclosing to Apple.
If you're a security researcher, you probably know how to cover your tracks.