Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

141–150 of 318 posts

Re: We Hacked Apple for 3 Months

#141
post #137

Earlier quoted context omitted.

A classic false comparison: the four experienced security researchers working for multiple months covers 55 issues, not "that one issue". If we're cherry picking a single one, the associated involvement and timeframe drops dramatically, to something much closer to one or two people, tops, over the course of just a few days, tops. That's something a pentesting team can absolutely achieve for far less than $500,000 ove…

There's really 2 options here. One, Apple doesn't employ a pen-testing team currently, which would be nuts, or, two, the pen-testing team couldn't find these bugs, or they'd already be found.

Apple has product security teams, in infra security team that covers a lot of this web attack surface, a large red team, researchers, and employs 3rd party firms to do sitewide tests.

Apple is also huge, and no huge company avoids vulnerabilities; staff as ambitiously as you want, but any disjoint group of competent testers attacking a new target is going to find a disjoint set of bugs.

Re: We Hacked Apple for 3 Months

#143
post #139

Earlier quoted context omitted.

> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?

Yes, because it is worth in pentesting services 180k USD, no more no less. I mean, you can pay around 360k in London or SV rates and 180k in European for _similar_ skills people. Calc based on 3 months, 5 people, 600USD/md rate. EDIT as I can't reply to tpaceck below: no, those 2000usd/day rates do not exists in projects in size of 300MD like here. In general they do not exist for big projects. Yes, I agree, you have…

If "md" means "billable day", a $600 billable day is extremely low for this kind of work; that's closer to what people pay for network pentesting. $1500-$2000 is closer to the market (before discount, assuming senior but not principal level delivery).

Re: We Hacked Apple for 3 Months

#144

Earlier quoted context omitted.

No. The only people who make this claim are Apple critics who put words in Apple's mouth to justify whatever clickbait blog post they're putting out this week to pad their resumes and harvest echo chamber thumbs. But as we know from politics, if you tell a lie enough times it becomes the truth.

"I'm a Mac And I'm a P----Error"-Apple ad year 200x And as you mentioned, like politics, you can deny it and fanatics will believe you..

Those ads aired so long ago that they referred to Windows Vista, they hardly seem relevant

Re: We Hacked Apple for 3 Months

#145

Earlier quoted context omitted.

A classic false comparison: the four experienced security researchers working for multiple months covers 55 issues, not "that one issue". If we're cherry picking a single one, the associated involvement and timeframe drops dramatically, to something much closer to one or two people, tops, over the course of just a few days, tops. That's something a pentesting team can absolutely achieve for far less than $500,000 ove…

I’m unsure what your point is? I see dozens of different issues listed in the post, on different endpoints, all of which presumably took time to find. When they said they had a team of multiple people work for months on this, I am unsure why you think they haven’t spent their time as efficiently as “a pentesting team”. Actually, I’ll be stronger: looking through the list of things they discovered, it seems like they…

A real team would have certainly cost much more than what they’ve currently been paid.

Yes, but that's a shared premise in this subthread already.

Re: We Hacked Apple for 3 Months

#146

Earlier quoted context omitted.

Something tells me the real money comes from future consulting contracts and that this PR will more than pay for itself. Just like how everyone on HN agrees writing a book isn't a great use of time besides what it allows you to put on your resume. Just because Apple got an amazing bargain doesn't mean the payout for them won't be great as well.

One problem is this puts a downward pressure on others who demand fair compensation for their labor. Not everyone wants to play a long game of "maybe i'll get paid in the future from the 'experience'" This is the professional equivalent of having interns do a bunch of real work and throwing them a pizza party.

Kind of a similar dilemma to strikebreaking

Re: We Hacked Apple for 3 Months

#147

Earlier quoted context omitted.

A classic false comparison: the four experienced security researchers working for multiple months covers 55 issues, not "that one issue". If we're cherry picking a single one, the associated involvement and timeframe drops dramatically, to something much closer to one or two people, tops, over the course of just a few days, tops. That's something a pentesting team can absolutely achieve for far less than $500,000 ove…

I’m unsure what your point is? I see dozens of different issues listed in the post, on different endpoints, all of which presumably took time to find. When they said they had a team of multiple people work for months on this, I am unsure why you think they haven’t spent their time as efficiently as “a pentesting team”. Actually, I’ll be stronger: looking through the list of things they discovered, it seems like they…

Issue count != time spent. I found about a dozen issues in a day once. And once, it took me three days to find one.

Always found at least a medium severity issue though.

Big engagements were typically a week, max. Usually one day of kickoff / getting “in the zone” for a project, three or so days of intensive testing, then the final day is usually writing reports (ugh, reports) all day.

Re: We Hacked Apple for 3 Months

#148
This is a big win for Apple because in my experience most internal security teams are BU specific and never get to throw a wider net. Most security engineers probably realize that there are many gaping holes around the company but they never have the time or bandwidth to go broad and find issues in areas outside their BU. Ultimately, this kind of bug hunting, though lucrative for bug bounty people, does not realize true gains for the company because you are doing bug whack-a-mole all the time instead of trying to fix problems systemically. The joke at a big company I use to work was that its easier to pay thousands in bounty then trying to fix systemic issues because fixing those issues would be more costly. Not saying that this is the right mentality but leaders try to do cost benefit analysis and a bad bug is mostly just a bad PR day without any loss of value to the shareholders.

Re: We Hacked Apple for 3 Months

#149
post #95

> I had even tried emailing the company who provided the software asking how you were supposed to form these API calls, but they wouldn't respond to my email because I didn't have a subscription to the service. We talk about the ethical responsibility (and common-sense practicality) of companies cooperating with white-hats who have found vulnerabilities in their systems. But how does HN feel about this policy as it a…

As an ISV, why would I have any reason to help anyone who isn't paying me?

Re: We Hacked Apple for 3 Months

#150

Earlier quoted context omitted.

Something tells me the real money comes from future consulting contracts and that this PR will more than pay for itself. Just like how everyone on HN agrees writing a book isn't a great use of time besides what it allows you to put on your resume. Just because Apple got an amazing bargain doesn't mean the payout for them won't be great as well.

One problem is this puts a downward pressure on others who demand fair compensation for their labor. Not everyone wants to play a long game of "maybe i'll get paid in the future from the 'experience'" This is the professional equivalent of having interns do a bunch of real work and throwing them a pizza party.

This is very fair criticism for standard jobs like a regular software developer.

For a role like this, where outsized skill of someone who is and needs to be elite should be rewarded with enormously outsized pay, I think this a good model.

Post reply on HN