Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

161–170 of 318 posts

Re: We Hacked Apple for 3 Months

#161

"As of now, October 4th, we have received four payments totaling $51,500" What a joke. That's an hourly rate of $20 (assuming 5 researchers working for 3 months). Just enough to buy a MacBook to do the research in the first place.

In the article he says they invested "a few hundred hours"... I take that to be around 350 hours - $147/hr... still not a lot for speculative research

you missed a word: "we each ended up putting a few hundred hours into it."

So the 20-30$ per hour figure is closer, before taxes, with zero benefits like health, dental or pension plans.

They themselves say: bounty hunting is not a job

Re: We Hacked Apple for 3 Months

#162
post #95

> I had even tried emailing the company who provided the software asking how you were supposed to form these API calls, but they wouldn't respond to my email because I didn't have a subscription to the service. We talk about the ethical responsibility (and common-sense practicality) of companies cooperating with white-hats who have found vulnerabilities in their systems. But how does HN feel about this policy as it a…

As an ISV, why would I have any reason to help anyone who isn't paying me?

If you don't have a way to share documentation for your API with anyone for a cost of about $0.00, then you're signaling that your development process is a bit broken.

Re: We Hacked Apple for 3 Months

#163
Great write-up! I love these kind of posts. It's like solving a puzzle, picking a very complicated lock, or like being water trying to get into a supposedly water-tight box. This beats any crime novel.

The technical speak was very understandable and none of the technical terms seemed really foreign. Again, good job, Mr. Author.

Re: We Hacked Apple for 3 Months

#164
post #95

> I had even tried emailing the company who provided the software asking how you were supposed to form these API calls, but they wouldn't respond to my email because I didn't have a subscription to the service. We talk about the ethical responsibility (and common-sense practicality) of companies cooperating with white-hats who have found vulnerabilities in their systems. But how does HN feel about this policy as it a…

As an ISV, why would I have any reason to help anyone who isn't paying me?

Thanks, great point. At first I was thinking that it was the ISV playing "security by obscurity" but it's probably much more simple than that: labor costs!

Re: We Hacked Apple for 3 Months

#165
post #97

Earlier quoted context omitted.

Does Apple make this claim?

No. The only people who make this claim are Apple critics who put words in Apple's mouth to justify whatever clickbait blog post they're putting out this week to pad their resumes and harvest echo chamber thumbs. But as we know from politics, if you tell a lie enough times it becomes the truth.

https://www.theatlantic.com/technology/archive/2019/01/apple...

Re: We Hacked Apple for 3 Months

#166

Earlier quoted context omitted.

Oh totally, as I mentioned above I am not an infosec person and I hope I didn't imply otherwise (I did mention this specifically above). The above is just my impression from the outside but as someone who talks to and works with a lot of security/RE/infosec people.

That was just a really snarky way of saying that RE people and people who pay attention to OWASP are not comparables. Sorry, I should have just been direct about it.

Oh yeah, fair enough, point taken. :)

Re: We Hacked Apple for 3 Months

#167
post #56

Earlier quoted context omitted.

It is impossible to quantify what is a good use of their time without knowing them. Also not everyone does things in the pursuit of money. I sell eggs and could easily ask 5$ a dozen with the demand I have. Instead I only ask 4$ and have lots of clients I only charge 2$ and some I just give eggs to when I have extra. These are people with no money or means. I don’t expect to ever get anything from these people but ev…

> I sell eggs Is this like an actual side business you run? Can you tell us more?

Well after covid started and the stores ran out of a lot of food I decided to get some chickens again. I have had a maximum of 6 in the past but decided to increase the flock since 6 birds is pretty much the same effort as 30 birds. I now have 33 in total and at this point in their life get one egg a day. They average something like 300+ eggs a year. I have sold enough to buy an automatic egg washer and now mainly worry about selling enough to cover feed costs. I do it because chickens are very therapeutic and I find them relaxing to be around. I have young kids so they are also learning the value of food and can eat all the eggs they want. So I wouldn’t really call it much of a business it is more of a hobby that I reap little reward other then my eggs and to help out a few others near me. I think if I ramped up to a few hundred birds I could make a bit of money but at the small size it keeps me from getting overwhelmed with too much work and I can just share my harvest with those around me. I have learned that making money is nice but I also get a great deal reward from helping others in need.

Re: We Hacked Apple for 3 Months

#168

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

I think that saying that Apple is especially bad at security would be wrong. But apple claiming they are the only ones who can protect users might be going a bit far....

> I think that saying that Apple is especially bad at security would be wrong.

iOS vulnerabilities cost less than Android vulnerabilities because there are just so many iOS exploits on the market.

Re: We Hacked Apple for 3 Months

#169
post #4

I sorted exploits by date, it made a fun short headline summary of how productive they were. Short answer: very. I know it’s hard for senior management to want to really commit to bug bounty programs like this because it feels embarrassing and vulnerable, but posts like this should be sent around the boardroom when discussing — apple rented an AMAZING security team here. Sam, can you disclose what you got paid for al…

End of the post it says 51k so far. I'd expect the price to go up a LOT more, because otherwise the sane (monetary) advice becomes "report some vulnerabilities to apple, and then keep finding them and sell them to third parties".

There are defense contractors that do exactly this. Governments pay more than Apple will ever pay, so if you are in it for the money (and don't care about the ethical repercussions), selling the discovered exploits to governments is the way to go.

Re: We Hacked Apple for 3 Months

#170
post #97

Earlier quoted context omitted.

Does Apple make this claim?

No. The only people who make this claim are Apple critics who put words in Apple's mouth to justify whatever clickbait blog post they're putting out this week to pad their resumes and harvest echo chamber thumbs. But as we know from politics, if you tell a lie enough times it becomes the truth.

https://www.cnn.com/2020/09/03/tech/apple-iphone-privacy-ad/...
Post reply on HN