Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

171–180 of 318 posts

Re: We Hacked Apple for 3 Months

#171

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM) From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you…

PRISM absolutely was about tech companies sharing data with the government.

From the PRISM Wikipedia article[1]:

> The documents identified several technology companies as participants in the PRISM program, including Microsoft in 2007, Yahoo! in 2008, Google in 2009, Facebook in 2009, Paltalk in 2009, YouTube in 2010, AOL in 2011, Skype in 2011 and Apple in 2012.

[1] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)#M...

Re: We Hacked Apple for 3 Months

#172

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

You seem to be quite prone to making unfounded hyperbolic pronouncements about Apple in several different threads lately. As the responses show, it might be worth toning down the rhetoric and staying true to proven reality for a while concerning this subject.

Re: We Hacked Apple for 3 Months

#173

Earlier quoted context omitted.

> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM) From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you…

PRISM absolutely was about tech companies sharing data with the government. From the PRISM Wikipedia article[1]: > The documents identified several technology companies as participants in the PRISM program, including Microsoft in 2007, Yahoo! in 2008, Google in 2009, Facebook in 2009, Paltalk in 2009, YouTube in 2010, AOL in 2011, Skype in 2011 and Apple in 2012. [1] https://en.wikipedia.org/wiki/PRISM_(surveillance_…

"Participating" covers a broad range of activity when it comes to this program, and would include things like having a portal to provide the legally mandated info that must be returned upon proper presentation of a warrant. Is it really 'sharing data with the government' if the latter shows up with a properly executed warrant for the data?

Re: We Hacked Apple for 3 Months

#174
post #73
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

You are making the false assumption that these people are working fulltime, which they are not. At least 3 of them have full time jobs.

As full time job might not mean 40 hours per week during the pandemic. This is briefly mentioned in the article.

“ This was originally meant to be a side project that we'd work on every once in a while, but with all of the extra free time with the pandemic we each ended up putting a few hundred hours into it.”

Re: We Hacked Apple for 3 Months

#175
post #4

I sorted exploits by date, it made a fun short headline summary of how productive they were. Short answer: very. I know it’s hard for senior management to want to really commit to bug bounty programs like this because it feels embarrassing and vulnerable, but posts like this should be sent around the boardroom when discussing — apple rented an AMAZING security team here. Sam, can you disclose what you got paid for al…

It seems like this cooperative approach was very effective. I assume rubber duck debugging and having multiple minds attacking the problem from from multiple directions greatly improves the efficiency.

Re: We Hacked Apple for 3 Months

#176

Earlier quoted context omitted.

As an ISV, why would I have any reason to help anyone who isn't paying me?

If you don't have a way to share documentation for your API with anyone for a cost of about $0.00, then you're signaling that your development process is a bit broken.

its probably just a case of they emailed support@ without a support contract, and didn't get very far. I don't think that's very indicitive of much, especially for "enterprise software".

Re: We Hacked Apple for 3 Months

#177

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM) From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you…

You're thinking of WINDSTOP programs like MUSCULAR, not PRISM.

Re: We Hacked Apple for 3 Months

#178

Earlier quoted context omitted.

> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?

Yes. I'd say "word to the wise", but I think very few people reading this thread buy pentest time in such large blocks: past a month and you start getting into steep discounts. (This was not several months of full time work, but rather several months of part time work; but I'm stipulating the former condition.)

Your comment got me thinking, Apple probably was already buying large blocks of pentest time, and the comments in the thread make it seem like these were obvious flaws. Is that right? If we assume Apple already had a contracted pentest firm, can you speculate why didn't they find these flaws?

Re: We Hacked Apple for 3 Months

#179
post #36

I’ve always been interested in this round of thing, but have no idea how or where to get started

Check out ctf competitions. They have a number of "problems" of varying difficulties. Depending on the competition, the easier ones start out with simple stack buffer overflows, SQL injection, etc., and many competitors will post writeups after the competition.

Ctftime.org is a good place for a list of competitions (note: some are more difficult, in that an unexperienced person won't be able to do the intro problems). I'd recommend checking out picoctf as a good intro one.

Re: We Hacked Apple for 3 Months

#180
post #178

Earlier quoted context omitted.

Yes. I'd say "word to the wise", but I think very few people reading this thread buy pentest time in such large blocks: past a month and you start getting into steep discounts. (This was not several months of full time work, but rather several months of part time work; but I'm stipulating the former condition.)

Your comment got me thinking, Apple probably was already buying large blocks of pentest time, and the comments in the thread make it seem like these were obvious flaws. Is that right? If we assume Apple already had a contracted pentest firm, can you speculate why didn't they find these flaws?

I don't know what "obvious flaws" means. I know from like a dozen years of consulting experience, and from 10 years of vuln research prior to that, that putting a different set of eyes on a target tends to get you a different set of bugs. Finding vulnerabilities is as much an art as a science, which makes sense when you think about what hunting for software vulnerabilities actually entails. If you could do it deterministically, you'd be saying something big about computer science.

I think we're on firmer ground saying that there are ways of delivering software that foreclose on "obvious bugs". But when we talk about fundamentally changing the way we deliver software --- in secure-by-default development environments, on secure-by-default deployment platforms, with security as a primary functional goal prioritized over time-to-market --- we're actually into real money now, not just another $250k on pentesters.

Post reply on HN