Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

181–190 of 318 posts

Re: We Hacked Apple for 3 Months

#181

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

If one bounty hunter got $100k for a single exploit, these guys should’ve gotten millions...

Re: We Hacked Apple for 3 Months

#182

Earlier quoted context omitted.

> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM) From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you…

PRISM absolutely was about tech companies sharing data with the government. From the PRISM Wikipedia article[1]: > The documents identified several technology companies as participants in the PRISM program, including Microsoft in 2007, Yahoo! in 2008, Google in 2009, Facebook in 2009, Paltalk in 2009, YouTube in 2010, AOL in 2011, Skype in 2011 and Apple in 2012. [1] https://en.wikipedia.org/wiki/PRISM_(surveillance_…

The slides on that page diagree. PRISM was/is a data collection project. The sources came from other projects like the diagrams show. Those dont show anything about cooperation, only collection.

https://en.wikipedia.org/wiki/PRISM_(surveillance_program)#/...

https://en.wikipedia.org/wiki/PRISM_(surveillance_program)#/...

https://en.wikipedia.org/wiki/PRISM_(surveillance_program)#/...

Re: We Hacked Apple for 3 Months

#183
post #64

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich edit: fixed the number of addresses

Because back in the early days you could get one just by asking and they did?

The internet was just a research project to connect some universities, government sites, and a handful of companies. No one realized where it was going.

By the time it was clear the IPv4 address space would be exhausted it was also clear reclaiming those IP blocks (for which there is no legal basis) would merely temporarily delay the exhaustion - likely by a year or two at best.

Re: We Hacked Apple for 3 Months

#184
post #11

Earlier quoted context omitted.

"Our proof of concept for this report was demonstrating we could read and access Apple’s internal maven repository which contained the source code for what appeared to be hundreds of different applications, iOS, and macOS." This itself is massive. How many 0-days could emerge from something like that?!

Great, hard-shell/soft-centre. If anyone asks, why you should go to all the effort to secure the software in your internal-network, that's why.

I work on a giant famous multi-billion dollar company where all the internal stuff is full of permission requirements, training requirements, etc. It is absolutely HORRIBLE to be productive here. Every single kind of information you need to be able to work is hidden behind someone's wall. I often lose entire weeks of productivity just trying to find who owns a certain information or knows which permission I need to request in order to read a link. There was a time I literally had to wait a whole month before the person was on vacation and their manager didn't know how to authorize me into the system. All I needed was a binary file they provided.

Even worse: every team thinks the thing they do is absolutely the most important thing in the world so they hide it even more. They create empires around the information they control and explicitly force you out of it. So instead of just reading their freaking source code or documentation you have to get permission to open a ticket in their system, then you open it, then one person will triage your ticket, another will forward it, another will create an internal Jira about them, a PM will prioritize it, then a dev will gather the information and pass to the Senior Information Proxy employee who will instruct the intern to finally reply it in your ticket. And of course your original message was misunderstood so the thing they gave you is useless. All you needed was access to the damn thing, but they built an empire around it and now you have to fight a war of improductivity.

Re: We Hacked Apple for 3 Months

#185
post #172

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

You seem to be quite prone to making unfounded hyperbolic pronouncements about Apple in several different threads lately. As the responses show, it might be worth toning down the rhetoric and staying true to proven reality for a while concerning this subject.

Hyperbolic? Literally both are backed by factual examples. Did you read the article?

Some companies are horrible to their customers, is there something wrong about posting literal facts and comparing to marketing lies?

Re: We Hacked Apple for 3 Months

#186

Earlier quoted context omitted.

10 person months would be 10/12ths of a programmer salary i Silicon Valley, which would probably be around $200k

> 10 person months would be 10/12ths of a programmer salary i Silicon Valley, which would probably be around $200k To my mind, this team deserves a higher salary than typical Silicon Valley programmers for this work.

Agree; these people are incredibly skilled.

The conclusion is the same: they are underpaid by a factor of approximately 4+

Re: We Hacked Apple for 3 Months

#187

Earlier quoted context omitted.

7,000 unique domains seems insane, what could they possibly need all of those for? Unless that includes subdomains, I guess.

7,000 does seem REALLY high, but I can imagine them needing the TLD for every possible spelling of Apple. Maybe applesucks as well. appl3, 8ppl3 and so on. Anything close to apple. Same goes for icloud, and I anything else. I guess you get to 1k pretty quick just covering typo squatters. They must have a team of people just to manage domain names!

It's probably semi-random domain names. Like "auth-8e3fe.icloud.apple.com" type stuff.

Re: We Hacked Apple for 3 Months

#188
post #172

Earlier quoted context omitted.

You seem to be quite prone to making unfounded hyperbolic pronouncements about Apple in several different threads lately. As the responses show, it might be worth toning down the rhetoric and staying true to proven reality for a while concerning this subject.

Hyperbolic? Literally both are backed by factual examples. Did you read the article? Some companies are horrible to their customers, is there something wrong about posting literal facts and comparing to marketing lies?

Apple is far from perfect, but often in the context of its market peers being much further from perfect. In that context, saying that their considerable security efforts and accomplishments amount to nothing but marketing lies is more than a little uncharitable.

Re: We Hacked Apple for 3 Months

#189
post #99

Earlier quoted context omitted.

That's only true if you have no way to be put in (financial) risk by the vulnerability you're not disclosing to Apple.

If you're a security researcher, you probably know how to cover your tracks.

Do you? The skills involved in VR and exploit dev don't necessarily mean you're good at opsec.

Re: We Hacked Apple for 3 Months

#190

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

7,000 unique domains seems insane, what could they possibly need all of those for? Unless that includes subdomains, I guess.

That's probably right. A quick internet search shows up domains like applecoronavirus.com and similar, as well as this court case [1] where they acquired a bunch of ipod related names.

I suspect they are only parking those names after recovering them or buying them preemptively. Domain names are cheap, so why not. I don't think that's any argument for the possession of the /8 though.

I remember Google had ownership of duck.com until recently, so they probably participate in the wholesale acquisition of random domains as well [2].

[1]: https://techcrunch.com/2010/01/07/apple-domain-names/ [2]: https://www.theverge.com/2018/12/12/18137369/duckduckgo-duck...

Post reply on HN