Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

201–210 of 318 posts

Re: We Hacked Apple for 3 Months

#201

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM) From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you…

Google end-to-end encrypts Android backups. Apple does not end-to-end encrypt iCloud backups (on by default on every iOS device), and it serves as an effective cryptographic backdoor to the end-to-end encryption in iMessage by escrowing the keys (as well as the full message content and attachment history) to Apple each night, using Apple keys, which permits Apple (and by extension the FBI, without a warrant) to read every message sent or received by a device in such a default iCloud backup configuration, without ever touching that device.

They were going to fix this, but Apple Legal killed the project while it was underway. This was done at FBI request, according to Reuters' sources.

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

Re: We Hacked Apple for 3 Months

#202
post #173

Earlier quoted context omitted.

PRISM absolutely was about tech companies sharing data with the government. From the PRISM Wikipedia article[1]: > The documents identified several technology companies as participants in the PRISM program, including Microsoft in 2007, Yahoo! in 2008, Google in 2009, Facebook in 2009, Paltalk in 2009, YouTube in 2010, AOL in 2011, Skype in 2011 and Apple in 2012. [1] https://en.wikipedia.org/wiki/PRISM_(surveillance_…

"Participating" covers a broad range of activity when it comes to this program, and would include things like having a portal to provide the legally mandated info that must be returned upon proper presentation of a warrant. Is it really 'sharing data with the government' if the latter shows up with a properly executed warrant for the data?

PRISM data is obtained without a warrant, even for USians whose data is supposed to be protected by a warrant, because of a special secret interpretation of the FISA Amendments Act (FAA) Section 702.

It's warrantless, and the court that decides whether or not it's legal is itself classified and unaccountable and almost never denies surveillance.

This abuse was cited by Ed Snowden as one of the reasons he came forward. It's a public law, but a secret interpretation by a secret court that cannot be challenged by the people to which it applies.

It's not inaccurate to describe it as a military coup, given that it allows the US intelligence community to surveil everyone in the legislature and judiciary.

Re: We Hacked Apple for 3 Months

#203
post #4

I sorted exploits by date, it made a fun short headline summary of how productive they were. Short answer: very. I know it’s hard for senior management to want to really commit to bug bounty programs like this because it feels embarrassing and vulnerable, but posts like this should be sent around the boardroom when discussing — apple rented an AMAZING security team here. Sam, can you disclose what you got paid for al…

End of the post it says 51k so far. I'd expect the price to go up a LOT more, because otherwise the sane (monetary) advice becomes "report some vulnerabilities to apple, and then keep finding them and sell them to third parties".

Yeah, that is only for 4 vulnerabilities out of 55. And 3 of them were only "High." They still have 10 (!!) more critical vulnerabilities they may receive payment on.

Also, they state in the article: "However, it appears that Apple does payments in batches and will likely pay for more of the issues in the following months."

Re: We Hacked Apple for 3 Months

#204
post #99

Earlier quoted context omitted.

If you're a security researcher, you probably know how to cover your tracks.

Where do security researchers sell their investigation on the black market? Links?

any company that builds software for government tracking like NSO Group will happily pay, and have very deep pockets

Re: We Hacked Apple for 3 Months

#205

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

Not just saved Apple, but Apple users too. Wasn’t the “fappening” rooted in hacked iCloud accounts with weak credentials? Imagine what juicy political targets are out there using iPhones syncing with iCloud.

Re: We Hacked Apple for 3 Months

#206
post #205

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

Not just saved Apple, but Apple users too. Wasn’t the “fappening” rooted in hacked iCloud accounts with weak credentials? Imagine what juicy political targets are out there using iPhones syncing with iCloud.

iCloud wasn't cracked. They used social engineering to gain access to the accounts.

Re: We Hacked Apple for 3 Months

#207
post #99

Earlier quoted context omitted.

If you're a security researcher, you probably know how to cover your tracks.

Do you? The skills involved in VR and exploit dev don't necessarily mean you're good at opsec.

True, plus "opsec life sucks" so most of us don't do it.

Re: We Hacked Apple for 3 Months

#208

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

Apple has a trillion because they found a way to exploit the gullible and greed. I am surprised they paid at all.

Re: We Hacked Apple for 3 Months

#209
post #99

Earlier quoted context omitted.

If you're a security researcher, you probably know how to cover your tracks.

Where do security researchers sell their investigation on the black market? Links?

The following companies buy 0-days. Each has a slightly different business model:

Zerodium - http://zerodium.com/ Azimuth Security - https://www.azimuthsecurity.com/ NSO Group - https://www.nsogroup.com/ ZDI - https://www.zerodayinitiative.com/ SSD - https://ssd-disclosure.com/

Re: We Hacked Apple for 3 Months

#210

Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?

I wonder how many agents they pissed by blocking their access through exposing the holes...
Post reply on HN