Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

231–240 of 318 posts

Re: We Hacked Apple for 3 Months

#231

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

How is North Korea going to recruit top cybersecurity specialists?

It's safer not to underestimate them. Every country has smart, competent people in it, no matter how poor or how oppressive their government. A cybersecurity / black hat program is much cheaper than nuclear or ballistic missile programs; and mostly just a matter of human resources and education. And North Korea can set up very strong rewards and incentives for those who do well. Put their whole family up in Pyongyang luxury apartments, etc.

They aren't competing with FAANG salaries, except maybe for a few outside experts that they might bring in to kick off a program.

Re: We Hacked Apple for 3 Months

#232

Earlier quoted context omitted.

Apple paid with public exposure. Anything Apple is a story of interest, which has a value especially in security circles where half the business is a pure PR exercise. I’ve spent time in my career with a “big gorilla” employer whose business is very visible within its community. Companies will “pay” a lot to say “We solved FooCorp’s problems with ” or “FooCorp bought our ” Lazy buyers assume that their peers have the…

While it's a great marketing and reputation building tool, it's still pretty poor to pay people in exposure; they could have taken each and every one of these exploits to the black market instead and they probably would have earned a lot more money.

Your assuming the security professionals in question have a desire to commit a felony.

Re: We Hacked Apple for 3 Months

#233

I think what might not be immediately obvious to people outside of the bug bounty scene is that Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes represent some of the best bug bounty hunters out there which is definitely one of the reasons they absolutely pwnd Apple here. I would be genuinely shocked if Apple doesn't end up paying out much more for all the bugs found. Frankly, it would be gen…

"Within the article I'd mentioned that Apple had not yet paid for all of the vulnerabilities. Right after publishing it, they went ahead and paid for 28 more of the issues making the running total $288,500" https://twitter.com/samwcyo/status/1314310787243167744

Re: We Hacked Apple for 3 Months

#235

Earlier quoted context omitted.

It's a country of over 50 million people, all of whom are beholden to their government. They have all the top cybersecurity specialists they could ever need.

The population of North Korea is only 25M and 43% of them are malnourished and only a small percentage have access to the internet. https://globalnews.ca/news/5029484/north-korea-malnutrition-... Number of security researchers isn't a function of population size it is a function of population size * fraction with propensity to show requisite skill * fraction who go to work in the profession. Shockingly adding million…

It's also one of nine nuclear powers and one of ten to have developed space launch capability. It also scores near the top of the international math olympiad regularly. What makes you certain North Korea hasn't similarly invested in developing security researchers?

Re: We Hacked Apple for 3 Months

#236

I think what might not be immediately obvious to people outside of the bug bounty scene is that Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes represent some of the best bug bounty hunters out there which is definitely one of the reasons they absolutely pwnd Apple here. I would be genuinely shocked if Apple doesn't end up paying out much more for all the bugs found. Frankly, it would be gen…

I’ve interacted with some of them directly when I worked on a bounty program. Definitely some of the best in the business (and actually pleasant to work with).

Re: We Hacked Apple for 3 Months

#237
post #233

I think what might not be immediately obvious to people outside of the bug bounty scene is that Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes represent some of the best bug bounty hunters out there which is definitely one of the reasons they absolutely pwnd Apple here. I would be genuinely shocked if Apple doesn't end up paying out much more for all the bugs found. Frankly, it would be gen…

"Within the article I'd mentioned that Apple had not yet paid for all of the vulnerabilities. Right after publishing it, they went ahead and paid for 28 more of the issues making the running total $288,500" https://twitter.com/samwcyo/status/1314310787243167744

Even if they would pay a full $5.5 million, at 100k per issue, it seems reasonable for the breadth of the findings and potential losses prevented. The warehouse access alone could cause far more damage, while some of the smaller vulnerabilities are clearly not worth that much.

EDIT: see this comment thread for more info on the economics by people who know what they're talking about: https://news.ycombinator.com/item?id=24719656

Re: We Hacked Apple for 3 Months

#238
I wonder how much XSS and others are automatizable.

Beating markup escaping for example. A program may be able to infer the transformation used by comparing input and rendition, then confirm when JS execution is achieved.

Re: We Hacked Apple for 3 Months

#239
post #235

Earlier quoted context omitted.

The population of North Korea is only 25M and 43% of them are malnourished and only a small percentage have access to the internet. https://globalnews.ca/news/5029484/north-korea-malnutrition-... Number of security researchers isn't a function of population size it is a function of population size * fraction with propensity to show requisite skill * fraction who go to work in the profession. Shockingly adding million…

It's also one of nine nuclear powers and one of ten to have developed space launch capability. It also scores near the top of the international math olympiad regularly. What makes you certain North Korea hasn't similarly invested in developing security researchers?

Apples net income is bigger than their GDP and most of their people as impoverished, malnourished and poorly educated.

The upper caste from which all their "talent" is drawn is a small fraction of its total population mostly composed of the descendants of the lower class peasants and workers who supported the rise of the current regime. They supported not an establishment of such a system but rather an inversion of the prior order. It's an impoverished field from which little of value grows. To be clear there is nothing inferior about North Koreans by nature it is that the regime wastes the value that it does get.

Einsteins are in theory as apt to be born from the less privileged classes but there is only a 50 50 chance of getting enough food to be healthy let alone a chance at intellectual development.

Re: We Hacked Apple for 3 Months

#240
post #97

Earlier quoted context omitted.

I think that saying that Apple is especially bad at security would be wrong. But apple claiming they are the only ones who can protect users might be going a bit far....

Does Apple make this claim?

Well they claim that no one else can run a AppStore on iOS, because if someone else did it it would be a big security vulnerability.
Post reply on HN