Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

241–250 of 318 posts

Re: We Hacked Apple for 3 Months

#241

Earlier quoted context omitted.

> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?

Yes. I'd say "word to the wise", but I think very few people reading this thread buy pentest time in such large blocks: past a month and you start getting into steep discounts. (This was not several months of full time work, but rather several months of part time work; but I'm stipulating the former condition.)

someone is watching schit creek

Re: We Hacked Apple for 3 Months

#242
post #4

I sorted exploits by date, it made a fun short headline summary of how productive they were. Short answer: very. I know it’s hard for senior management to want to really commit to bug bounty programs like this because it feels embarrassing and vulnerable, but posts like this should be sent around the boardroom when discussing — apple rented an AMAZING security team here. Sam, can you disclose what you got paid for al…

End of the post it says 51k so far. I'd expect the price to go up a LOT more, because otherwise the sane (monetary) advice becomes "report some vulnerabilities to apple, and then keep finding them and sell them to third parties".

Yeah I imagine you can make a lot more money selling them to state actors than to apple.

Re: We Hacked Apple for 3 Months

#243
post #99

Earlier quoted context omitted.

If you're a security researcher, you probably know how to cover your tracks.

Yes, but the risk if you’re caught is huge.

not if you're selling them to -your- government. Then you're a patriot but also a rich patriot.

Re: We Hacked Apple for 3 Months

#244

The takeaway I have from this is really not related to Apple at all. It's that any network of enough complexity run by an organization of enough complexity is actually impossible to secure.

It is in that a lot of people rely on apple to secure their data and it's good for them to know they should add an extra layer of encryption for anything critical.

Re: We Hacked Apple for 3 Months

#245

If Apple does not pay these guys several hundred thousand dollars per person, they just recruited the worlds best hackers to work against them. Pay them, and the situation is reversed. Now we see how smart Apple really is.

World's best hacking team? That's highly unlikely. If they were wise though, they saved a few to sell to CIA/NSA/FBI who may be contacting them soon for said exploits thanks to articles like these. I doubt they showed the best cards in their magic deck.

Re: We Hacked Apple for 3 Months

#246

Earlier quoted context omitted.

In that case, do you think that Apple is incompetent for not stumping up $250k or less for an external pentester to find these bugs? Plus maybe $100k more for an internal PM/point of contact for the pentester? Or do you think Apple handled it fine, the expected cost to the business of their security holes was less than $350k and they could just wait for them to come through the bug bounty program or for internal engi…

I think everything is complicated, and that is certainly isn't as simple as "Apple should pay paid $250k to a pentesting firm to find these bugs", because you could keep paying $250k over and over again and keep finding different bugs of comparable severity.

And finding these bugs of comparable severity isn't worth the $250k each time?

I can easily see the iCloud photo worming one making it's way into mainstream media and causing millions of dollars of reputational damage.

Re: We Hacked Apple for 3 Months

#247

Earlier quoted context omitted.

Is that not the "XML External Entity processing to Blind SSRF on Java Management API" SSRF? As that would make sense to match that payment. I really struggle to believe that the $6k is for the maven access one, that's a billion dollar vulnerability.

That’s not a billion dollar vulnerability, you can buy recent copies of this source code for a million dollars.

A million dollars for iOS's source code?

Re: We Hacked Apple for 3 Months

#248
post #69

Am I being hyperbolic or is this an absolutely enormous compromise of trust in Apple? XSS in iCloud Email allowing for data exfiltration of emails, pictures, videos??? That's absolutely insane. It just comes to show how vulnerable we all are to exploits like this, especially if you're a notable person of interest.

Software is made by people and people are not perfect. The bigger the project the more moving pieces there are and the more likelihood of flaws. My experience in bug bounty programs has taught me that if you do start a bug bounty program you need to be serious about it and when a report comes in that is actually serious that you need to act on it quickly. And it seems Apple is doing that. What would be more concernin…

I agree. The bigger lesson here, imo, is that companies need to take security of their tools even if they're only used by a handful of people and not just focus on their front-facing tools. A forum that everyone had access to but that likely didn't get much traffic was used to get access to internal networks. That needs to be taken seriously.

Re: We Hacked Apple for 3 Months

#250
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

Apple hasn't paid them for the largest exploits yet. That $52k will likely blow-up to far more when Apple pays them so their work will end up being much more lucrative. Apple also pays in batches so they'll likely get a few more batches and some of those will be yuuuuuuuge!
Post reply on HN