Earlier quoted context omitted.
> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?
Yes. I'd say "word to the wise", but I think very few people reading this thread buy pentest time in such large blocks: past a month and you start getting into steep discounts. (This was not several months of full time work, but rather several months of part time work; but I'm stipulating the former condition.)
We Hacked Apple for 3 Months
241–250 of 318 posts
Re: We Hacked Apple for 3 Months
#242I sorted exploits by date, it made a fun short headline summary of how productive they were. Short answer: very. I know it’s hard for senior management to want to really commit to bug bounty programs like this because it feels embarrassing and vulnerable, but posts like this should be sent around the boardroom when discussing — apple rented an AMAZING security team here. Sam, can you disclose what you got paid for al…
End of the post it says 51k so far. I'd expect the price to go up a LOT more, because otherwise the sane (monetary) advice becomes "report some vulnerabilities to apple, and then keep finding them and sell them to third parties".
Re: We Hacked Apple for 3 Months
#243Re: We Hacked Apple for 3 Months
#244The takeaway I have from this is really not related to Apple at all. It's that any network of enough complexity run by an organization of enough complexity is actually impossible to secure.
Re: We Hacked Apple for 3 Months
#245If Apple does not pay these guys several hundred thousand dollars per person, they just recruited the worlds best hackers to work against them. Pay them, and the situation is reversed. Now we see how smart Apple really is.
Re: We Hacked Apple for 3 Months
#246Earlier quoted context omitted.
In that case, do you think that Apple is incompetent for not stumping up $250k or less for an external pentester to find these bugs? Plus maybe $100k more for an internal PM/point of contact for the pentester? Or do you think Apple handled it fine, the expected cost to the business of their security holes was less than $350k and they could just wait for them to come through the bug bounty program or for internal engi…
I think everything is complicated, and that is certainly isn't as simple as "Apple should pay paid $250k to a pentesting firm to find these bugs", because you could keep paying $250k over and over again and keep finding different bugs of comparable severity.
I can easily see the iCloud photo worming one making it's way into mainstream media and causing millions of dollars of reputational damage.
Re: We Hacked Apple for 3 Months
#247Earlier quoted context omitted.
Is that not the "XML External Entity processing to Blind SSRF on Java Management API" SSRF? As that would make sense to match that payment. I really struggle to believe that the $6k is for the maven access one, that's a billion dollar vulnerability.
That’s not a billion dollar vulnerability, you can buy recent copies of this source code for a million dollars.
Re: We Hacked Apple for 3 Months
#248Am I being hyperbolic or is this an absolutely enormous compromise of trust in Apple? XSS in iCloud Email allowing for data exfiltration of emails, pictures, videos??? That's absolutely insane. It just comes to show how vulnerable we all are to exploits like this, especially if you're a notable person of interest.
Software is made by people and people are not perfect. The bigger the project the more moving pieces there are and the more likelihood of flaws. My experience in bug bounty programs has taught me that if you do start a bug bounty program you need to be serious about it and when a report comes in that is actually serious that you need to act on it quickly. And it seems Apple is doing that. What would be more concernin…
Re: We Hacked Apple for 3 Months
#249Re: We Hacked Apple for 3 Months
#250July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.