July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.
Everybody wins here. It's a bargain for Apple, because their ledgers deal with numbers that require the -illions suffixes, but it's ALSO $10k per person, which even after taxes is still a lot of money on top of their regular salary for anyone with bills to pay.
We Hacked Apple for 3 Months
251–260 of 318 posts
Re: We Hacked Apple for 3 Months
#252The most valuable vulnerability they found was some publicly exposed Spring Boot Actuator endpoints ( https://docs.spring.io/spring-boot/docs/current/reference/ht... ): $34,000 - Multiple eSign environments vulnerable to system memory leaks containing secrets and customer data due to public-facing actuator heapdump, env, and trace I guess it goes to remind you if you are a developer, don't overlook the simple things…
Re: We Hacked Apple for 3 Months
#253We need better techology, that's one thing that's certain. The current technology we have has too many security holes.
Re: We Hacked Apple for 3 Months
#254Re: We Hacked Apple for 3 Months
#255Earlier quoted context omitted.
Not just saved Apple, but Apple users too. Wasn’t the “fappening” rooted in hacked iCloud accounts with weak credentials? Imagine what juicy political targets are out there using iPhones syncing with iCloud.
iCloud wasn't cracked. They used social engineering to gain access to the accounts.
Re: We Hacked Apple for 3 Months
#256Earlier quoted context omitted.
It's a country of over 50 million people, all of whom are beholden to their government. They have all the top cybersecurity specialists they could ever need.
The population of North Korea is only 25M and 43% of them are malnourished and only a small percentage have access to the internet. https://globalnews.ca/news/5029484/north-korea-malnutrition-... Number of security researchers isn't a function of population size it is a function of population size * fraction with propensity to show requisite skill * fraction who go to work in the profession. Shockingly adding million…
By your same logic, they would not have any Olympic competitors, let alone medalists.
Re: We Hacked Apple for 3 Months
#257Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?
Re: We Hacked Apple for 3 Months
#258Earlier quoted context omitted.
its probably just a case of they emailed support@ without a support contract, and didn't get very far. I don't think that's very indicitive of much, especially for "enterprise software".
Sure, but there's no reason for something like API documentation to require emailing support@. Let me cite a specific recent example: I was tasked with building an application that integrated document e-signatures. The spec called for Docusign specifically, so I looked at their documentation. What I could find of it was written unclearly and much of it was hidden behind a developer account login. Getting a developer…
Re: We Hacked Apple for 3 Months
#259Earlier quoted context omitted.
Write about it! I’m sure somebody would appreciate reading it.
well, there was a time here in Brazil when MSN was very popular (@hotmail.com), all my friends used it as the default messenger. Later came Facebook and people created their account using the @hotmail.com and starting to left MSN, since facebook had a messenger. One day I received an email from Microsoft saying that they were disabling MSN (I'm telling this from memory, forgive me if I'm saying anything super wrong).…
Re: We Hacked Apple for 3 Months
#260Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…
Late reply: They just paid for 28 more issues, running total is now $288,500. https://twitter.com/samwcyo/status/1314310787243167744
Well worth it for Apple and a decent payday for 3 months of spelunking.