Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

261–270 of 318 posts

Re: We Hacked Apple for 3 Months

#261

Earlier quoted context omitted.

That second bug they describe would have allowed them to mess with inventory in a warehouse. They could have easily "disappeared" millions of dollars of products. Some of these other bugs would have required apple to disclose PII leak disclosure which could do tens of millions of dollars of damage to their company valuation.

You'll find, if you talk to people that do this work professionally, that bugs where you can tell yourself a story about the millions of dollars you could make are not uncommon, and that the rack rate for generating those bugs doesn't scale with their hypothetical value. I've done multiple projects for FIX gateways at exchanges. Those are fun stories to tell yourself! But those projects weren't even especially lucrat…

> where you can tell yourself a story about the millions of dollars you could make

It’s not about the dollars you could make. That’s probably pretty hard to get away with.

But the damage you can do? That’s a whole different thing.

Re: We Hacked Apple for 3 Months

#262

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

> China or North Korea could easily allocate a much larger team to something like this

Chances are they already did, and are just sitting on the vulnerabilities.

Re: We Hacked Apple for 3 Months

#263

Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?

As an iPhone user (and Mac for work), of late I've often wondered whether Apple is really just all about the pretty looking things and overhyped launches and marketing campaigns, giving specific (usually trademarked) names to features that have been common place on other platforms for years. And a large portion of their user-base also being their staunch fans. Do they just glue things together under the hood this way…

> Do they just glue things together

In my experience all enterprises I have experience with do this. There’s just something about the whole process that makes everyone worry about security later.

Re: We Hacked Apple for 3 Months

#264

Earlier quoted context omitted.

It's a country of over 50 million people, all of whom are beholden to their government. They have all the top cybersecurity specialists they could ever need.

The population of North Korea is only 25M and 43% of them are malnourished and only a small percentage have access to the internet. https://globalnews.ca/news/5029484/north-korea-malnutrition-... Number of security researchers isn't a function of population size it is a function of population size * fraction with propensity to show requisite skill * fraction who go to work in the profession. Shockingly adding million…

Ask Sony

Re: We Hacked Apple for 3 Months

#265

Earlier quoted context omitted.

iCloud wasn't cracked. They used social engineering to gain access to the accounts.

It wasn't that, they did do password cracking, if I recall correctly iCloud itself had a limit on password attempts through the site but there was a way to attempt logins through the API that didn't have that limit which let them target those users for brute force attacks.

I think this was speculation at the time, but it later came out that they were phishing attacks which got access to iCloud accounts, and once you have that you have the person's device backups.

Re: We Hacked Apple for 3 Months

#266

Bug bounties have always been mispriced. Either the damage estimates for a given bug are wildly over-estimated by risk analysts, or the price paid to find them is based on some kind of stupidity-arbitrage play. I think it's the latter. Consulting firms bill between $1500-$2500/day for senior staff. 2 hackers for 10 days could be the $50k they got paid. Instead, this crew used 5 hackers for say 45 days, or 225 person…

Hi hi! Speaking as both a bug bounty vet, and a consulting vet (I run includesecurity.com), here's my .02 on some things you may not have considered given your comment. 1) Sam and the other hackers did not do this as a full time gig, they primarily do this as moonlighting from their full time jobs (you can verify this on LinkedIn) 2) Consultants are often given tight scopes, and these artificial client-driven constra…

Some fair statements, others less so. I've been in the game for a while, and the point I would emphasize is smart hackers don't get paid as well as people who do less difficult work with a lower bar to entry. Black/grey market bug bounties for iOS vulnerabilities in the $1m range reflect the risk profile and value much more accurately. The bundle in this report are worth at least the pro-consulting rate, and are more commensurate with that high watermark. Good on them for doing it, and the prestige payout is great, but advertising those disadvantaged numbers bears comment.

Regarding amateurs, olympic athletes are amateurs, it's a reference to people pursuing it out of interest instead of just a 9-5 job, even if they happen to do it full time. Amateurs will almost always outperform professionals because the skill distribution among pro's has a longer tail, where to even get in the game without a pro backing you have to be above average. This was an amateur moonlighting effort that delivered better results than consultants who cost 10x the money.

Bug bounties find most vulns in scope that %80 of hackers would find, which I think is more valuable than an assurance level, because assurance levels are bunk. A security architecture is valuable, provided it's built with an understanding of the threat model of the actual business and gets implemented, but otherwise, I think the security assessment document production business doesn't have a long future.

Re: We Hacked Apple for 3 Months

#267
post #256

Earlier quoted context omitted.

The population of North Korea is only 25M and 43% of them are malnourished and only a small percentage have access to the internet. https://globalnews.ca/news/5029484/north-korea-malnutrition-... Number of security researchers isn't a function of population size it is a function of population size * fraction with propensity to show requisite skill * fraction who go to work in the profession. Shockingly adding million…

They just need to send a couple dozen of their brightest talent. You know their engineers & scientists train in Russia and China, right? Which from my last recollection, invests heavily in offensive cyber warfare. By your same logic, they would not have any Olympic competitors, let alone medalists.

You get a bright talented individual by offering 1000 ample nutrition and educational opportunities historically with computer tech you give people the opportunity to learn and play with it from an early age.

Most nations educate millions to 10s of millions in order to get their doctors, scientists, software developers, leaders. Someone who educates merely thousands of the kids of new rich kids selected primarily from the ranks of the lowest echelons of society a century OK is poorly positioned to be the best in any field.

Re: We Hacked Apple for 3 Months

#268
post #217

Earlier quoted context omitted.

This happens when a company choses to amass wealth instead of investing in security. Their ads about privacy now sound laughable

Oh please... EVERY SINGLE piece of software has some security issue. Apple is no exception. Assuming they should be perfect is just petty BS and short sighted. Also, keep in mind that security and privacy, while related, are not the same things. You can have privacy (i.e. minimal data gathering) and poor security. You can also have poor privacy but amazing security. Not sure why I'm feeding the troll here but whateve…

Do you mean issues like those found here? It's pretty embarrasing and negligent.

Re: We Hacked Apple for 3 Months

#269

If Apple does not pay these guys several hundred thousand dollars per person, they just recruited the worlds best hackers to work against them. Pay them, and the situation is reversed. Now we see how smart Apple really is.

World's best hacking team? That's highly unlikely. If they were wise though, they saved a few to sell to CIA/NSA/FBI who may be contacting them soon for said exploits thanks to articles like these. I doubt they showed the best cards in their magic deck.

This isn't a cyberpunk movie, that's not how it goes.

Re: We Hacked Apple for 3 Months

#270
post #259
post #151

Earlier quoted context omitted.

well, there was a time here in Brazil when MSN was very popular (@hotmail.com), all my friends used it as the default messenger. Later came Facebook and people created their account using the @hotmail.com and starting to left MSN, since facebook had a messenger. One day I received an email from Microsoft saying that they were disabling MSN (I'm telling this from memory, forgive me if I'm saying anything super wrong).…

I am not sure what Facebook could have done in such situation in those days.

"Hey man, thank you for bringing this to our attention. Wanna a free t-shirt? Anyways, be good!"

Edit - On a more serious note, I think they tried to enforce account creation to a cellphone number instead of email.

Post reply on HN