Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…
How is North Korea going to recruit top cybersecurity specialists?
We Hacked Apple for 3 Months
271–280 of 318 posts
Re: We Hacked Apple for 3 Months
#272Earlier quoted context omitted.
> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?
Yes. I'd say "word to the wise", but I think very few people reading this thread buy pentest time in such large blocks: past a month and you start getting into steep discounts. (This was not several months of full time work, but rather several months of part time work; but I'm stipulating the former condition.)
Re: We Hacked Apple for 3 Months
#273Earlier quoted context omitted.
"Within the article I'd mentioned that Apple had not yet paid for all of the vulnerabilities. Right after publishing it, they went ahead and paid for 28 more of the issues making the running total $288,500" https://twitter.com/samwcyo/status/1314310787243167744
Even if they would pay a full $5.5 million, at 100k per issue, it seems reasonable for the breadth of the findings and potential losses prevented. The warehouse access alone could cause far more damage, while some of the smaller vulnerabilities are clearly not worth that much. EDIT: see this comment thread for more info on the economics by people who know what they're talking about: https://news.ycombinator.com/item?…
Re: We Hacked Apple for 3 Months
#274Earlier quoted context omitted.
Even if they would pay a full $5.5 million, at 100k per issue, it seems reasonable for the breadth of the findings and potential losses prevented. The warehouse access alone could cause far more damage, while some of the smaller vulnerabilities are clearly not worth that much. EDIT: see this comment thread for more info on the economics by people who know what they're talking about: https://news.ycombinator.com/item?…
In the instance yes, but bounty programs need to be sustainable so parameters are set up front. Folks can choose to participate or not. If they don't like the offering, they can find something else.
Re: We Hacked Apple for 3 Months
#275Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…
Late reply: They just paid for 28 more issues, running total is now $288,500. https://twitter.com/samwcyo/status/1314310787243167744
Kudos to Apple for following through.
I hope this sets the standard for companies going forward.
Re: We Hacked Apple for 3 Months
#276Earlier quoted context omitted.
In the instance yes, but bounty programs need to be sustainable so parameters are set up front. Folks can choose to participate or not. If they don't like the offering, they can find something else.
Bounty programs are in place so that bad actors are not the only ones on the lookout for bugs. If experts get paid pennies for finding enormous security vulnerabilities, what's stopping them from selling them to actually bad actors for a potentially much greater cut? I can imagine that someone would be willing to pay far more than $5M to gain access to Apple wharehouses.
But why would an expert spend any of their valuable time outside of work looking for bugs if they didn't like the terms of the program? That's irrational behavior.
And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers? The vast majority of companies in operation today have no such program and would likely be much more fruitful.
And lastly how would paying more for bugs prevent someone from also selling it to criminals?
Re: We Hacked Apple for 3 Months
#277I think what might not be immediately obvious to people outside of the bug bounty scene is that Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes represent some of the best bug bounty hunters out there which is definitely one of the reasons they absolutely pwnd Apple here. I would be genuinely shocked if Apple doesn't end up paying out much more for all the bugs found. Frankly, it would be gen…
"Within the article I'd mentioned that Apple had not yet paid for all of the vulnerabilities. Right after publishing it, they went ahead and paid for 28 more of the issues making the running total $288,500" https://twitter.com/samwcyo/status/1314310787243167744
Re: We Hacked Apple for 3 Months
#278Earlier quoted context omitted.
I’m unsure what your point is? I see dozens of different issues listed in the post, on different endpoints, all of which presumably took time to find. When they said they had a team of multiple people work for months on this, I am unsure why you think they haven’t spent their time as efficiently as “a pentesting team”. Actually, I’ll be stronger: looking through the list of things they discovered, it seems like they…
Issue count != time spent. I found about a dozen issues in a day once. And once, it took me three days to find one. Always found at least a medium severity issue though. Big engagements were typically a week, max. Usually one day of kickoff / getting “in the zone” for a project, three or so days of intensive testing, then the final day is usually writing reports (ugh, reports) all day.
Re: We Hacked Apple for 3 Months
#279I’ve always been interested in this round of thing, but have no idea how or where to get started
Many years ago, you'd likely have been told to start by reading the Web Application Hackers Handbook (WAHH). But that has since been replaced by the online interactive labs, available free of charge by the fine folks of PortSwigger. https://portswigger.net/web-security IMHO there is no better place to start.