Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

281–290 of 318 posts

Re: We Hacked Apple for 3 Months

#281

Earlier quoted context omitted.

Late reply: They just paid for 28 more issues, running total is now $288,500. https://twitter.com/samwcyo/status/1314310787243167744

Absolutely wonderful news! Congrats to everyone involved. Kudos to Apple for following through. I hope this sets the standard for companies going forward.

Apple are already behind the standard and times on this. Apple aren’t leading here, they are reluctantly catching up and doing the minimum they need.

Re: We Hacked Apple for 3 Months

#282
post #139

Earlier quoted context omitted.

> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?

Yes, because it is worth in pentesting services 180k USD, no more no less. I mean, you can pay around 360k in London or SV rates and 180k in European for _similar_ skills people. Calc based on 3 months, 5 people, 600USD/md rate. EDIT as I can't reply to tpaceck below: no, those 2000usd/day rates do not exists in projects in size of 300MD like here. In general they do not exist for big projects. Yes, I agree, you have…

When I worked as a 'consultant' (glorified contractor) .Net developer, the company charged > 90 Euro / 105 USD per hour for my time. So that would make my going rate be > 800 USD / day. This is in a country where 50K / year is a decent developer salary.

I do not believe you can find pen testers worth their salt who would cost _less_ than a non-distinctive developer. At least not one who will do more than run some automated report over all your endpoints.

Re: We Hacked Apple for 3 Months

#283

Earlier quoted context omitted.

First, practically nobody uses iCloud Email. I'm honestly surprised it still exists. You can confirm with Google searchs the C.W. that iCloud Mail isn't a serious contender among email platforms. Second, you'd be a little naive if you thought Google Mail has never had XSS vulnerabilities.

The people who specifically choose to use iCloud email are far more likely to care about an XSS than the average Gmail user.

People who have mac.com and me.com email addresses (which are now part of iCloud email) are many and have the same variation in security posture as any other cloud email user.

Re: We Hacked Apple for 3 Months

#284

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

It's interesting that by owning and using that Class A block, Apple are making it easier to scan for their infrastructure. Moving that to IPv6 and releasing the Class A would help them avoid the preliminary scanning that was performed.

There's also something to be said about migrating internal DNS to a subdomain of apple.com that is only visible internally.

Not solutions to security, but making things harder to scan makes it harder to find the vulnerabilities.

Re: We Hacked Apple for 3 Months

#285

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

How is North Korea going to recruit top cybersecurity specialists?

> How is North Korea going to recruit top cybersecurity specialists?

Just like with Russia or China, by bribing cybersecurity specialists.

Re: We Hacked Apple for 3 Months

#286
Operations like this should be a fixture. Considering that not only individuals and companies but society as a whole increasingly depends on digital infrastructure we should develop mandatory procedures and frameworks for measuring security and improving it. You can't drive a car without a license but you can grab personal/private data of millions of people and give it away to criminals without consequence.

Re: We Hacked Apple for 3 Months

#287
post #276
post #274

Earlier quoted context omitted.

Bounty programs are in place so that bad actors are not the only ones on the lookout for bugs. If experts get paid pennies for finding enormous security vulnerabilities, what's stopping them from selling them to actually bad actors for a potentially much greater cut? I can imagine that someone would be willing to pay far more than $5M to gain access to Apple wharehouses.

Nothing but their ethics. But why would an expert spend any of their valuable time outside of work looking for bugs if they didn't like the terms of the program? That's irrational behavior. And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers? The vast majority of companies in operation today have no such program and would likely be…

> Nothing but their ethics.

That's not something a company the size of Apple can count on.

> And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers?

Because it's Apple, it's one of the biggest companies on earth. iPhone jailbreak vulnerabilities alone fetch millions on the black market.

If you know the bug bounty program doesn't pay much you can expect only the trivial things to have been found, and if you're very skilled you know you still have a good chance of finding things to sell.

> And lastly how would paying more for bugs prevent someone from also selling it to criminals?

It would keep more honest people interested in your bug bounty program instead of doing something else.

Re: We Hacked Apple for 3 Months

#288
post #287
post #276

Earlier quoted context omitted.

Nothing but their ethics. But why would an expert spend any of their valuable time outside of work looking for bugs if they didn't like the terms of the program? That's irrational behavior. And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers? The vast majority of companies in operation today have no such program and would likely be…

> Nothing but their ethics. That's not something a company the size of Apple can count on. > And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers? Because it's Apple, it's one of the biggest companies on earth. iPhone jailbreak vulnerabilities alone fetch millions on the black market. If you know the bug bounty program doesn't pay m…

>Because it's Apple, it's one of the biggest companies on earth.

Yes, and do you think you have a better understanding of the situation than the security and risk management folks that work there? There's absolutely nothing that has been said in this thread that they aren't keenly aware of. There are people in Cupertino that are going to wake up in a few hours, grab some coffee and pore over the threat intel reports from last night. They know who is buying and for how much and have a long detailed analysis of what happened with previous jailbreaks. There is another team of people dedicated to staffing the bounty program, rifling through stacks of reports with a signal to noise ratio that's approaching the Shannon limit, triaging findings, tracking down product and engineering teams to get a quick response so they can get back to the researcher in a timely fashion, handling rejections for out of scope and dupes.

These people are in it up to their eyeballs in this every day. They live it, breathe it, love it and they'll move the needle when moving the needle makes sense. Until then anyone that participates in the bounty program and then cries foul when payouts are in line with the posted max and not with what could be had on the black market are going to get zero sympathy from me.

Re: We Hacked Apple for 3 Months

#289
post #217

Earlier quoted context omitted.

Oh please... EVERY SINGLE piece of software has some security issue. Apple is no exception. Assuming they should be perfect is just petty BS and short sighted. Also, keep in mind that security and privacy, while related, are not the same things. You can have privacy (i.e. minimal data gathering) and poor security. You can also have poor privacy but amazing security. Not sure why I'm feeding the troll here but whateve…

Do you mean issues like those found here? It's pretty embarrasing and negligent.

I feel like you’ve never worked at a large company before.

None of this is abnormal. And it seems based on this article that Apple responded quickly and fixed the reported issues.

Re: We Hacked Apple for 3 Months

#290

If Apple does not pay these guys several hundred thousand dollars per person, they just recruited the worlds best hackers to work against them. Pay them, and the situation is reversed. Now we see how smart Apple really is.

I'd argue that those people may be better

https://ctftime.org/

Post reply on HN