Earlier quoted context omitted.
Late reply: They just paid for 28 more issues, running total is now $288,500. https://twitter.com/samwcyo/status/1314310787243167744
Absolutely wonderful news! Congrats to everyone involved. Kudos to Apple for following through. I hope this sets the standard for companies going forward.
We Hacked Apple for 3 Months
281–290 of 318 posts
Re: We Hacked Apple for 3 Months
#282Earlier quoted context omitted.
> $500k is much more than a sitewide external app pentest of comparable scope would cost Apple, by an integer multiple. By a team of four experienced security researchers working for multiple months?
Yes, because it is worth in pentesting services 180k USD, no more no less. I mean, you can pay around 360k in London or SV rates and 180k in European for _similar_ skills people. Calc based on 3 months, 5 people, 600USD/md rate. EDIT as I can't reply to tpaceck below: no, those 2000usd/day rates do not exists in projects in size of 300MD like here. In general they do not exist for big projects. Yes, I agree, you have…
I do not believe you can find pen testers worth their salt who would cost _less_ than a non-distinctive developer. At least not one who will do more than run some automated report over all your endpoints.
Re: We Hacked Apple for 3 Months
#283Earlier quoted context omitted.
First, practically nobody uses iCloud Email. I'm honestly surprised it still exists. You can confirm with Google searchs the C.W. that iCloud Mail isn't a serious contender among email platforms. Second, you'd be a little naive if you thought Google Mail has never had XSS vulnerabilities.
The people who specifically choose to use iCloud email are far more likely to care about an XSS than the average Gmail user.
Re: We Hacked Apple for 3 Months
#284"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.
There's also something to be said about migrating internal DNS to a subdomain of apple.com that is only visible internally.
Not solutions to security, but making things harder to scan makes it harder to find the vulnerabilities.
Re: We Hacked Apple for 3 Months
#285Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…
How is North Korea going to recruit top cybersecurity specialists?
Just like with Russia or China, by bribing cybersecurity specialists.
Re: We Hacked Apple for 3 Months
#286Re: We Hacked Apple for 3 Months
#287Earlier quoted context omitted.
Bounty programs are in place so that bad actors are not the only ones on the lookout for bugs. If experts get paid pennies for finding enormous security vulnerabilities, what's stopping them from selling them to actually bad actors for a potentially much greater cut? I can imagine that someone would be willing to pay far more than $5M to gain access to Apple wharehouses.
Nothing but their ethics. But why would an expert spend any of their valuable time outside of work looking for bugs if they didn't like the terms of the program? That's irrational behavior. And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers? The vast majority of companies in operation today have no such program and would likely be…
That's not something a company the size of Apple can count on.
> And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers?
Because it's Apple, it's one of the biggest companies on earth. iPhone jailbreak vulnerabilities alone fetch millions on the black market.
If you know the bug bounty program doesn't pay much you can expect only the trivial things to have been found, and if you're very skilled you know you still have a good chance of finding things to sell.
> And lastly how would paying more for bugs prevent someone from also selling it to criminals?
It would keep more honest people interested in your bug bounty program instead of doing something else.
Re: We Hacked Apple for 3 Months
#288Earlier quoted context omitted.
Nothing but their ethics. But why would an expert spend any of their valuable time outside of work looking for bugs if they didn't like the terms of the program? That's irrational behavior. And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers? The vast majority of companies in operation today have no such program and would likely be…
> Nothing but their ethics. That's not something a company the size of Apple can count on. > And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers? Because it's Apple, it's one of the biggest companies on earth. iPhone jailbreak vulnerabilities alone fetch millions on the black market. If you know the bug bounty program doesn't pay m…
Yes, and do you think you have a better understanding of the situation than the security and risk management folks that work there? There's absolutely nothing that has been said in this thread that they aren't keenly aware of. There are people in Cupertino that are going to wake up in a few hours, grab some coffee and pore over the threat intel reports from last night. They know who is buying and for how much and have a long detailed analysis of what happened with previous jailbreaks. There is another team of people dedicated to staffing the bounty program, rifling through stacks of reports with a signal to noise ratio that's approaching the Shannon limit, triaging findings, tracking down product and engineering teams to get a quick response so they can get back to the researcher in a timely fashion, handling rejections for out of scope and dupes.
These people are in it up to their eyeballs in this every day. They live it, breathe it, love it and they'll move the needle when moving the needle makes sense. Until then anyone that participates in the bounty program and then cries foul when payouts are in line with the posted max and not with what could be had on the black market are going to get zero sympathy from me.
Re: We Hacked Apple for 3 Months
#289Earlier quoted context omitted.
Oh please... EVERY SINGLE piece of software has some security issue. Apple is no exception. Assuming they should be perfect is just petty BS and short sighted. Also, keep in mind that security and privacy, while related, are not the same things. You can have privacy (i.e. minimal data gathering) and poor security. You can also have poor privacy but amazing security. Not sure why I'm feeding the troll here but whateve…
Do you mean issues like those found here? It's pretty embarrasing and negligent.
None of this is abnormal. And it seems based on this article that Apple responded quickly and fixed the reported issues.
Re: We Hacked Apple for 3 Months
#290If Apple does not pay these guys several hundred thousand dollars per person, they just recruited the worlds best hackers to work against them. Pay them, and the situation is reversed. Now we see how smart Apple really is.