Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

301–310 of 318 posts

Re: We Hacked Apple for 3 Months

#301

Earlier quoted context omitted.

First, practically nobody uses iCloud Email. I'm honestly surprised it still exists. You can confirm with Google searchs the C.W. that iCloud Mail isn't a serious contender among email platforms. Second, you'd be a little naive if you thought Google Mail has never had XSS vulnerabilities.

The people who specifically choose to use iCloud email are far more likely to care about an XSS than the average Gmail user.

Please elaborate.

Re: We Hacked Apple for 3 Months

#302
post #52
post #36

I’ve always been interested in this round of thing, but have no idea how or where to get started

one way to understand how to break things is to first build a couple when you build things you can understand the trade-offs people have to make which gives you an intuition for weak spots

This is what I tell everyone interested in becoming a pentester. Know your enemy.

Re: We Hacked Apple for 3 Months

#303
post #190

Earlier quoted context omitted.

That's probably right. A quick internet search shows up domains like applecoronavirus.com and similar, as well as this court case [1] where they acquired a bunch of ipod related names. I suspect they are only parking those names after recovering them or buying them preemptively. Domain names are cheap, so why not. I don't think that's any argument for the possession of the /8 though. I remember Google had ownership o…

All parked domains could lead to the same IP. A single web server could distinguish which domain it’s contacted for, using the HTTP headers for example, and serve different content (probably all 301-redirects, but to relevant other websites of Apple).

In this case it looks like a lot of them don't have A records at all.

Re: We Hacked Apple for 3 Months

#304
post #181

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

If one bounty hunter got $100k for a single exploit, these guys should’ve gotten millions...

Not to discredit the great work all these people did but not all exploits are created equally. Generally speaking the bug bounty amount is directly correlated to the blast radius of the exploit.

Re: We Hacked Apple for 3 Months

#305
post #298

Earlier quoted context omitted.

$288k and Apple has only paid them for roughly half of the vulnerabilities. They expect the payout to exceed $500k. Well worth it for Apple and a decent payday for 3 months of spelunking.

Gross pay (not including employee benefits and before payroll tax deduction), split among a team of 5 people, unclear if they were working on this one project full time, and amortized over other months with less renumeration. It may not be better amortized pay than a regular software job.

Especially considering that the authors are some of the best bug bounty hunters in the world. $500 an hour is a fairly normal rate for a top security consultant, as far as I'm aware.

Re: We Hacked Apple for 3 Months

#306
post #137

Earlier quoted context omitted.

A classic false comparison: the four experienced security researchers working for multiple months covers 55 issues, not "that one issue". If we're cherry picking a single one, the associated involvement and timeframe drops dramatically, to something much closer to one or two people, tops, over the course of just a few days, tops. That's something a pentesting team can absolutely achieve for far less than $500,000 ove…

There's really 2 options here. One, Apple doesn't employ a pen-testing team currently, which would be nuts, or, two, the pen-testing team couldn't find these bugs, or they'd already be found.

Or option 3: apple is HUGE, in all respects: physical space, people with access, code base, etc. etc. and they already have plenty of teams in place, but a bug bounty program is a cheap supplemental. In which case paying out more for your bug bounty program than you pay your real teams would be really weird.

Re: We Hacked Apple for 3 Months

#307
post #235

Earlier quoted context omitted.

It's also one of nine nuclear powers and one of ten to have developed space launch capability. It also scores near the top of the international math olympiad regularly. What makes you certain North Korea hasn't similarly invested in developing security researchers?

Apples net income is bigger than their GDP and most of their people as impoverished, malnourished and poorly educated. The upper caste from which all their "talent" is drawn is a small fraction of its total population mostly composed of the descendants of the lower class peasants and workers who supported the rise of the current regime. They supported not an establishment of such a system but rather an inversion of t…

And yet they are able to assemble a team of math olympiad contestants that consistently places in the top 10 in every year that it competes.

Re: We Hacked Apple for 3 Months

#308
post #283

Earlier quoted context omitted.

The people who specifically choose to use iCloud email are far more likely to care about an XSS than the average Gmail user.

People who have mac.com and me.com email addresses (which are now part of iCloud email) are many and have the same variation in security posture as any other cloud email user.

We'd be talking about people who have @me.com email addresses and use the web application and not Mail.app on macOS or iOS. I doubt there's that many.

Re: We Hacked Apple for 3 Months

#309
post #246

Earlier quoted context omitted.

I think everything is complicated, and that is certainly isn't as simple as "Apple should pay paid $250k to a pentesting firm to find these bugs", because you could keep paying $250k over and over again and keep finding different bugs of comparable severity.

And finding these bugs of comparable severity isn't worth the $250k each time? I can easily see the iCloud photo worming one making it's way into mainstream media and causing millions of dollars of reputational damage.

It's not a question of whether any spot assessment is worth $250k (though: Apple can get a sitewide pentest from experts for substantially less than that). It's a question of whether paying that continuously is worth it, or whether that many can be spent more productively on something else.

For what it's worth, "reputational damage" has always been a kind of rhetorical escape hatch from arguments that have become too mired in facts.

Re: We Hacked Apple for 3 Months

#310
post #278

Earlier quoted context omitted.

Issue count != time spent. I found about a dozen issues in a day once. And once, it took me three days to find one. Always found at least a medium severity issue though. Big engagements were typically a week, max. Usually one day of kickoff / getting “in the zone” for a project, three or so days of intensive testing, then the final day is usually writing reports (ugh, reports) all day.

Sounds about right. :-)

It's not. The median appsec engagement is ~4 person-weeks.
Post reply on HN