Earlier quoted context omitted.
First, practically nobody uses iCloud Email. I'm honestly surprised it still exists. You can confirm with Google searchs the C.W. that iCloud Mail isn't a serious contender among email platforms. Second, you'd be a little naive if you thought Google Mail has never had XSS vulnerabilities.
The people who specifically choose to use iCloud email are far more likely to care about an XSS than the average Gmail user.
We Hacked Apple for 3 Months
301–310 of 318 posts
Re: We Hacked Apple for 3 Months
#302I’ve always been interested in this round of thing, but have no idea how or where to get started
one way to understand how to break things is to first build a couple when you build things you can understand the trade-offs people have to make which gives you an intuition for weak spots
Re: We Hacked Apple for 3 Months
#303Earlier quoted context omitted.
That's probably right. A quick internet search shows up domains like applecoronavirus.com and similar, as well as this court case [1] where they acquired a bunch of ipod related names. I suspect they are only parking those names after recovering them or buying them preemptively. Domain names are cheap, so why not. I don't think that's any argument for the possession of the /8 though. I remember Google had ownership o…
All parked domains could lead to the same IP. A single web server could distinguish which domain it’s contacted for, using the HTTP headers for example, and serve different content (probably all 301-redirects, but to relevant other websites of Apple).
Re: We Hacked Apple for 3 Months
#304Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…
If one bounty hunter got $100k for a single exploit, these guys should’ve gotten millions...
Re: We Hacked Apple for 3 Months
#305Earlier quoted context omitted.
$288k and Apple has only paid them for roughly half of the vulnerabilities. They expect the payout to exceed $500k. Well worth it for Apple and a decent payday for 3 months of spelunking.
Gross pay (not including employee benefits and before payroll tax deduction), split among a team of 5 people, unclear if they were working on this one project full time, and amortized over other months with less renumeration. It may not be better amortized pay than a regular software job.
Re: We Hacked Apple for 3 Months
#306Earlier quoted context omitted.
A classic false comparison: the four experienced security researchers working for multiple months covers 55 issues, not "that one issue". If we're cherry picking a single one, the associated involvement and timeframe drops dramatically, to something much closer to one or two people, tops, over the course of just a few days, tops. That's something a pentesting team can absolutely achieve for far less than $500,000 ove…
There's really 2 options here. One, Apple doesn't employ a pen-testing team currently, which would be nuts, or, two, the pen-testing team couldn't find these bugs, or they'd already be found.
Re: We Hacked Apple for 3 Months
#307Earlier quoted context omitted.
It's also one of nine nuclear powers and one of ten to have developed space launch capability. It also scores near the top of the international math olympiad regularly. What makes you certain North Korea hasn't similarly invested in developing security researchers?
Apples net income is bigger than their GDP and most of their people as impoverished, malnourished and poorly educated. The upper caste from which all their "talent" is drawn is a small fraction of its total population mostly composed of the descendants of the lower class peasants and workers who supported the rise of the current regime. They supported not an establishment of such a system but rather an inversion of t…
Re: We Hacked Apple for 3 Months
#308Earlier quoted context omitted.
The people who specifically choose to use iCloud email are far more likely to care about an XSS than the average Gmail user.
People who have mac.com and me.com email addresses (which are now part of iCloud email) are many and have the same variation in security posture as any other cloud email user.
Re: We Hacked Apple for 3 Months
#309Earlier quoted context omitted.
I think everything is complicated, and that is certainly isn't as simple as "Apple should pay paid $250k to a pentesting firm to find these bugs", because you could keep paying $250k over and over again and keep finding different bugs of comparable severity.
And finding these bugs of comparable severity isn't worth the $250k each time? I can easily see the iCloud photo worming one making it's way into mainstream media and causing millions of dollars of reputational damage.
For what it's worth, "reputational damage" has always been a kind of rhetorical escape hatch from arguments that have become too mired in facts.
Re: We Hacked Apple for 3 Months
#310Earlier quoted context omitted.
Issue count != time spent. I found about a dozen issues in a day once. And once, it took me three days to find one. Always found at least a medium severity issue though. Big engagements were typically a week, max. Usually one day of kickoff / getting “in the zone” for a project, three or so days of intensive testing, then the final day is usually writing reports (ugh, reports) all day.
Sounds about right. :-)