Earlier quoted context omitted.
"Participating" covers a broad range of activity when it comes to this program, and would include things like having a portal to provide the legally mandated info that must be returned upon proper presentation of a warrant. Is it really 'sharing data with the government' if the latter shows up with a properly executed warrant for the data?
PRISM data is obtained without a warrant, even for USians whose data is supposed to be protected by a warrant, because of a special secret interpretation of the FISA Amendments Act (FAA) Section 702. It's warrantless, and the court that decides whether or not it's legal is itself classified and unaccountable and almost never denies surveillance. This abuse was cited by Ed Snowden as one of the reasons he came forward…
We Hacked Apple for 3 Months
311–318 of 318 posts
Re: We Hacked Apple for 3 Months
#312Earlier quoted context omitted.
> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM) From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you…
PRISM absolutely was about tech companies sharing data with the government. From the PRISM Wikipedia article[1]: > The documents identified several technology companies as participants in the PRISM program, including Microsoft in 2007, Yahoo! in 2008, Google in 2009, Facebook in 2009, Paltalk in 2009, YouTube in 2010, AOL in 2011, Skype in 2011 and Apple in 2012. [1] https://en.wikipedia.org/wiki/PRISM_(surveillance_…
The government issues a Section 702 order for some account(s) data, the company reviews the request and denies it if the account appears to belong to somebody in the US or an American (both of which cannot have their data requested via a Section 702 order), and then sets up a forward to the FBI. PRISM then geta that data from the FBI and parses it into fields for various NSA databases. Again, this is very clearly drawn out in the system diagram slide that Snowden leaked.
Re: We Hacked Apple for 3 Months
#313It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…
> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM) From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you…
Re: We Hacked Apple for 3 Months
#314Earlier quoted context omitted.
In the instance yes, but bounty programs need to be sustainable so parameters are set up front. Folks can choose to participate or not. If they don't like the offering, they can find something else.
Bounty programs are in place so that bad actors are not the only ones on the lookout for bugs. If experts get paid pennies for finding enormous security vulnerabilities, what's stopping them from selling them to actually bad actors for a potentially much greater cut? I can imagine that someone would be willing to pay far more than $5M to gain access to Apple wharehouses.
Re: We Hacked Apple for 3 Months
#315I think what might not be immediately obvious to people outside of the bug bounty scene is that Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes represent some of the best bug bounty hunters out there which is definitely one of the reasons they absolutely pwnd Apple here. I would be genuinely shocked if Apple doesn't end up paying out much more for all the bugs found. Frankly, it would be gen…
"Within the article I'd mentioned that Apple had not yet paid for all of the vulnerabilities. Right after publishing it, they went ahead and paid for 28 more of the issues making the running total $288,500" https://twitter.com/samwcyo/status/1314310787243167744
That's barely the yearly cost of one generic software engineer at Apple.
I was expecting multiple millions in payment given the severity and quantity of vulnerabilities found. State actors could easily 10x that amount legaly through gov contractors.
Re: We Hacked Apple for 3 Months
#316Earlier quoted context omitted.
In the article he says they invested "a few hundred hours"... I take that to be around 350 hours - $147/hr... still not a lot for speculative research
you missed a word: "we each ended up putting a few hundred hours into it." So the 20-30$ per hour figure is closer, before taxes, with zero benefits like health, dental or pension plans. They themselves say: bounty hunting is not a job
Re: We Hacked Apple for 3 Months
#317Earlier quoted context omitted.
PRISM data is obtained without a warrant, even for USians whose data is supposed to be protected by a warrant, because of a special secret interpretation of the FISA Amendments Act (FAA) Section 702. It's warrantless, and the court that decides whether or not it's legal is itself classified and unaccountable and almost never denies surveillance. This abuse was cited by Ed Snowden as one of the reasons he came forward…
Section 702 only allows them to request data from accounts that belong to foreigners outside the US, so no, it doesn't allow the US intelligence community to surveil everyone in the legislature and judiciary.
Re: We Hacked Apple for 3 Months
#318Earlier quoted context omitted.
In the instance yes, but bounty programs need to be sustainable so parameters are set up front. Folks can choose to participate or not. If they don't like the offering, they can find something else.
Bounty programs are in place so that bad actors are not the only ones on the lookout for bugs. If experts get paid pennies for finding enormous security vulnerabilities, what's stopping them from selling them to actually bad actors for a potentially much greater cut? I can imagine that someone would be willing to pay far more than $5M to gain access to Apple wharehouses.