Earlier quoted context omitted.
My first thought would be that the team within Apple may worry the researcher may resell the vulnerability to an exploits site. Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with. I would also understand the researcher's point of view that this fell through the cracks or Apple is not wil…
I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere. No maybe the shadiness inherent in the field means no one trusts that agreement anyway, but I suspect there's generally some amount of trust for researchers submitting vulnerabilities, particularly if they have some kind of history of good faith. Also, I'm not sure that saying "we have discovered a deeper p…
Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
181–190 of 254 posts
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#182I wish Apple would do a feature freeze for iOS and macOS for a couple of years, then focus on fixing bugs, improving security and optimizing performance instead.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#183Earlier quoted context omitted.
I would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere. No maybe the shadiness inherent in the field means no one trusts that agreement anyway, but I suspect there's generally some amount of trust for researchers submitting vulnerabilities, particularly if they have some kind of history of good faith. Also, I'm not sure that saying "we have discovered a deeper p…
> would assume that trying to get a bounty means accepting that you're not selling the vulnerability elsewhere Having an e-mail from the company confirming the bug is serious and systemic massively raises its market value. Security is necessarily trust less. These game dynamics are unavoidable.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#184Earlier quoted context omitted.
>Who? Cellebrite and all the surveillance-as-a-service shops might be interested in information disclosure bugs. You maybe will not get the $100K Apple promised, but maybe you can sell it four times for $30K or something like that if the bug is still "good enough" for certain uses. RCEs in Windows or iOS go for a lot more than a measly $100K if you can manage to get in contact with the right people. Think 10-20 times…
Full chain RCEs in iOS go for 1MM from the Apple bounty program , so you'd imagine they'd have to go for more than that from a tranched grey market contract. This is a bug that allows you to read contacts from a malicious app installed from the app store. It's not drive-by contract exfiltration; it's intensively interactive. I'm surprised the Apple bounty terms are so generous-sounding about bugs like these, but I re…
But who knows, it still might worth a few bucks to you because you already figure out the delivery. And your relationship to somebody with the skills to find interesting bugs and willingness to sell to you might be even worth more, so you might pay money not just for the bug but for the relationship.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#185Zerodium ( https://zerodium.com/program.html ) pays out $2 million dollars for an iOS “full chain with persistence” exploit. $500k for an iMessage RCE. Up to $100k for an iOS “information disclosure” exploit (likely what this would have fallen under). Paid for via bank wire or Bitcoin/Monero/Zcash in 1 week or less. And legal. Next time someone finds one of these, I wonder where they will report it to….
See my comment history for a firsthand account of Zerodium.
If you're ever in Amsterdam and feel up for drinking a beer [0] with someone interested in netsec [1], feel free to email me.
[0] Or coffee, tea, your beverage of choice.
[1] I did a couple of fairly good security courses and about 300 hours of hackthebox.eu. So while I'm not a professional, at least I've scripted with IDA Python and defeated fun boxes like PlayerTwo.
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#186Earlier quoted context omitted.
What makes you think the seller’s donation is going to counterbalance the harm of his now-weaponized exploit?
The report to the manufacturer with the remark that there is a existing weaponized exploit will lead to a much faster fix. And why you are so sure that there was no weaponized exploit out there before?
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#187Earlier quoted context omitted.
that is, unfortunately, not at all how the bug-bounty market works. Apple (or any other tech company) can't outbid three-letter-agencies, certainly not on a regular basis. Open market value is at least 10x higher than companies will pay directly. Apple will pay a million bucks? Fine, NSA TAO will pay $10m. Apple can't pay $10m or $100m a bug on a regular basis, for the customers whom this matters the check is basical…
How does one contact the NSA TAO and offer to sell a zero-day?
>One person who will share those sales numbers is a South African hacker who goes by the name “the Grugq” and lives in Bangkok. For just over a year the Grugq has been supplementing his salary as a security researcher by acting as a broker for high-end exploits, connecting his hacker friends with buyers among his government contacts. He says he takes a 15% commission on sales and is on track to earn more than $1 million from the deals this year. “I refuse to deal with anything below mid-five-figures these days,” he says. In December of last year alone he earned $250,000 from his government buyers. “The end-of-year budget burnout was awesome.”
https://www.forbes.com/sites/andygreenberg/2012/03/21/meet-t...
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#188Earlier quoted context omitted.
I have also worked on managing bug bounties and that is why you keep lines of communication open with the researchers. Not to throw stones in glass houses, but there are a number of ways Apple could improve on their approach to how they do their bug bounty program. I have heard of many researchers having extremely long delays, poor communication and simple things like not acknowledging the bug submissions.
Aftering filing multiple bug reports with Apple now against WkWebView, I can say that extremely long delays and poor communication is not isolated to the bug bounty team :)
Re: Apple silently fixes iOS zero-day, asks bug reporter to keep quiet
#189Earlier quoted context omitted.
Ya, if I interpreted this right, also really convenient that they seem to be dragging their feet on a $100,000 bounty.
Nobody's going to pay $100,000 for a bug that lets you download someone's contact list.