Live data from Hacker News

I hacked macOS

asahilina.net

91–100 of 140 posts

Re: I hacked macOS

#91

Earlier quoted context omitted.

Sounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.

On the other hand, that's a years salary for many people. Seems like a quite fair payment, and a payout to envy. Lower, easier to get payouts are arguably better than rare jackpot payouts you have to fight over...

> On the other hand, that's a years salary for many people.

It's several years salary for many people.

Re: I hacked macOS

#92
Any suggestions for how I can get to anywhere close to Lina's skills? It's just mad skills.. I don't believe simply putting in huge amount of time in front of the machine is adequate. Neither is simply being smart. Is it just a combination of being smart, sinking in a lot of time, interests etc?

Re: I hacked macOS

#94

Earlier quoted context omitted.

Sounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.

How would you value this exploit, or any exploit?

I understand this is arbitrary code execution with root access. I'm imagining the potential of infecting a high status individual and I think a bad actor would pay millions for such an exploit.

Re: I hacked macOS

#95

Earlier quoted context omitted.

Sounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.

>Sounds extremely low for this kind of vulnerability How do you know that?

Which part? I feel that arbitrary code execution with root access is a pretty extreme thing to accomplish. But I might be mistaken!

Re: I hacked macOS

#96

Any suggestions for how I can get to anywhere close to Lina's skills? It's just mad skills.. I don't believe simply putting in huge amount of time in front of the machine is adequate. Neither is simply being smart. Is it just a combination of being smart, sinking in a lot of time, interests etc?

Read computer architecture and computer systems books.

Re: I hacked macOS

#97
post #74

Earlier quoted context omitted.

Sounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.

I mean, this is the company where the only security certification advertised on their website for macOS [1][2] only achieved the lowest possible level of security, EAL1. A level only fit for products where [3]: "some confidence in correct operation is required, but the threats to security are not viewed as serious" which is one level lower than "demonstrating resistance to penetration attackers with a basic attack po…

EAL is not a measure of security but a measure of the depth of analysis. Looking at the complexity of monolithic-kernel-based operating systems, I don't much can be derived from certifications with an EAL < 5.

Re: I hacked macOS

#99
post #90

Earlier quoted context omitted.

Sounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.

What? That's an insane amount of money

I'm comparing it with Apple's market cap of $10^12. Such a vulnerability seems pretty serious. But maybe I'm mistaken and it's not that bad.

Re: I hacked macOS

#100
post #46
post #15

[flagged]

" Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting. " " Please don't pick the most provocative thing in an article or post to complain about in the thread. Find something interesting to respond to instead. " https://news.ycombinator.com/newsguidelines.html

It's just a guideline.
Post reply on HN