Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

11–20 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#11
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

I forget who, but someone made a comment about this a long time ago that stuck with me. We often say, "They'll just sell all these 0 days on the black market." but honestly that's not like a literal market, and you have to make a lot of compromises to not only your own integrity, but also to your safety and ability to stay out of jail if you do something like that. I wish I remembered the specifics of the comment, bu…

I don't see how there's any risk when it gets sold to a broker like Zerodium who then sells it to some government.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#12
post #5
post #2

Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-rem... ?

From the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?

At the end of their Black Hat talk they showed one. Anyway, Project Zero doesn't accept bounties.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#13
post #5
post #2

Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-rem... ?

From the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?

She has a list at https://twitter.com/natashenka/status/1155940732084973568 (recall that "remote, interaction-less" means "do not require any physical interaction from the target to be exploited, and work in real time", according to the Project Zero blog post).

Edit: As the posters below said, those aren't kernel bugs. Thanks for the correction!

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#14

Earlier quoted context omitted.

No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.

You really think Apple is just going to gives special dev devices to random hackers from the Internet?

I don’t think they will, I know they will.

But maybe it depends on how you define “hacker” and what you call “random”. I’m saying that folks in the jailbreaking scene are some of the primary targets for this. It wouldn’t be worth launching if the plan was to exclude them. Some are already part of Apple’s bounty program.

“Apple Calls In Rock Star iPhone And Mac Hackers For Secret Bug Bounty Bash”

https://www.forbes.com/sites/thomasbrewster/2016/09/28/apple...

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#15
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

Depends who’s buying I imagine. Not sure about everyone else but I always picture the entities buying on the black market as singular people for some reason

When you consider it could be the likes of the three digit shoe inspectors over there in the US it could be a fair chunk of change

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#16
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

From the article:

>Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone.

So that's already more than what Apple offers. I tend to think they'll always be outbid.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#17
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

Worth adding that clean money is worth more than dirty money

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#18
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

> I could easily see some less than ethical researchers applying for this program and selling all the 0 days they find to the usual suspects rather than informing Apple.

That's what has been happening so far. Here's a report from a couple of years ago about this: https://www.vice.com/en_us/article/gybppx/iphone-bugs-are-to...

The announcement today is actually raising the rewards 5x (from $200K to $1M) to make it more valuable to report this to Apple.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#19
post #5

Earlier quoted context omitted.

From the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?

She has a list at https://twitter.com/natashenka/status/1155940732084973568 (recall that "remote, interaction-less" means "do not require any physical interaction from the target to be exploited, and work in real time", according to the Project Zero blog post). Edit: As the posters below said, those aren't kernel bugs. Thanks for the correction!

Did any of those touch the kernel? I thought all of those were in userspace.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#20
"Another $500,000 will be given to those who can find a "network attack requiring no user interaction.""

The implication of this conditional reward is that interactive use presents more/easier attack opportunities than non-interactive use. To clarify terminology, it is arguable that "non-interactive" can be a synonym for "automated" in this context.

Further, we might argue that canonical examples of "interactive" use are clicks, drags, taps or swipes. In other words, the prevailing "UI" for many users and the one promoted by many developers.

Now, if you agree these are fair statements then it is also arguable that from the user's persepctive it could be useful to engage in non-interactive/automated use not only for reasons of efficiency or convenience but also for reasons of "security".

Finally, given these propositions, the question I ask is why website and app users are continually faced with "terms and conditions" that seek to prohibit non-interactive use. Interactive use benefits those running a website or app server in at least one obvious and significant way: more interaction means more data to collect. But if we accept the implication of this bug bounty it also means greater risk to the user.

Regulators need to protect the user's right to use her computer, including a "smartphone", in a non-interactive manner. This right is constantly under attack (no pun intended) by those who are in the business of collecting user data. Interactive use can result in less data privacy and more/easier attack opportunities.

Post reply on HN