Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

161–170 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#161
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices.

You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#162

Earlier quoted context omitted.

I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell expl…

On these marketplaces, how do people demonstrate PoC without giving away the intellectual property? Or is it unproven and completely reputation based

Reputation plays a big part in it on both sides. Most buys are not Zerodium and putting themselves out there as buyers. So, there is a certain degree of vouching that happens as someone introduces a buyer to a seller.

So, when either party violates the agreement, it reflects poorly on that person who made the introduction, making it harder for them to make those connections in the future. And, these introductions matters, most sellers don't want to just sell to anyone, there needs to be some trust that who you're selling to will be selling it to friendly governments or whatever. Its not like a craigslist ad where you sell to just anyone who answers.

So that acts as a deterrent on the buyer side. It'll be harder to get new sellers if you have a poor, or no reputation.

On the seller side, you're not going to get too many people willing to vouch for you as you start burning bridges by selling non-working exploits.

And on that, the payment scheme acts as a deterrent, like teh great-grandparent said:

> grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid.

That is, you might get XX Thousand upfront, and then an agreed upon XXX thousand based on the exploit surviving XX days.

So trying to scam the buyer will net you a small amount of the total at best, but I mean, often times they'll hold payment until its confirmed and contracts are written and signed over these sales too, its not under the table payments or anything for the most part. Legitimate business transactions.

So, I guess to sum it up, reputation and a demonstrated, or atleast vouched for past record. There is a lot of trust on both sides.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#163
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

Agreed. People talking in the top-rated comments of this thread seem to think 1M is a lot of money for a vulnerability that could cost Apple lifetime customer value 10-100x the amount they’re offering in bounty.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#164
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Isn't it much simpler and cheaper for apple to buy the same exploit through the same brokers anonymously?

That would be a scam if bug on the grey market are paid over time until fixed.

Then Apple could buy and fix ASAP so the researcher get screwed. So yeah it’s cheaper but if someone notice just wait for the backfire! Guaranteed one time payement seem like the fair way to go.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#165

Earlier quoted context omitted.

On these marketplaces, how do people demonstrate PoC without giving away the intellectual property? Or is it unproven and completely reputation based

I imagine that a remote exploit should be pretty easy to demonstrate without giving away how you did it?

Harder than you might think. Who gets to control the server being compromised?

1. The buyer or someone the buyer trusts, then the buyer can log all the network traffic and find the incoming attack traffic and work out the exploit from there.

2. The seller or someone the seller trusts, can backdoor the software to fake it.

3. Someone they both trust, that would require they have some mutual contacts which while possible I wouldn't count on it.

4. A random victim, more possible, but neither party would want to risk prematurely burning the exploit.

And of course there are a ton of exploits that are not remote, all sorts of local privilege escalations, and there are partial exploits that are sold. Like a multistage exploits like say just the exploit to escape a sandbox, or even just an exploit that requires a memory leak could be sold without a memory leak, or just selling the memory leak. Obviously a fully weaponized exploit sells for the most, but there are buyers for stages also.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#166
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

I agree it’s a smart move, but I don’t know that I agree with the figure. Anyone who claims this bounty could make 500k+ at Apple without question. In some ways it seems like a recruitment exercise.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#167

Earlier quoted context omitted.

On these marketplaces, how do people demonstrate PoC without giving away the intellectual property? Or is it unproven and completely reputation based

Reputation plays a big part in it on both sides. Most buys are not Zerodium and putting themselves out there as buyers. So, there is a certain degree of vouching that happens as someone introduces a buyer to a seller. So, when either party violates the agreement, it reflects poorly on that person who made the introduction, making it harder for them to make those connections in the future. And, these introductions mat…

Exactly

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#168
post #158

Apple salaries aren’t much of a secret, see: levels.fyi. 1M is a lot of money to me, a regular person, but when you consider that top security engineering talent could be making north of 500k in total compensation, 1M suddenly doesn’t seem all that impressive. It’s a good bet to make on their risk. Imagine paying a mere 1M to avoid a public fiasco where all of your users get owned. This just seems like good business.…

I'm surprised by how cheap the vulnerabilities market is. A good exploit, against a popular product like Chrome, selling for 100k or even $1M may sound like a lot, but it's really pennies for any top software firm. And $1M is still a lot for a vulnerability by market prices. You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.

Out of interest how do you get to know the market price or the market in general for this sort of thing?

If I were to discover a vulnerability is there a legal way I could cash in on it (aside from this case with Apple)?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#169
post #147

Earlier quoted context omitted.

With those terms, they can buy a bug, report it to Apple, collect the $1m, and be off the hook to pay out the remaining payments. It seems to me this makes it much riskier to go to the black market than people here realize.

Yes, because that is exactly the sort of behavior that a business would engage in. Screwing over their suppliers and demonstrating that they offer no value whatsoever. How would that make any sense? It is ludicrous.

Would be a nice pivot for patent troll companies. In a world where profit is king the question is not why, but when?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#170
post #144

Earlier quoted context omitted.

It is not illegal to sell that type of software. It is not a black market, it is a grey market. There is no way you will ever hear authentic answers to your questions. The only time anyone tried to explain that the resulting article backfired on the interviewee. (Disclaimer, it was me) Governments do not buy from developers. The paperwork would be insane. They buy from businesses like Raytheon. How Raytheon gets them…

> the resulting article was a hatchet job Was that the forbes article linked above? > You can’t unfuck the goat. C’est la vie. That goat laid you golden eggs though. It takes me over 15 years to earn a $1m paycheck, and I wouldn't mind dealing with some people moaning at me for it. People always find something to complain about anyway, so I wouldn't be too concerned about it. > The conversation about vulnerability sa…

Yeah, that’s part of the hatchet job. I said I was projecting sales of $1M over the year. At 15% commission that would be $150k. You can make a lot more money than that, I’m sure. Also, don’t predict your sales funnel in February when you have no historical data to compare it with. I was off by about $900k.

So yeah, that $15k golden egg. ¯\_(ツ)_/¯

At thetime I did not know about phrases like “off the record” or that you could have corrections made to articles that had false information. Had I known I would have OTRed at the beginning although I should never have spoken in the first place. And I should have made them correct the inaccuracies.

But, c’est la vie.

Post reply on HN