Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

191–200 of 318 posts

Re: We Hacked Apple for 3 Months

#191
post #11

Earlier quoted context omitted.

Great, hard-shell/soft-centre. If anyone asks, why you should go to all the effort to secure the software in your internal-network, that's why.

I work on a giant famous multi-billion dollar company where all the internal stuff is full of permission requirements, training requirements, etc. It is absolutely HORRIBLE to be productive here. Every single kind of information you need to be able to work is hidden behind someone's wall. I often lose entire weeks of productivity just trying to find who owns a certain information or knows which permission I need to r…

It's funny, because the received wisdom in the industry is that Apple behaves exactly this way. I guess not in their production environment!

Re: We Hacked Apple for 3 Months

#192
post #64

"To be brief: Apple's infrastructure is massive. They own the entire 17.0.0.0/8 IP range, which includes 25,000 web servers with 10,000 of them under apple.com, another 7,000 unique domains, and to top it all off, their own TLD (dot apple)." Wow. I would think it's just impossible to secure all that, and that's not even everything.

Why do they need 17.0.0.0/8 (16,777,216 addresses) if they only have 25000 webservers? #eattheIPrich edit: fixed the number of addresses

#letthemeatipv6

Re: We Hacked Apple for 3 Months

#193
post #11

Earlier quoted context omitted.

Great, hard-shell/soft-centre. If anyone asks, why you should go to all the effort to secure the software in your internal-network, that's why.

I work on a giant famous multi-billion dollar company where all the internal stuff is full of permission requirements, training requirements, etc. It is absolutely HORRIBLE to be productive here. Every single kind of information you need to be able to work is hidden behind someone's wall. I often lose entire weeks of productivity just trying to find who owns a certain information or knows which permission I need to r…

To add insult to injury, your account of the state of things gives me no reason to think that their internal systems aren't rife with similar vulnerabilities, so rather like DRM only making life hard for paying customers, I suspect that these measures only make access difficult for honest employees.

Re: We Hacked Apple for 3 Months

#194
post #165

Earlier quoted context omitted.

No. The only people who make this claim are Apple critics who put words in Apple's mouth to justify whatever clickbait blog post they're putting out this week to pad their resumes and harvest echo chamber thumbs. But as we know from politics, if you tell a lie enough times it becomes the truth.

https://www.theatlantic.com/technology/archive/2019/01/apple...

In the article you linked to, I didn't see Apple claiming they alone can protect user's privacy. I read instead that Apple suggested all companies should strive to protect their user's privacy.

Re: We Hacked Apple for 3 Months

#195

Earlier quoted context omitted.

One problem is this puts a downward pressure on others who demand fair compensation for their labor. Not everyone wants to play a long game of "maybe i'll get paid in the future from the 'experience'" This is the professional equivalent of having interns do a bunch of real work and throwing them a pizza party.

Unfortunately, it doesn’t matter if other people don’t want to play the long game. This team does, they’re executing it well, and it will boost their careers as a result. Everything was done voluntarily by consenting professionals with the rules of the game outlined up front. Can’t really fault them for that.

People can consent or do plenty of things that are allowable. That doesn't mean I can't fault the actions or dig deeper into whether or not it has other drawbacks (or even pros). Just because something is allowable doesn't mean it doesn't have other impacts.

But to be clear that doesn't mean I think they (or someone else) should not be allowed to make this choice. The possibility should definitely exist. I just don't think it's a good choice in terms of it being a norm.

Re: We Hacked Apple for 3 Months

#196
post #35

$6k for an internal perimiter SSRF that led to source code access? What a joke.

Is that not the "XML External Entity processing to Blind SSRF on Java Management API" SSRF? As that would make sense to match that payment. I really struggle to believe that the $6k is for the maven access one, that's a billion dollar vulnerability.

That’s not a billion dollar vulnerability, you can buy recent copies of this source code for a million dollars.

Re: We Hacked Apple for 3 Months

#197

Earlier quoted context omitted.

No. The only people who make this claim are Apple critics who put words in Apple's mouth to justify whatever clickbait blog post they're putting out this week to pad their resumes and harvest echo chamber thumbs. But as we know from politics, if you tell a lie enough times it becomes the truth.

https://www.cnn.com/2020/09/03/tech/apple-iphone-privacy-ad/...

Not seeing Apple claiming only they can protect user's privacy. Instead the article quotes Tim Cook trying to pressure the governments t recognize privacy as a fundamental human right.

Re: We Hacked Apple for 3 Months

#198

Earlier quoted context omitted.

One problem is this puts a downward pressure on others who demand fair compensation for their labor. Not everyone wants to play a long game of "maybe i'll get paid in the future from the 'experience'" This is the professional equivalent of having interns do a bunch of real work and throwing them a pizza party.

This is very fair criticism for standard jobs like a regular software developer. For a role like this, where outsized skill of someone who is and needs to be elite should be rewarded with enormously outsized pay, I think this a good model.

I think we're in agreement.

But, I do find it wild that a group as decorated as this already can't even get compensation that is commensurate with their skill and experience without having to rely on intangible future benefits.

Re: We Hacked Apple for 3 Months

#199

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

But that is the thing... their official Bug Bounty program scope didn't include most of these exploits so any payments/awards would have to be made outside of the traditional system and thus probably take more senior approval/time to make payments. They knew that they would possibly not get paid for them but took the risk anyways. I have a feeling they will end up getting at least a hundred thousand dollars total.

Re: We Hacked Apple for 3 Months

#200

Earlier quoted context omitted.

https://www.cnn.com/2020/09/03/tech/apple-iphone-privacy-ad/...

Not seeing Apple claiming only they can protect user's privacy. Instead the article quotes Tim Cook trying to pressure the governments t recognize privacy as a fundamental human right.

> Not seeing Apple claiming only they can protect user's privacy

You would if you had watched the commercial.

Post reply on HN