Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

21–30 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#21
post #9

Earlier quoted context omitted.

No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.

The point is apple is likely to only aim for researchers for this program as the hackers could just resell most 0days, letting apple know about a small fraction to maintain reputation. It would make sense for apple to not allow hackers access to the program for this reason.

I’m using researchers and hackers interchangeably here. It isn’t intended for academics or companies affiliated with Apple, that’s for sure.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#22
post #5

Earlier quoted context omitted.

From the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?

She has a list at https://twitter.com/natashenka/status/1155940732084973568 (recall that "remote, interaction-less" means "do not require any physical interaction from the target to be exploited, and work in real time", according to the Project Zero blog post). Edit: As the posters below said, those aren't kernel bugs. Thanks for the correction!

I do not believe a springboard crash counts as a hack of the kernel.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#23
post #20

"Another $500,000 will be given to those who can find a "network attack requiring no user interaction."" The implication of this conditional reward is that interactive use presents more/easier attack opportunities than non-interactive use. To clarify terminology, it is arguable that "non-interactive" can be a synonym for "automated" in this context. Further, we might argue that canonical examples of "interactive" use…

> The implication of this conditional reward is that non-interactive use presents more/easier attack opportunities than interactive use.

Doesn't this mean the opposite?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#24
post #20

"Another $500,000 will be given to those who can find a "network attack requiring no user interaction."" The implication of this conditional reward is that interactive use presents more/easier attack opportunities than non-interactive use. To clarify terminology, it is arguable that "non-interactive" can be a synonym for "automated" in this context. Further, we might argue that canonical examples of "interactive" use…

This seems backwards.... they are offering more money for attacks that don't require user interaction because they are HARDER, not easier, to accomplish.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#25

Earlier quoted context omitted.

No, it’s hackers. The same folks who have been releasing jailbreaks. Professors haven’t been finding ios 0days. I’d say that the researchers have a pretty strong incentive not to screw around with Apple. It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.

You really think Apple is just going to gives special dev devices to random hackers from the Internet?

Note that random hackers from the internet already have access to these devices.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#26

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

From the article: >Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone. So that's already more than what Apple offers. I tend to think they'll always be outbid.

Governments are strong. Wow.

I forget the influence until I see things like this.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#28
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

There's going to be an equilibrium here dictated by how much Apple itself is willing to pay for bugs. If Apple pays more then presumably more bugs will get reported which makes the remaining unreported bugs much more valuable since they'll be relatively rare.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#29

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

Worth adding that clean money is worth more than dirty money

If the money is directly from the government, is it really dirty money?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#30
post #5
post #2

Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-rem... ?

From the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?

The article also had

> Another $500,000 will be given to those who can find a “network attack requiring no user interaction.”

which I believe many of her vulnerabilities are definitely eligible for. I read that article from https://news.ycombinator.com/item?id=20639999 yesterday, and she had this paragraph as her second

> Vulnerabilities are considered ‘remote’ when the attacker does not require any physical or network proximity to the target to be able to use the vulnerability. Remote vulnerabilities are described as ‘fully remote’, ‘interaction-less’ or ‘zero click’ when they do not require any physical interaction from the target to be exploited, and work in real time. I focused on the attack surfaces of the iPhone that can be reached remotely, do not require any user interaction and immediately process input. [0]

The full $1 million is for that level of fully remote attack, but against the kernel. I'd have to look up to see if any of the code she found vulnerabilities in are part of the iOS kernel.

[0] https://googleprojectzero.blogspot.com/2019/08/the-fully-rem...

Post reply on HN