Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

21–30 of 318 posts

Re: We Hacked Apple for 3 Months

#22
Am I being hyperbolic or is this an absolutely enormous compromise of trust in Apple? XSS in iCloud Email allowing for data exfiltration of emails, pictures, videos??? That's absolutely insane. It just comes to show how vulnerable we all are to exploits like this, especially if you're a notable person of interest.

Re: We Hacked Apple for 3 Months

#23

Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?

> Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have? And Russia, and Iran, and so on... It seems safe to assume someone else out there found at least one of these and got in to the Apple internal network and has been quietly doing their job, whatever it may be.

And sends a request to an external C&C server... once a year-ish, just in case the ingress route is closed.

Re: We Hacked Apple for 3 Months

#24
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

Exactly.

The amount of effort put into finding multiple critical - high vulnerabilities of a $1TN+ company and the result is $51k + taxes to possibly share between 5 hackers for 4 qualifying bugs for that bounty sounds like Apple took them for a cheap ride through their campus.

Compared to 1 hacker, 1 month, JWT signature check failure = 100k from Apple [0]:

[0] https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-a...

Re: We Hacked Apple for 3 Months

#26

Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?

I had the same thought. Really basic front end web vulnerabilities right in HTML response. One can only speculate on the state of Apple's web hosts' ip filtering, rate limiting, ddos protection, etc.

Re: We Hacked Apple for 3 Months

#27

Jesus, that prebaked password on the Jive platform was really bad. Especially as one could ultimately access nearly the entirety of Apple's internal network from that. Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have?

> Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have? And Russia, and Iran, and so on... It seems safe to assume someone else out there found at least one of these and got in to the Apple internal network and has been quietly doing their job, whatever it may be.

Any of those countries could just get someone hired at Apple for that

Re: We Hacked Apple for 3 Months

#28
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

If they actually did get paid so little, why did they do it? This seems like a terrible use of their time.

Qualifying people for highly paid info security positions is shockingly broken right now. No one who knows what they are doing cares about credentials you can get from a training program or school, but they also complain constantly about how hard it is to find and hire qualified people. The result is: there is a lot of salary out there for people who can figure out how to get it.

Developing exploits that are acknowledged by major targets--even if done freelance or as a hobby--is one of the few ways to gain lines on your resume that everyone in the security field will pay attention to.

Re: We Hacked Apple for 3 Months

#29
post #27

Earlier quoted context omitted.

> Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have? And Russia, and Iran, and so on... It seems safe to assume someone else out there found at least one of these and got in to the Apple internal network and has been quietly doing their job, whatever it may be.

Any of those countries could just get someone hired at Apple for that

Why not both so as to protect your assets.

Re: We Hacked Apple for 3 Months

#30
post #3

July 6 - August 6 - September 6 -- that's 2 months elapsed, not three. Five people working for 2 months is 10 person-months. Apple paid them just under $52,000, none of which was guaranteed. They had to pay whatever taxes are appropriate for their jurisdictions. I'd say Apple got an amazing bargain.

i had expected that Appple might have paid a million to him.
Post reply on HN