Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

221–230 of 318 posts

Re: We Hacked Apple for 3 Months

#221

Bug bounties have always been mispriced. Either the damage estimates for a given bug are wildly over-estimated by risk analysts, or the price paid to find them is based on some kind of stupidity-arbitrage play. I think it's the latter. Consulting firms bill between $1500-$2500/day for senior staff. 2 hackers for 10 days could be the $50k they got paid. Instead, this crew used 5 hackers for say 45 days, or 225 person…

Hi hi! Speaking as both a bug bounty vet, and a consulting vet (I run includesecurity.com), here's my .02 on some things you may not have considered given your comment.

1) Sam and the other hackers did not do this as a full time gig, they primarily do this as moonlighting from their full time jobs (you can verify this on LinkedIn)

2) Consultants are often given tight scopes, and these artificial client-driven constraints often prevent consultants from identifying similar findings as Sam and crew found.

3) Bug bounties provide no defined level of assurance. They found an SSRF, but it is a very real possibility that somebody in their crew (or an individual bug hunter) doesn't have experience in that particular topic and Apple would have never been the wiser. In a bug bounty you're at the whim of the crowd's varying skills and interests. You can game this by offering larger bounties, but you can't pre-define a scope or level of assurance.

4) They've gotten paid ~$50k thus far for four bugs, if you read the article they mention they'll very likely be getting paid more. I'd be surprised if their total payout isn't six figures when all is said and done.

5) Your stated rate for consulting firms charge for a particular role is correct for the US market, but the level of "seniority" in a senior consultant varies wildly. Many large firms will undeservedly give somebody with two years experience the title "senior", regardless of actual skillset.

6) You state "a group of amateurs will do better work", first point is to note these five are not amateurs in any way! They're in the top 1% of global bug bounty hackers. Second it seems like you're defining "better" as "finds more vulnerabilities from a blackbox bug bounty perspective". I find that client's IRL don't define things in the same way you've done here.

7) "but over the years I've found that the difference in the security world is that you hire a small shop to discover the truth about risks, but you pay a big firm to lie about them." This I couldn't agree with you more on, it is MIND BOGGLING to me that firms with no ethics, actual standards, or transparency are the top firms in the security assessment/pentesting space. For an industry that proports to hate snake oil security, we sure are comfortable with a ton of snake oil security assessments.

8) This industry needs standards, for-profit old boys clubs are not the way https://www.theregister.com/2020/08/11/ncc_group_crest_cheat... And the grass roots/non-profit approach also failed due to lack of advocacy, adoption, and persistent leadership. http://www.pentest-standard.org/index.php/Main_Page

I'd love to see a world where Bug Bounties and full security assessments can live harmoniously and people do flip out declaring one or the other service totally useless all the damn time.

Re: We Hacked Apple for 3 Months

#222

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

Late reply: They just paid for 28 more issues, running total is now $288,500.

https://twitter.com/samwcyo/status/1314310787243167744

Re: We Hacked Apple for 3 Months

#223

Earlier quoted context omitted.

End of the post it says 51k so far. I'd expect the price to go up a LOT more, because otherwise the sane (monetary) advice becomes "report some vulnerabilities to apple, and then keep finding them and sell them to third parties".

Yeah, that is only for 4 vulnerabilities out of 55. And 3 of them were only "High." They still have 10 (!!) more critical vulnerabilities they may receive payment on. Also, they state in the article: "However, it appears that Apple does payments in batches and will likely pay for more of the issues in the following months."

Update: They just paid for 28 more issues, running total is now $288,500.

https://twitter.com/samwcyo/status/1314310787243167744

Re: We Hacked Apple for 3 Months

#224

Earlier quoted context omitted.

10 person months would be 10/12ths of a programmer salary i Silicon Valley, which would probably be around $200k

> 10 person months would be 10/12ths of a programmer salary i Silicon Valley, which would probably be around $200k To my mind, this team deserves a higher salary than typical Silicon Valley programmers for this work.

FWIW Typical SV programmers don't make anything like 200k/yr, so they are already above that range even if there aren't more payouts...

Re: We Hacked Apple for 3 Months

#225

Earlier quoted context omitted.

Not seeing Apple claiming only they can protect user's privacy. Instead the article quotes Tim Cook trying to pressure the governments t recognize privacy as a fundamental human right.

> Not seeing Apple claiming only they can protect user's privacy You would if you had watched the commercial.

I watched the video, still didn't seen any claims that only Apple can protect a user's privacy. You must be reading between the lines where I am not.

Re: We Hacked Apple for 3 Months

#226

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

How is North Korea going to recruit top cybersecurity specialists?

Re: We Hacked Apple for 3 Months

#227

Apple only paid them $52k? Apple is a trillion dollar company. These hackers saved them easily millions of dollars in expenses. China or North Korea could easily allocate a much larger team to something like this and disrupt Apple (not for bug bounties). Although, China and North Korea dedicate their resources to financial fraud where there is real money to be had. Apple is a tightwad joke. If they laid out a scope o…

How is North Korea going to recruit top cybersecurity specialists?

It's a country of over 50 million people, all of whom are beholden to their government.

They have all the top cybersecurity specialists they could ever need.

Re: We Hacked Apple for 3 Months

#229

Earlier quoted context omitted.

How is North Korea going to recruit top cybersecurity specialists?

It's a country of over 50 million people, all of whom are beholden to their government. They have all the top cybersecurity specialists they could ever need.

The population of North Korea is only 25M and 43% of them are malnourished and only a small percentage have access to the internet.

https://globalnews.ca/news/5029484/north-korea-malnutrition-...

Number of security researchers isn't a function of population size it is a function of population size * fraction with propensity to show requisite skill * fraction who go to work in the profession.

Shockingly adding millions of more starving people who have never seen a computer doesn't get you many more cybersecurity specialists.

Re: We Hacked Apple for 3 Months

#230
post #205

Earlier quoted context omitted.

Not just saved Apple, but Apple users too. Wasn’t the “fappening” rooted in hacked iCloud accounts with weak credentials? Imagine what juicy political targets are out there using iPhones syncing with iCloud.

iCloud wasn't cracked. They used social engineering to gain access to the accounts.

You're right iCloud itself wasn't "cracked", per se, but the XSS exploit is (was) incredibly malicious and did not require any social engineering that I can see.

https://samcurry.net/hacking-apple/#vuln3

Post reply on HN