Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

271–280 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#272
post #242
post #190

Earlier quoted context omitted.

Your argument is limited to technical and political science concepts, and by limiting itself so, is correct. It is inapplicable to the real world. Governments have used zero days. Most famously to use a zero day unlock an iPhone against a terrorist (whose house was ransacked by the news media). Less famously was to botch a legal case against a pedophile (amazingly, it would be possible to find and arrest nearly all p…

I’m sorry, I don’t understand.

I Googled for grugq, iCloud, and terrorist, and yielded the below link:

https://medium.com/@thegrugq/feeble-noise-pollution-627acb59...

>Farook destroyed his personal phone. The FBI wants access to his work phone. UPDATE: FBI locked themselves out of the iCloud account after it was seized.

>FBI already has huge amounts of data from the telco and Apple. This is almost certainly enough to rule out clear connection with any other terrorists.

>FBI is playing politics, very cynically and very adroitly.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#273

Earlier quoted context omitted.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

I'd imagine this is to combat marketplaces like zerodium and the deep web. Traditionally grey hat hackers don't always go through bug bounty programs because the pay is awful compared to what you can get through less ethical sources. By flexing that much cash at bug hunters, they are potentially now offering even more than what you could get on the mentioned markets. The only reason people go underground to sell expl…

> I'd imagine this is to combat marketplaces like Zerodium

Zerodium already pays double what Apple does. Where's the incentive?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#274
post #272
post #242

Earlier quoted context omitted.

I’m sorry, I don’t understand.

I Googled for grugq, iCloud, and terrorist, and yielded the below link: https://medium.com/@thegrugq/feeble-noise-pollution-627acb59... >Farook destroyed his personal phone. The FBI wants access to his work phone. UPDATE: FBI locked themselves out of the iCloud account after it was seized. >FBI already has huge amounts of data from the telco and Apple. This is almost certainly enough to rule out clear connection with…

Ok. I'm still unclear on your point.

You are referencing cases where exploits were in the news. What does that have to do with vulnerability markets?

Are you saying that the IC used exploits only twice? And they were misused both times? What does that have to do with vulnerability markets?

I'm sorry, but I'm utterly lost. Can you please clarify?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#276
post #274
post #272

Earlier quoted context omitted.

I Googled for grugq, iCloud, and terrorist, and yielded the below link: https://medium.com/@thegrugq/feeble-noise-pollution-627acb59... >Farook destroyed his personal phone. The FBI wants access to his work phone. UPDATE: FBI locked themselves out of the iCloud account after it was seized. >FBI already has huge amounts of data from the telco and Apple. This is almost certainly enough to rule out clear connection with…

Ok. I'm still unclear on your point. You are referencing cases where exploits were in the news. What does that have to do with vulnerability markets? Are you saying that the IC used exploits only twice? And they were misused both times? What does that have to do with vulnerability markets? I'm sorry, but I'm utterly lost. Can you please clarify?

I can’t clarify, I can only make disparaging statements saying the government hires incompetent people who can’t notice corruption in front of them, as a side result they mishandle everything and their bosses must work overtime not only to hide corruption from the public but to spin their employees incompetence as reasons to reduce the public’s civil liberties.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#277
post #38

What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

Before this, some people complained that Apple’s bug bounty rewards were too low. Now they’re higher and a different set of people are complaining that they only did it for PR. It seems like a bit of a “damned if you do, damned if you don’t” scenario.

It’s true that Apple pins its rewards to specific outcomes, but I think a lot of bug bounty programs do something like this. For instance, Google’s top bounty for Android ($200k) is only awarded if you can provide an exploit compromises that the trusted execution environment (see https://www.google.com/about/appsecurity/android-rewards/).

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#278

Earlier quoted context omitted.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

When I read the article my first reaction was "Only a million?" Considering the importance of a bug like this to Apple's business and the size of their cash hoard, this sounds like they don't actually care that much.

I know some security companies have higher payouts, but do any manufacturers? As far as I can tell, Google’s highest bounty for an Android exploit is $200k. Apple will pay up to $1.5m if you can hack the kernel in a prerelease version of iOS. Zerodium tops out at $2m.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#279

Earlier quoted context omitted.

You're conflating an exploit for a narrow bug target class with a malware package which likely contains one or more exploits and probably a payload. The act of exploiting requires much more than an exploit alone to have the desired effect.

What's meant is that real exploits require one to get RCE, another to break sandbox, another for privilege escalation.

Also maybe an infoleak to set up the RCE.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#280
post #277

Earlier quoted context omitted.

Is not Apple's move mostly a PR stunt? Standard people will read "The iPhone is so secure that Apple is willing to pays $1M for somebody that find a security vulnerability." The reality is that they only pay that much for bugs in the kernel that do not require a user interaction. Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order t…

Before this, some people complained that Apple’s bug bounty rewards were too low. Now they’re higher and a different set of people are complaining that they only did it for PR. It seems like a bit of a “damned if you do, damned if you don’t” scenario. It’s true that Apple pins its rewards to specific outcomes, but I think a lot of bug bounty programs do something like this. For instance, Google’s top bounty for Andro…

Does it really matter if it's for PR or not? It seems to me like Apple is hitting two birds with one stone.
Post reply on HN