>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…
I forget who, but someone made a comment about this a long time ago that stuck with me. We often say, "They'll just sell all these 0 days on the black market." but honestly that's not like a literal market, and you have to make a lot of compromises to not only your own integrity, but also to your safety and ability to stay out of jail if you do something like that. I wish I remembered the specifics of the comment, bu…
Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
31–40 of 308 posts
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#32Earlier quoted context omitted.
Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…
From the article: >Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone. So that's already more than what Apple offers. I tend to think they'll always be outbid.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#33Earlier quoted context omitted.
Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…
Worth adding that clean money is worth more than dirty money
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#34"Another $500,000 will be given to those who can find a "network attack requiring no user interaction."" The implication of this conditional reward is that interactive use presents more/easier attack opportunities than non-interactive use. To clarify terminology, it is arguable that "non-interactive" can be a synonym for "automated" in this context. Further, we might argue that canonical examples of "interactive" use…
This seems backwards.... they are offering more money for attacks that don't require user interaction because they are HARDER, not easier, to accomplish.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#35Earlier quoted context omitted.
You really think Apple is just going to gives special dev devices to random hackers from the Internet?
Note that random hackers from the internet already have access to these devices.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#36Earlier quoted context omitted.
Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…
From the article: >Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone. So that's already more than what Apple offers. I tend to think they'll always be outbid.
Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#37Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#38Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#39Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone
#40Earlier quoted context omitted.
Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…
Worth adding that clean money is worth more than dirty money