Live data from Hacker News

Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

forbes.com

31–40 of 308 posts

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#31
post #3

>Forbes also revealed on Monday that Apple was to give bug bounty participants "developer devices" - iPhones that let hackers dive further into iOS. They can, for instance, pause the processor to look at what's happening with data in memory. Krstić confirmed the iOS Security Research Device program would be by application only. It will arrive next year. I wonder how they're going to manage this. I could easily see so…

I forget who, but someone made a comment about this a long time ago that stuck with me. We often say, "They'll just sell all these 0 days on the black market." but honestly that's not like a literal market, and you have to make a lot of compromises to not only your own integrity, but also to your safety and ability to stay out of jail if you do something like that. I wish I remembered the specifics of the comment, bu…

Selling bugs and exploits is not illegal just about everywhere, so there is really no risk. Plus, law enforcement and intelligence agencies, or their contractors, are the ones buying on the “black market”. Nobody has to worry about jail for knowing about a mistake that Apple made in their code and telling someone else.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#32

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

From the article: >Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone. So that's already more than what Apple offers. I tend to think they'll always be outbid.

Apologies, I did fail to RTFA in this case. Thankyou!

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#33

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

Worth adding that clean money is worth more than dirty money

Kind of what I meant by "Especially considering the lower legal risk" but I guess there's the specific cost of laundering it too. A good point!

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#34
post #20

"Another $500,000 will be given to those who can find a "network attack requiring no user interaction."" The implication of this conditional reward is that interactive use presents more/easier attack opportunities than non-interactive use. To clarify terminology, it is arguable that "non-interactive" can be a synonym for "automated" in this context. Further, we might argue that canonical examples of "interactive" use…

This seems backwards.... they are offering more money for attacks that don't require user interaction because they are HARDER, not easier, to accomplish.

Exactly. I seem to remember an app a while back that was billed as a heartbeat reader and it would have you repeatedly press and release the fingerprint sensor. After a delay it would flash some sort of in-app purchase authorization. Pwnage that relies on some sort of user interaction is worth 50% less, and rightly so.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#35

Earlier quoted context omitted.

You really think Apple is just going to gives special dev devices to random hackers from the Internet?

Note that random hackers from the internet already have access to these devices.

In the form of stolen red board or internal testing iPhones or something else?

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#36

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

From the article: >Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone. So that's already more than what Apple offers. I tend to think they'll always be outbid.

[deleted]

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#37
post #35

Earlier quoted context omitted.

Note that random hackers from the internet already have access to these devices.

In the form of stolen red board or internal testing iPhones or something else?

Yeah, they're just buying dev-fused devices.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#38
What Apple is doing here is really smart. An under-appreciated wrinkle is that grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid. Apple isn't just bidding against the brokers and IC in lump-sum payments, but also encouraging people to submit bugs early, before they're operationally valuable for bad actors.

Re: Apple Confirms $1M Reward for Anyone Who Can Hack an iPhone

#40

Earlier quoted context omitted.

Isn't the idea of a bug bounty at this scale that the monetary reward (especially combined with the lowered legal risk, but also when considered in isolation) is higher from reporting it to the vendor than from selling it on the black market? I.E. presumably Apple has done their research and one million dollars is more than they believe you'd getting selling a zero day to somebody else. I don't work in the security f…

Worth adding that clean money is worth more than dirty money

Are there any laws you bump into selling 0-days? Honest question, I know their are laws about the actual hacking part but is it illegal to sell the payload? Obviously this is ethically dirty money I just was curious if it's actually dirty money in a criminal sense.
Post reply on HN