Live data from Hacker News

We Hacked Apple for 3 Months

samcurry.net

311–318 of 318 posts

Re: We Hacked Apple for 3 Months

#311
post #202
post #173

Earlier quoted context omitted.

"Participating" covers a broad range of activity when it comes to this program, and would include things like having a portal to provide the legally mandated info that must be returned upon proper presentation of a warrant. Is it really 'sharing data with the government' if the latter shows up with a properly executed warrant for the data?

PRISM data is obtained without a warrant, even for USians whose data is supposed to be protected by a warrant, because of a special secret interpretation of the FISA Amendments Act (FAA) Section 702. It's warrantless, and the court that decides whether or not it's legal is itself classified and unaccountable and almost never denies surveillance. This abuse was cited by Ed Snowden as one of the reasons he came forward…

Section 702 only allows them to request data from accounts that belong to foreigners outside the US, so no, it doesn't allow the US intelligence community to surveil everyone in the legislature and judiciary.

Re: We Hacked Apple for 3 Months

#312

Earlier quoted context omitted.

> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM) From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you…

PRISM absolutely was about tech companies sharing data with the government. From the PRISM Wikipedia article[1]: > The documents identified several technology companies as participants in the PRISM program, including Microsoft in 2007, Yahoo! in 2008, Google in 2009, Facebook in 2009, Paltalk in 2009, YouTube in 2010, AOL in 2011, Skype in 2011 and Apple in 2012. [1] https://en.wikipedia.org/wiki/PRISM_(surveillance_…

The documents don't identity them as "participants." They only say when data from those company was ingested into PRISM, which is simply a data integration program between the NSA and the FBI. The FBI's Data Intercept Technology Unit is clearly labeled in the slides.

The government issues a Section 702 order for some account(s) data, the company reviews the request and denies it if the account appears to belong to somebody in the US or an American (both of which cannot have their data requested via a Section 702 order), and then sets up a forward to the FBI. PRISM then geta that data from the FBI and parses it into fields for various NSA databases. Again, this is very clearly drawn out in the system diagram slide that Snowden leaked.

Re: We Hacked Apple for 3 Months

#313

It really goes to show Apple Advertising has no basis in reality. "Security" claims are obviously debunked on a weekly basis if you work in tech. "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM). You bet Apple will sell your privacy if the deal is good enough. That being said, I don't think anything can be secure, we must treat everything as potentially compromised and…

> "Privacy" claims are just as nonsensical as we've seen Apple bend to multiple governments (PRISM) From everything I have seen, PRISM wasn't about companies cooperating. It was about literally hardware splicing the fiber lines between FAANG type corp datacenters and taking that info. Google famously was using dark fiber unencrypted and started encrypting that traffic between DCs because of it. It just so happens you…

No, that is upstream collection, which is separate from PRISM.

Re: We Hacked Apple for 3 Months

#314
post #274
post #273

Earlier quoted context omitted.

In the instance yes, but bounty programs need to be sustainable so parameters are set up front. Folks can choose to participate or not. If they don't like the offering, they can find something else.

Bounty programs are in place so that bad actors are not the only ones on the lookout for bugs. If experts get paid pennies for finding enormous security vulnerabilities, what's stopping them from selling them to actually bad actors for a potentially much greater cut? I can imagine that someone would be willing to pay far more than $5M to gain access to Apple wharehouses.

[deleted]

Re: We Hacked Apple for 3 Months

#315
post #233

I think what might not be immediately obvious to people outside of the bug bounty scene is that Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes represent some of the best bug bounty hunters out there which is definitely one of the reasons they absolutely pwnd Apple here. I would be genuinely shocked if Apple doesn't end up paying out much more for all the bugs found. Frankly, it would be gen…

"Within the article I'd mentioned that Apple had not yet paid for all of the vulnerabilities. Right after publishing it, they went ahead and paid for 28 more of the issues making the running total $288,500" https://twitter.com/samwcyo/status/1314310787243167744

> They went ahead and paid for 28 more of the issues making the running total $288,500"

That's barely the yearly cost of one generic software engineer at Apple.

I was expecting multiple millions in payment given the severity and quantity of vulnerabilities found. State actors could easily 10x that amount legaly through gov contractors.

Re: We Hacked Apple for 3 Months

#316

Earlier quoted context omitted.

In the article he says they invested "a few hundred hours"... I take that to be around 350 hours - $147/hr... still not a lot for speculative research

you missed a word: "we each ended up putting a few hundred hours into it." So the 20-30$ per hour figure is closer, before taxes, with zero benefits like health, dental or pension plans. They themselves say: bounty hunting is not a job

Good catch

Re: We Hacked Apple for 3 Months

#317
post #202

Earlier quoted context omitted.

PRISM data is obtained without a warrant, even for USians whose data is supposed to be protected by a warrant, because of a special secret interpretation of the FISA Amendments Act (FAA) Section 702. It's warrantless, and the court that decides whether or not it's legal is itself classified and unaccountable and almost never denies surveillance. This abuse was cited by Ed Snowden as one of the reasons he came forward…

Section 702 only allows them to request data from accounts that belong to foreigners outside the US, so no, it doesn't allow the US intelligence community to surveil everyone in the legislature and judiciary.

[deleted]

Re: We Hacked Apple for 3 Months

#318
post #274
post #273

Earlier quoted context omitted.

In the instance yes, but bounty programs need to be sustainable so parameters are set up front. Folks can choose to participate or not. If they don't like the offering, they can find something else.

Bounty programs are in place so that bad actors are not the only ones on the lookout for bugs. If experts get paid pennies for finding enormous security vulnerabilities, what's stopping them from selling them to actually bad actors for a potentially much greater cut? I can imagine that someone would be willing to pay far more than $5M to gain access to Apple wharehouses.

Legal risk. You can make a quick safe buck from selling the fix to Apple or you can risk some trouble for selling it to criminals.
Post reply on HN