Live data from Hacker News

Million Dollar iOS9 Bug Bounty

zerodium.com

61–70 of 80 posts

Re: Million Dollar iOS9 Bug Bounty

#62
post #48
post #36

And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.

If I had a bug that met the criteria I'd give Apple first dibs. That way the bug would get fixed, and I'd still get my $1M.

Ask Apple for some freebies and call it a day.

Re: Million Dollar iOS9 Bug Bounty

#64
post #58

Earlier quoted context omitted.

If the last 8 versions were jailbreakable I think this one will be too - eventually - but it is certainly the case that devices are becoming more secure both for and against their owners. The tension between freedom and security is definitely increasing.

But who's going to release one publically when they can get $1 million for not doing so?

You can only get a million for a really impressive jailbreak. If it involves plugging the phone into your computer and downloading something, or even just pushing a button, it doesn't qualify for this bounty.

Re: Million Dollar iOS9 Bug Bounty

#65
post #47
post #35

Earlier quoted context omitted.

Stagefright (Remote Android code execution) does exactly that http://arstechnica.com/security/2015/07/950-million-android-...

Stagefright was not a rootable exploit.

Not alone, but as part of a chain of exploits (which is what most jailbreaks are, and which is what this document expressly asks for), certainly it is: it allows you to get arbitrary code execution on the device, which can be paired with a kernel exploit (something that has been comparatively quite common) to get root. I mean, this same argument can be said about the individual components of JailbreakMe 2.0 and 3.0: the initial exploit in FreeType only just barely got you the ability to run code as Safari within its even-at-the-time relatively restricted sandbox: it was then paired with a kernel exploit to finish the jailbreak. Zimperium actually did a demo on stage at BlackHat of using Stagefright as the vector to push a privilege escalation (probably some old kernel exploit; I think they said, but I don't remember) to the device, and they have also posted a video of that process.

https://www.youtube.com/watch?v=PxQc5gOHnKs

Re: Million Dollar iOS9 Bug Bounty

#67
A million bucks for a iOS 9 vulnerability sounds nice. But is that worth having the death, imprisonment, or torture of possibly innocent people on your conscience? If a government is buying these vulns, there is no telling what they will do with them.

Re: Million Dollar iOS9 Bug Bounty

#68

Sounds like ios8 will be the last jailbreakable version. Shame.

I am under the impression that the large companies in China (the equivalents of Google, Microsoft, and Ebay/PayPal), who have essentially been funding the jailbreaks of iOS 7 and 8, have been paying quite hefty sums as well (if not a million dollars, then I would argue "close enough" that even people who only see "sort of a problem" with selling weaponized exploits to arms dealers might still value the ethical advantages of a public release at least highly enough to cover the marginal utility of the price difference), as they use them as part of a proxy war to "control mobile" by providing an alternative App Store (with actual "Apps", unlike Cydia) for Chinese users; so like, this might change the game slightly, and I do know people in our community whose hats are sufficiently dark that they would be swayed by this, but it isn't a done deal or anything.

(Further, I will point out that most jailbreaks don't even involve a remote and silent deployment: while there are tons of possible exploitable bugs found in WebKit all the time, Apple has sandboxed the living daylights out of that process, and a lot of the kernel bugs people find don't work even in processes that have the lightest of sandboxes. The standard stack for a jailbreak is usually something that requires the device to be pincode unlocked and plugged into a computer that the device has been told to "trust", in order to take advantage of the attack surface provided by the protocols iTunes and Xcode use to talk to the device over USB, which often will touch the filesystem in complex ways, at least indirectly if not directly as part of something like "restore a backup". If you find this kind of limited stack, you usually don't just "throw it back" and keep fishing ;P.)

Re: Million Dollar iOS9 Bug Bounty

#69
post #38
post #4

Earlier quoted context omitted.

Seems to just be a list of iOS 9 supported devices...

iPhone 4s can run iOS 9 and is not on the list.

iPhone 4s is out of official support as soon as the iPhone 6s is released to market.

they always give users the 'last' iOS version but I highly doubt any work will go into patching it in future.

Re: Million Dollar iOS9 Bug Bounty

#70
post #36

And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.

It's a win-win for Zerodium. They are getting free publicity for having the biggest bug bounty ever, and if somebody actually does submit a working exploit, they sell it to their clients for a hefty profit. I'm sure there are government agencies that would pay well over a million for the ability to infect any IOS device silently and easily.

I don't see why someone wouldn't sell it to them, collect the bounty, and then either release/sell it themselves. It seems like Zerodium would have very little recourse.
Post reply on HN