Live data from Hacker News

Million Dollar iOS9 Bug Bounty

zerodium.com

1–10 of 80 posts

Re: Million Dollar iOS9 Bug Bounty

#2
I for one actually feel much more secure knowing that iOS is so secure that $1 million is considered the public value of an exploit. Vupen bought flash zero days for $30,000 in the past so knowing that iOS exploits are now valued enough to attract this kind of bounty makes me much more confident script kiddies and scammers will not be able afford to attack me. And lets face it, we were never secure from the NSA in the first place...

Re: Million Dollar iOS9 Bug Bounty

#3
The exploit/jailbreak must support and work reliably on the following devices (32-bit and 64-bit when applicable): - iPhone 6s / iPhone 6s Plus / iPhone 6 / iPhone 6 Plus - iPhone 5 / iPhone 5c / iPhone 5s - iPad Air 2 / iPad Air / iPad (4rd generation) / iPad (3th generation) / iPad mini 4 / iPad mini 2

So did i read this correct and the exploit must be backwards compatible in order to get the full bounty?

Re: Million Dollar iOS9 Bug Bounty

#4
post #3

The exploit/jailbreak must support and work reliably on the following devices (32-bit and 64-bit when applicable): - iPhone 6s / iPhone 6s Plus / iPhone 6 / iPhone 6 Plus - iPhone 5 / iPhone 5c / iPhone 5s - iPad Air 2 / iPad Air / iPad (4rd generation) / iPad (3th generation) / iPad mini 4 / iPad mini 2 So did i read this correct and the exploit must be backwards compatible in order to get the full bounty?

Seems to just be a list of iOS 9 supported devices...

Re: Million Dollar iOS9 Bug Bounty

#5
post #2

I for one actually feel much more secure knowing that iOS is so secure that $1 million is considered the public value of an exploit. Vupen bought flash zero days for $30,000 in the past so knowing that iOS exploits are now valued enough to attract this kind of bounty makes me much more confident script kiddies and scammers will not be able afford to attack me. And lets face it, we were never secure from the NSA in th…

This is purely market value. If iOS simply had less users, the price would be lower. So I think your conclusion of it being more secure because of this is incorrect.

About less people being able to afford it - this again depends on what ZERODIUM intends to do with it. They may sell it for cheap and count on a large number of sales because, again, iOS is so popular.

Re: Million Dollar iOS9 Bug Bounty

#6
post #3

The exploit/jailbreak must support and work reliably on the following devices (32-bit and 64-bit when applicable): - iPhone 6s / iPhone 6s Plus / iPhone 6 / iPhone 6 Plus - iPhone 5 / iPhone 5c / iPhone 5s - iPad Air 2 / iPad Air / iPad (4rd generation) / iPad (3th generation) / iPad mini 4 / iPad mini 2 So did i read this correct and the exploit must be backwards compatible in order to get the full bounty?

"backwards compatible" how? iOS 9 runs on all of those devices, so they're just saying it has to be hardware agnostic.

Re: Million Dollar iOS9 Bug Bounty

#7
post #4
post #3

The exploit/jailbreak must support and work reliably on the following devices (32-bit and 64-bit when applicable): - iPhone 6s / iPhone 6s Plus / iPhone 6 / iPhone 6 Plus - iPhone 5 / iPhone 5c / iPhone 5s - iPad Air 2 / iPad Air / iPad (4rd generation) / iPad (3th generation) / iPad mini 4 / iPad mini 2 So did i read this correct and the exploit must be backwards compatible in order to get the full bounty?

Seems to just be a list of iOS 9 supported devices...

Thanks. Make sense. I was confused as it not list devices that also support iOS9 like the iPad mini 3.

Re: Million Dollar iOS9 Bug Bounty

#8
post #2

I for one actually feel much more secure knowing that iOS is so secure that $1 million is considered the public value of an exploit. Vupen bought flash zero days for $30,000 in the past so knowing that iOS exploits are now valued enough to attract this kind of bounty makes me much more confident script kiddies and scammers will not be able afford to attack me. And lets face it, we were never secure from the NSA in th…

This is purely market value. If iOS simply had less users, the price would be lower. So I think your conclusion of it being more secure because of this is incorrect. About less people being able to afford it - this again depends on what ZERODIUM intends to do with it. They may sell it for cheap and count on a large number of sales because, again, iOS is so popular.

I disagree. Less users also mean low price for bounty since the media is not paying attention. It is a fair conclusion that a reward as big as $1M is imposed since it has been proven (so far) that iOS platform is quite secure.

Re: Million Dollar iOS9 Bug Bounty

#9
post #2

I for one actually feel much more secure knowing that iOS is so secure that $1 million is considered the public value of an exploit. Vupen bought flash zero days for $30,000 in the past so knowing that iOS exploits are now valued enough to attract this kind of bounty makes me much more confident script kiddies and scammers will not be able afford to attack me. And lets face it, we were never secure from the NSA in th…

This is purely market value. If iOS simply had less users, the price would be lower. So I think your conclusion of it being more secure because of this is incorrect. About less people being able to afford it - this again depends on what ZERODIUM intends to do with it. They may sell it for cheap and count on a large number of sales because, again, iOS is so popular.

Yeah I was suggesting this may even be below market value as selling to Vupen is probably considered more acceptable than selling on the black market for a likely even higher price.

With regards to users flash player has more users than iOS but the exploit was cheaper, while these users might not be as valuable as iOS users neither market is what you would consider small.

And finally it's unlikely they would sell it to mass users for extremely cheap and risk it leaking. It's probably more out of desperation, Vupen has heaps of long term customers who they have promised the ability to hack phones to, it's probably embarrassing to them if they can't hack them most popular phone model out there.

Post reply on HN