7 ms·
Million Dollar iOS9 Bug Bounty
- ck2 11y agoHas anyone tried a really long password ;-)
- z02d 11y agoMMD :D
- alexivanovs 11y ago
- stirlo 11y agoI for one actually feel much more secure knowing that iOS is so secure that $1 million is considered the public value of an exploit. Vupen bought flash zero days for $30,000 in the past so knowing that iOS exploits are now valued enough to attract this kind of bounty makes me much more confident script kiddies and scammers will not be able afford to attack me. And lets face it, we were never secure from the NSA in the first place...
- MatekCopatek 11y agoThis is purely market value. If iOS simply had less users, the price would be lower. So I think your conclusion of it being more secure because of this is incorrect. About less people being able to afford it - this again depends on what ZERODIUM intends to do with it. They may sell it for cheap and count on a large number of sales because, again, iOS is so popular.
- xoail 11y agoI disagree. Less users also mean low price for bounty since the media is not paying attention. It is a fair conclusion that a reward as big as $1M is imposed since it has been proven (so far) that iOS platform is quite secure.
- stirlo 11y agoYeah I was suggesting this may even be below market value as selling to Vupen is probably considered more acceptable than selling on the black market for a likely even higher price. With regards to users flash player has more users than iOS but the exploit was cheaper, while these users might not be as valuable as iOS users neither market is what you would consider small. And finally it's unlikely they would sell it to mass users for extremely cheap and risk it leaking. It's probably more out of desperation, Vupen has heaps of long term customers who they have promised the ability to hack phones to, it's probably embarrassing to them if they can't hack them most popular phone model out there.
- w23j 11y agoHacking Team: a zero-day market case study [1] seems to support the idea that iOS exploits are scarce. Especially compared to Android (when using your "less users" perspective). "Mobile: VUPEN offered several different remote code execution and local privilege escalation exploits for Android; however, not all of them were 0day and Hacking Team deemed that the prices were too high to purchase. Though there was interest in purchasing exploits for iOS, VUPEN said they were limited to certain customers, presumably high-paying government agencies." [1] "iOS exploit pricing: Adriel stated he was supply-constrained for iOS RCE exploits because exploit developers frequently had their own connections to sell them, and that he believed that such exploits were overpriced. An exclusive exploit sale could cost over a million dollars, [...]." [1] [1] https://news.ycombinator.com/item?id=9949818 https://news.ycombinator.com/item?id=9949818
- jgome 11y agoDid you read the announcement? > Apple iOS, like all operating system, is often affected by critical security vulnerabilities, however due to the increasing number of security improvements and the effectiveness of exploit mitigations in place, Apple's iOS is currently the most secure mobile OS. But don't be fooled, secure does not mean unbreakable, it just means that iOS has currently the highest cost and complexity of vulnerability exploitation and here's where the Million Dollar iOS 9 Bug Bounty comes into play. BTW, I guess Flash is as popular as iOS9 (the Steam hardware survey used to show that 99.9% of the Steam users had Flash installed), yet, as stirlo says, they only paid up to $30k for Flash exploits.
- MatekCopatek 11y agoI was replying to stirlo's deduction, which I felt was wrong, not the original announcement. You do make a great point with that Flash comparison, though.
- bonestamp2 11y agoDoes anybody know if ZERODIUM is not the government/nsa?
- ins0 11y agoThe exploit/jailbreak must support and work reliably on the following devices (32-bit and 64-bit when applicable): - iPhone 6s / iPhone 6s Plus / iPhone 6 / iPhone 6 Plus - iPhone 5 / iPhone 5c / iPhone 5s - iPad Air 2 / iPad Air / iPad (4rd generation) / iPad (3th generation) / iPad mini 4 / iPad mini 2 So did i read this correct and the exploit must be backwards compatible in order to get the full bounty?
- lawnchair_larry 11y agoSounds like ios8 will be the last jailbreakable version. Shame.
- userbinator 11y agoIf the last 8 versions were jailbreakable I think this one will be too - eventually - but it is certainly the case that devices are becoming more secure both for and against their owners. The tension between freedom and security is definitely increasing.
- rimantas 11y agoOTOH, Apple TV 3 was never jailbroken, iirc. Sure, that may just mean not enough interest.
- ikeboy 11y agoBut who's going to release one publically when they can get $1 million for not doing so?
- burkaman 11y agoYou can only get a million for a really impressive jailbreak. If it involves plugging the phone into your computer and downloading something, or even just pushing a button, it doesn't qualify for this bounty.
- ikeboy 11y agoFair enough; but if you're a hacker looking for exploits, what do you search for first?
- captainmuon 11y agoI wonder if we will now see more hardware-based jailbreaks. It's a bit like with oil drilling. Once the easily accessible options are gone, people reconsider options that used to be considered too expensive to exploit or too damaging for the environment. Like fracking, oil sands, oil wells that are very deep or far up in the arctic, ... In the case of iOS explots, maybe you'll be able to jailbreak it over the lightning connector. Maybe you'll have to open the phone and hook up the circuit board to a device. Maybe someone in china will build a robot for phone shops that'll disassemble, jailbreak, and reassemble a phone in seconds (and replace a cracked screen while it is at it). Heck, maybe it'll become economic for criminals to bribe and/or blackmail Apple engineers to put a backdoor into iOS, or to leak keys?
- jjoe 11y agoIs this a Zerodium ad masquing the politically incorrect PR of "zerodium has 0day exploits available for sale"? I mean how else would anyone advertise availability of 0day without compromising their credibility? $1M per exploit would sure get you lots of press.
- camillomiller 11y agoConsidering the strictness of the requirements, I can think of two options: - this is just a PR stunt, nobody will realistically deliver such a piece of code before oct. 31st. - they know that someone in the jailbreak community is cooking something big like that and they're trying to tempt them and acquire a very interesting exploit before anybody else.
- JoshTriplett 11y agoI have to wonder: what stops someone from selling the "exclusive" rights to an exploit, waiting for the check to clear, and then disclosing it privately to the vendor to get fixed?
- hyperpape 11y agoTrust. That sounds funny, given that it's a grey market, but there were excerpts from the Hacking Team email dump where they talked extensively about which exploit providers were high quality, reliable, etc. Someone absolutely can try and play games, but the people they sell to will do their best to determine whether that's happening and penalize them.
- JabavuAdams 11y agoIf you're dealing with bad people, do you really want to screw them over?
- Klathmon 11y agoI might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all security checks to allow full root access.
- captainmuon 11y agoYou used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.
- SlashmanX 11y agoYou're correct. jailbreak.me I think it was called
- deleted 11y ago[deleted]
- haywardsmyfault 11y agoRight! One of the famous initial iPhone OS exploits involved a vulnerability in LibTiff. Decoding a crafted .tiff in Safari would grant the site's javascript root access. Read more: https://books.google.com/books?id=1kDcjKcz9GwC&pg=PA9&lpg=PA9#v=onepage&q&f=false https://books.google.com/books?id=1kDcjKcz9GwC&pg=PA9&lpg=PA...
- soared 11y ago"The whole exploitation/jailbreak process should be achievable remotely, reliably, silently, and without requiring any user interaction except visiting a web page or reading a SMS/MMS (attack vectors such as physical access, bluetooth, NFC, or baseband are not eligible for the Million Dollar iOS 9 Bug Bounty. ZERODIUM may, at its sole discretion, make a distinct offer to acquire such attack vectors.)." Can someone explain this part? Jailbreak from a website, sms, or mms seems ... impossible. Has this even been possible with older jailbreaks?
- wingerlang 11y agoLong time ago, but yes: https://en.wikipedia.org/wiki/JailbreakMe https://en.wikipedia.org/wiki/JailbreakMe
- deleted 11y ago[deleted]
- pmdarrow 11y agoIt's not impossible and has been done several times in the past, see https://en.wikipedia.org/wiki/JailbreakMe https://en.wikipedia.org/wiki/JailbreakMe
- cstavish 11y agoBack when all iOS apps ran as root, and MobileSafari had a vulnerable libtiff, jailbreakme.com was "easy" by today's standards.
- moviuro 11y agoStagefright (Remote Android code execution) does exactly that http://arstechnica.com/security/2015/07/950-million-android-phones-can-be-hijacked-by-malicious-text-messages/ http://arstechnica.com/security/2015/07/950-million-android-...
- TwoBit 11y agoStagefright was not a rootable exploit.
- fla 11y agoSaurik, you can do it ;)
- tptacek 11y agoAnd all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.
- Mahn 11y agoSo, let me get this straight, this company is in the business of buying zero-day exploits and selling them to corporations and government organizations. How does this even exist? Is it legal? Can anyone buy and sell zero day exploits with total impunity?
- tptacek 11y agoYes, they can.
- ddoolin 11y agoSure. The buying and selling tools is not the issue (depending on where you live), it's using them.
- lawnchair_larry 11y agoAn exploit is just an input to a bug that someone else put there. The idea of it being illegal fundamentally makes no sense.
- Miner49er 11y agoIt's a win-win for Zerodium. They are getting free publicity for having the biggest bug bounty ever, and if somebody actually does submit a working exploit, they sell it to their clients for a hefty profit. I'm sure there are government agencies that would pay well over a million for the ability to infect any IOS device silently and easily.
- ikeboy 11y agoYou can sell the same exploit to multiple governments.
- myohan 11y agoWhat they're not telling you is finding this exploit entails NP=P. It sure has the same bounty value on its head. jk
- halestock 11y agooff topic, but wow it's really annoying that the site overrides your scroll-speed settings.
- nkrisc 11y agoIt's terribly annoying. It also hijacks my ability to move forward/backward in the browser by swiping my trackpad.
- eyeareque 11y agoA million bucks for a iOS 9 vulnerability sounds nice. But is that worth having the death, imprisonment, or torture of possibly innocent people on your conscience? If a government is buying these vulns, there is no telling what they will do with them.
- JabavuAdams 11y agoIf you live in the US or Canada and voted for a recent government, this is already on your conscience. The realization that there's a dirty, dirty underside to our standard of living seems to polarize people. Some dedicate themselves to helping. Some conclude that the world is run by gangsters, so they might as well pick a gang and profit. Most, either never realize or just decide that the problem is too big and they should focus on their own little islands of comfort.