5 ms·
But...this is true of every software vendor. Does anyone think Microsoft is paying market value for a remote code execution exploit in Edge? They're not, they'l
by objclxt 9y ago
But...this is true of every software vendor. Does anyone think Microsoft is paying market value for a remote code execution exploit in Edge? They're not, they'll give you $15k for it[1].
I find this particularly interesting:
> [the security researchers] asked Apple's security team for special iPhones that don't have certain restrictions so it's easier to hack them [...] these devices would have some security features, such as sandboxing, disabled in order to allow the researchers to continue doing their work.
If I go to Google or Facebook and ask them to, say, turn off some key security features on their site so I can find more bugs they're gong to tell me to go take a hike. It's unclear to me why a security researcher thinks Apple would give them access to a device with the sandbox bypassed. Why would they possibly trust them?
[1]: https://technet.microsoft.com/en-us/library/dn425036.aspx https://technet.microsoft.com/en-us/library/dn425036.aspx
- saurik 9y agoYour analogy to me falls extremely flat given that in this situation you own the iPhone in question and are just asking for the right to put arbitrary software... on your own phone. (My comment is now at -1. I challenge anyone considering to downvote this response to actually answer how asking for the right to modify the software on the one phone in your possession--the one whose security features, if you really want to insist that this is about a security feature, only affects you--is even remotely comparable in an honest setting to "go[ing] to Google or Facebook and ask[ing] them to, say, turn off some key security features on their site".)
- andy_ppp 9y agoI agree with you here, you can get to other parts of the OS with this ability and will find different flaws. I would say that this comparable to an external penetration test vs a more formal internal practices and code review. Both are acceptable approaches finding different results.
- ghughes 9y agoMany of the phone’s security features don’t only benefit the user - they also make widespread piracy virtually impossible, and they ensure that nobody can set up a rival software ecosystem on Apple’s hardware.
- saurik 9y agoYour comment agrees with my world view (and why I even pointed out that "if you really want to insist..."), but comes across as an attempt to answer my question or refute my point, so I will then respond by saying "and giving a handful of security researchers the ability to run arbitrary software doesn't lead to rampant piracy" (but you know what does? the "free developer" tier added by the Swift team ;P).
- cageface 9y agoThis has been my biggest complaint about the iPhone from the very beginning of the app store and remains my primary reservation about committing to Apple devices to this day. Thankfully the UX on Android has caught up to the point where it's as good as or even better, in some respects, than iOS. At least for my purposes, anyway.
- Someone 9y agoI didn't down-vote, and don't know enough of this field to be sure, but I think there's an edge case that can affect other users: opening any door a bit may make it easier to retrieve keys that allows hackers to break into other phones. For example, if they open the secure enclave so that security researchers can see in full detail how it works, that may expose some master key. Countermeasure would be to have separate keys, ideally for each such phone, but having them for only this class of phones might be sufficient, too, if they also restrict access to this class of phones. I think that's technically easy, but may be expensive, process wise.
- saurik 9y agoA system designed like that is flawed and insecure, and someone else with more resources--probably someone much more evil, sadly--is going to have figured out a way to get to that key... we should want to air that to the light of day and get that fixed. I mean, at some level your comment turns into "we should try to hide the security flaws we have as much as possible, even from the people who are actively trying to help the world be more secure"... if you aren't serious about finding bugs, why bother with security?
- Someone 9y agoI don't understand that logic. Apple built a safe. If I want to check that it is secure, it would be helpful if they built one from glass, so that I can see how the mechanism works, and thus verify the design. My argument is that that may expose a secret stored in that safe that then can be used to break into 'real' safes. Your argument seems (to me) to be there should be no secrets on that phone that make attackers any the wiser (might well be possible, given the existence of asymmetric encryption). If so, why did Apple go to the effort to add the secure enclave?
- willstrafach 9y agoSaurik is correct about security through obscurity not really being helpful, but for what it is worth, this: > Countermeasure would be to have separate keys, ideally for each such phone, but having them for only this class of phones might be sufficient, too, if they also restrict access to this class of phones. I think that's technically easy, but may be expensive, process wise. ...is already something Apple does with the special development devices. Different keys and certificates used, probably to allow easier access for engineers while tightly monitoring and auditing production infrastructure.
- jsjohnst 9y agoHere's the concern I have, if you're able to "unlock" a single device, how do you do it where it's useful to the researcher, but can't be done to an unsuspecting 3rd party's phone? The only way I can think of that doesn't have an endless array of problematic edge cases is for Apple to have a "researcher edition" of the phone, but even that isn't problem free. Thoughts?
- saurik 9y agoApple already solves this problem by way of their TSS update server: they can whitelist specific ECIDs to be able to sign and install developer customized firmwares. What the argument was was "if we sign on to your program, can you add us to your whitelist?". The only issue I can come up with would be "what if a researcher who was registered with and known to Apple gave their phone to someone else as a fake gift to spy on them". If you really want to go there we could argue it, but it seems a little far fetched in terms of "amount of damage that can be done via this route that couldn't be done via other ones".
- jsjohnst 9y ago> The only issue I can come up with would be .... If it's locked to specific hardware, then no, I definitely wouldn't argue the edge case scenario you mentioned.
- willstrafach 9y agoApple has DEV-fused devices which use separate development certificates and keys. The bootloaders and kernels for production devices still retain the code for the "special" functionality, that is how researchers are aware of it, but it simply will not work without an actual dev-fused device.
- paulcole 9y agoYou own an iPhone designed to work in a specific way. You don't need Apple's permission to put arbitrary software on your own phone. You can just do it! If you can figure out how and don't mind maybe breaking your iPhone. Apple doesn't sell infinitely customizable devices. Anyone who buys an iPhone knows this going in or is being intentionally obtuse. The idea that it's my phone I should be able to do anything I want with it is completely antithetical to the brand Apple has built over the last 40 years.
- saurik 9y agoI am not certain what conversation you think you are joining, but this is one about "people invited by Apple to take part in a bug bounty program--one with an in-person onboarding process and which involved a meeting with Apple's security team, all expenses paid, in Cupertino--with the stated goal of working together to improve the security of the device have asked to be given the ability to modify the software on a limited number of test devices to aid in their security research". Your response is trying to tackle the general argument for arbitrary customers. I still think you are wrong, but that isn't the argument today.
- michaelbuckbee 9y agoYou're right, but it's still puzzling to me. That at a certain point, wouldn't it still be cheaper for MS (or whoever) to pay a more serious amount for critical bugs. I don't quite understand the demand side of this, is it just complacency among customers of these companies not demanding more secure systems.
- TheSpiceIsLife 9y agoWouldn't the black market always be willing to pay more?
- michaelbuckbee 9y agoI guess that's my question. We're talking about companies with hundreds of millions of customers here - which would make me think that any minor security issue's impact is magnified. Which I would think would mean MG/Amz/Goog/Apple would be willing to pay more.
- qq66 9y agoThe government markets will always be willing to pay more because money is free to them. In general, the financially motivated criminal black markets would probably be willing to pay less (if hackers use an exploit to steal $250m from Apple users, that probably hurts Apple by more than $250m). However, a $250m bug bounty is hard for Apple to pay, because the harm is hard to quantify, so they generally don't, leaving the criminals to pay $1m for it.
- PeterisP 9y agoFigures like that IMHO indicate that the black market doesn't sell the exploit to teams doing financial fraud (it doesn't pay back that much) but that instead they act as resellers / auction houses for nation states stockpiling cyberweapons.
- kpcyrd 9y agoWouldn't there be a limit at some point? If apple starts paying 1 million, how many shady companies can afford paying 10 million? Also, if you can make 5 million with a single exploit through bug bounties, would you even bother selling to the blackmarket if you can easily live off of that money for the rest of your life?
- smt88 9y ago> Does anyone think Microsoft is paying market value for a remote code execution exploit in Edge? No bug bounty program has to pay market rate. They just have to pay enough so that $bounty > $market_rate - $fear_of_getting_arrested Edit: there are actually other non-monetary benefits to being a white hat. Some of them get high-paying contracts or fantastic jobs. Some just like the prestige of finding flaws. So it's a more complicated equation than I presented above.
- y_u_no_rust 9y agoarrested? there's nothing illegal about selling exploits to non-criminal groups like zerodium or whoever
- Neliquat 9y agoAny evidence of anyone EVER being arrested for selling an exploit or is this pure FUD?
- dsl 9y ago> If I go to Google or Facebook and ask them to, say, turn off some key security features on their site so I can find more bugs they're gong to tell me to go take a hike. It isn't that uncommon in bug bounty programs to get specific restrictions (say rate limiting on web apps) turned off. When I do security audits i'll often ask for shortcuts (give me access to X machine as if I phished it, etc). These shortcuts will shave a month of the low level grunt work off so I can spend my limited time working on the core vulnerability.
- kinkrtyavimoodh 9y agoYes but you are presumably doing these audits on request, not cold-calling them, so to speak.
- masklinn 9y agoI did a surface comparison of the Apple, Microsoft and Google programs and while the top lend is the same everywhere (150k~200k) Apple still looks pretty unrewarding when you go below that: Google can pay up to 150k for a critical Android Kernel compromise (not including Trusted Environment compromise) reproducible on a Pixel, Pixel XL or Pixel C. If my reading is correct, at Apple that tops out at 50k, you have to compromise the Secure Enclave to go even reach 100k If I'm not mistaken for MS it's covered under the Mitigation Bypass and Bounty for Defense Program, which is up to 100k + 100k (100k for mitigation bypass, 100k for bounty for defense)