4 ms·
Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-remote-attack-surface-of.html https://googleprojectzero.blogspot.com/2019/08/the-full
by OrgNet 7y ago
Can she claim it: https://googleprojectzero.blogspot.com/2019/08/the-fully-remote-attack-surface-of.html https://googleprojectzero.blogspot.com/2019/08/the-fully-rem... ?
- RKearney 7y agoFrom the article: > The full $1 million will go to researchers who can find a > hack of the kernel—the core of iOS—with zero clicks required > by the iPhone owner. Which one of the vulnerabilities discovered met that criteria?
- zabuni 7y agoAt the end of their Black Hat talk they showed one. Anyway, Project Zero doesn't accept bounties.
- borski 7y agoWell, sort of. They ask that the bounties be donated to charity.
- mauricioc 7y agoShe has a list at https://twitter.com/natashenka/status/1155940732084973568 https://twitter.com/natashenka/status/1155940732084973568 (recall that "remote, interaction-less" means "do not require any physical interaction from the target to be exploited, and work in real time", according to the Project Zero blog post). Edit: As the posters below said, those aren't kernel bugs. Thanks for the correction!
- tareqak 7y agoThe article also had > Another $500,000 will be given to those who can find a “network attack requiring no user interaction.” which I believe many of her vulnerabilities are definitely eligible for. I read that article from https://news.ycombinator.com/item?id=20639999 https://news.ycombinator.com/item?id=20639999 yesterday, and she had this paragraph as her second > Vulnerabilities are considered ‘remote’ when the attacker does not require any physical or network proximity to the target to be able to use the vulnerability. Remote vulnerabilities are described as ‘fully remote’, ‘interaction-less’ or ‘zero click’ when they do not require any physical interaction from the target to be exploited, and work in real time. I focused on the attack surfaces of the iPhone that can be reached remotely, do not require any user interaction and immediately process input. [0] The full $1 million is for that level of fully remote attack, but against the kernel. I'd have to look up to see if any of the code she found vulnerabilities in are part of the iOS kernel. [0] https://googleprojectzero.blogspot.com/2019/08/the-fully-remote-attack-surface-of.html https://googleprojectzero.blogspot.com/2019/08/the-fully-rem...
- saagarjha 7y ago> Another Surely this is an additional $500,000 if she finds a kernel exploit (which would net her $1 million)?
- tareqak 7y agoI found a photo of a table here which hopefully makes things clearer: https://cdn.macrumors.com/article-new/2019/08/applebugbountypayouts-800x600.jpg https://cdn.macrumors.com/article-new/2019/08/applebugbounty... . 'dang and/or 'scbt: This link and title is probably better: https://www.macrumors.com/2019/08/08/apple-bug-bounty-program-improvements/ https://www.macrumors.com/2019/08/08/apple-bug-bounty-progra... | Apple Ups Bug Bounty Payouts, Expands Access to All Researchers and Launches macOS Program.
- saagarjha 7y agoThanks, that does make things clearer.
- tptacek 7y agoIf Natalie Silvanovich finds a vulnerability that meets Apple's high-payout bounty criteria, they will pay her; nobody is going to mess with Silvanovich, least of all Apple ProdSec, who I have to assume exists in a relatively constant state of trying to recruit her out of P0 (good luck, ivan).
- ehsankia 7y agoTo be clear, she doesn't want the money, she's paid by Google, but I believe they've said the companies can give the money to charities. Now we see if Apple will payout her prize to charity. She may not have found a $1m exploit, but a lot of those 10 she found are pretty serious.