5 ms·
Zerodium expects iOS exploit prices to drop as it announces surplus
- saltedonion 6y agoWhat is the business model of this company? Are they selling such exploits to whoever is willing to pay the most? And does this mean Android is more secure?
- newacct583 6y agoIf you take the press release at face value, it means Android has fewer newly-discovered vulnerabilities on the open market right now. That's probably good news for Android, but there are alternative explanations too: maybe Google is paying more for their exploits to keep them hidden, for example. Or maybe Zerodium is trying to get Apple to sign a new/bigger contract and applying pressure. This is all, indeed, a pretty shady business. I don't think there's anything authoritative we can say from the outside.
- softwarejosh 6y agoor maybe being closed source didnt help apple in the long run
- whynotminot 6y agoToo simplistic of an answer, though it could be part of it. I think we wrap ourselves in a bit of false security when we say something is open source and think that automatically makes it more secure. We assume someone has looked at the source. But has anyone really? And those with the most incentive to look into these things might not be inclined to share the vulnerabilities back to the community for safety's sake, given the princely sums being offered by companies like Zerodium.
- smokelegend 6y agoFunny how Microsoft is now saying they were "on the wrong side before" with open source. Let that sink in...
- joemazerino 6y agoApple is the device to exploit right now which drove supply. Meanwhile Google, Project Zero and companies like Copperhead are actively securing Android.
- headmelted 6y agoThis sounds really logical to me but also raises yet more questions. How much is Zerodium charging people for these exploits if Apple isn’t paying? Sure, they could stick the knife in if Craig Federeghi calls up to ask how much, but you’d assume it’s nothing to Apple to spin up an arms-length subsidiary with a folksy name to buy the info through.
- axlee 6y agoCompanies can subscribe to a feed of 0-day exploits ("Zero-Day Research Feed"), for what I assume is a hefty fee, large enough to make a profit despite millions of dollars spent on exploit acquisition.
- saltedonion 6y agoTheir website says they mostly sell to North American and European governments. I can only assume this is for offensive purposes, since they can’t patch the kernel/software even if they know how the exploits work.
- deleted 6y ago[deleted]
- fpoling 6y agoI wonder what is the reason for that? I doubt Apple code quality dropped significantly. Is it simply because more people started to look for vulnerabilities? Or was it because better tools to discover the bugs became available?
- mschuster91 6y ago> I doubt Apple code quality dropped significantly. Oh it did. Earlier OS X releases were way more stable and didn't break shit for no reason. Quality assurance has gone downhill over the last years, that's what happens when the people in control are no longer engineers taking pride in high quality bug free code but rather managers whose incentives are to push as many new features out as possible - which IMO was also the reason why 86 support was dropped in Catalina, it was too expensive to keep supporting, but heh who cares about users of stuff like VSTs for sound people or people wanting to use their Mac for gaming...
- colejohnson66 6y agoOptimization is not the same as security. The first iPhone was jail broken and unlocked within days of its release IIRC. As the years went on, we were lucky to get a jailbreak at all. In fact, checkra1n was the newest exploit in a long time. Yes, their quality has gone down a bit, but don’t confuse that with their security measures.
- nicoburns 6y agoNo, but QA is necessary for security. If they're letting through bugs that cause crashes or product misbehaviour, then they're also more likely to be letting through security issues.
- mschuster91 6y agoApple effectively put an end to the jailbreak scene by allowing people to compile their own applications without paying a dime. Put the incentive away and suddenly there's a lot less eyes on the code.
- 6y ago
- masnao 6y agoseems like a guerrilla marketing campaign to make researchers know sandbox is broken but they are still shopping for persistence.
- vsareto 6y agoThe price has been downgraded before: https://www.wired.com/story/android-zero-day-more-than-ios-zerodium/ https://www.wired.com/story/android-zero-day-more-than-ios-z... And going back further: https://twitter.com/cBekrar/status/1128702955555713024 https://twitter.com/cBekrar/status/1128702955555713024 Pretty sure it's not marketing
- londons_explore 6y agoHow about another theory... The kind of organisations that use these exploits rarely want to use the same one twice. That would link the two uses, which could reveal who was attacking who or why. However, anti-rooting protections on iOS devices are such that the vast majority of organisations don't have any kind of logging or analysis infrastructure set up which could trace which devices have a specific exploit run against them. The exploit is probably delivered by an encrypted channel, so even if you did full traffic logging from all employee devices to the internet, you still wouldn't have enough info to know which devices were infected, since the attacker will surely use a different server each time to deliver the exploit. That suddenly makes it much safer to reuse exploits, so there isn't such a big market for a new exploit for every covert operation. The same isn't true of Android - there are plenty of apps which will trace syscalls, dump logs, send suspicious files for analysis, etc. That makes reusing an exploit a risky business for three letter agencies, especially if you're attacking another three letter agency who probably has their own custom anti-malware type software just waiting for you to trip a tripwire.
- captn3m0 6y agoI made a few guesses on a previous thread: https://news.ycombinator.com/item?id=23170237 https://news.ycombinator.com/item?id=23170237