4 ms·
I think what might not be immediately obvious to people outside of the bug bounty scene is that Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tann
by a5withtrrs 6y ago
I think what might not be immediately obvious to people outside of the bug bounty scene is that Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes represent some of the best bug bounty hunters out there which is definitely one of the reasons they absolutely pwnd Apple here.
I would be genuinely shocked if Apple doesn't end up paying out much more for all the bugs found. Frankly, it would be genuinely concerning if they didn't acknowledge the severity of the bugs and the time invested by this particularly skilled team.
To Sam and the others involved. Fantastic job and amazing write up. 10/10
- w0mbat 6y ago"Within the article I'd mentioned that Apple had not yet paid for all of the vulnerabilities. Right after publishing it, they went ahead and paid for 28 more of the issues making the running total $288,500" https://twitter.com/samwcyo/status/1314310787243167744 https://twitter.com/samwcyo/status/1314310787243167744
- hu3 6y ago> They went ahead and paid for 28 more of the issues making the running total $288,500" That's barely the yearly cost of one generic software engineer at Apple. I was expecting multiple millions in payment given the severity and quantity of vulnerabilities found. State actors could easily 10x that amount legaly through gov contractors.
- ricardobeat 6y agoEven if they would pay a full $5.5 million, at 100k per issue, it seems reasonable for the breadth of the findings and potential losses prevented. The warehouse access alone could cause far more damage, while some of the smaller vulnerabilities are clearly not worth that much. EDIT: see this comment thread for more info on the economics by people who know what they're talking about: https://news.ycombinator.com/item?id=24719656 https://news.ycombinator.com/item?id=24719656
- jcims 6y agoIn the instance yes, but bounty programs need to be sustainable so parameters are set up front. Folks can choose to participate or not. If they don't like the offering, they can find something else.
- pinusc 6y agoBounty programs are in place so that bad actors are not the only ones on the lookout for bugs. If experts get paid pennies for finding enormous security vulnerabilities, what's stopping them from selling them to actually bad actors for a potentially much greater cut? I can imagine that someone would be willing to pay far more than $5M to gain access to Apple wharehouses.
- deleted 6y ago[deleted]
- jbirer 6y agoLegal risk. You can make a quick safe buck from selling the fix to Apple or you can risk some trouble for selling it to criminals.
- jcims 6y agoNothing but their ethics. But why would an expert spend any of their valuable time outside of work looking for bugs if they didn't like the terms of the program? That's irrational behavior. And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers? The vast majority of companies in operation today have no such program and would likely be much more fruitful. And lastly how would paying more for bugs prevent someone from also selling it to criminals?
- ric2b 6y ago> Nothing but their ethics. That's not something a company the size of Apple can count on. > And why would someone who's willing to sell bugs to criminals bother with a site that's already been picked over by bug bounty researchers? Because it's Apple, it's one of the biggest companies on earth. iPhone jailbreak vulnerabilities alone fetch millions on the black market. If you know the bug bounty program doesn't pay much you can expect only the trivial things to have been found, and if you're very skilled you know you still have a good chance of finding things to sell. > And lastly how would paying more for bugs prevent someone from also selling it to criminals? It would keep more honest people interested in your bug bounty program instead of doing something else.
- fulafel 6y agoMaybe there's demand for agents/managers for less famous/media-savvy bug hunters, quintupling the payout would easily pay for the agent's fee in a case like this.
- jcims 6y agoI’ve interacted with some of them directly when I worked on a bounty program. Definitely some of the best in the business (and actually pleasant to work with).