8 ms·
Apple’s effort to court ‘ethical’ hackers draws poor reviews
- headmelted 5y agoNon-paywalled link?
- commoner 5y agoNon-paywalled archive link: https://web.archive.org/web/20210909140946/https://www.washingtonpost.com/technology/2021/09/09/apple-bug-bounty/ https://web.archive.org/web/20210909140946/https://www.washi... You can generate this snapshot on your own by using "Save Page Now" at: https://web.archive.org https://web.archive.org If your web browser supports the extension, try Bypass Paywalls Clean: - Firefox: https://addons.mozilla.org/en-US/firefox/addon/bypass-paywalls-clean/ https://addons.mozilla.org/en-US/firefox/addon/bypass-paywal... - Chrome: https://gitlab.com/magnolia1234/bypass-paywalls-chrome-clean https://gitlab.com/magnolia1234/bypass-paywalls-chrome-clean
- tailspin2019 5y ago> You can generate this snapshot on your own I never knew that. I've often seen archive.org links posted like this but without realising you can actually initiate a snapshot! Thanks!
- MegaDeKay 5y agoPaste the link into google to get access to their cached version. https://webcache.googleusercontent.com/search?q=cache:40fEbDjgHD0J:https://www.washingtonpost.com/technology/2021/09/09/apple-bug-bounty/+&cd=1&hl=en&ct=clnk https://webcache.googleusercontent.com/search?q=cache:40fEbD...
- xhkkffbf 5y agoHow funny to find hackers trying to avoid paying journalists for their work on a story about a company that's trying to avoid paying hackers for their work.
- poetaster 5y agoxhk (etc). Nice spotting. You saved someone from drownig.
- WesolyKubeczek 5y agoI haven't read the article, because fuck paywalls. But given the stories from hackers that drip here and there, I have got a feeling they are setting forth conditions that are too crazy to be even taken seriously, compared to competitors. It could be that 0-days are easier just to sell to black market and not bother with Apple's ridiculousness and red tape.
- smoldesu 5y agoA lot of CVE disclosures I've read involving Apple typically go cold-case for a few months after disclosure. The person responsible for the old Thunderbolt memory access hack (Thunderspy) didn't even hear back from Apple upon disclosing their findings, so I think it's safe to say that they're either understaffed or not interested in fixing your critical security vulnerability
- bell-cot 5y ago$can_see_story_free = $javascript_enabled ? false : true;
- lostcolony 5y agoWow. "Apple’s bug bounty program offers $100,000 for attacks that gain “unauthorized access to sensitive data.” Apple defines sensitive data as access to contacts, mail, messages, notes, photos or location data." But a hack that allows arbitrary, malicious applications to be installed doesn't count; even though it could send any user files on the computer (so any data that is not encrypted by its consuming application). That seems...a bit of a logical leap. I mean, yes, it can't let you access iCloud photos, but a random JPG on your computer is totally fair game, so even with their list, it feels like it should be included (let alone the excel file with revenue figures that are going to be broadcast at the next quarterly result meeting with shareholders, or the HR docs containing PII, or...)
- chongli 5y agoA malicious application on macOS doesn’t automatically get access to the user’s sensitive data (contacts, photos, documents, etc). When an application tries to access those things the user normally gets a prompt from the OS to authorize such access. Verified bugs that allow circumvention of this prompt are what Apple is paying for.
- lostcolony 5y agoFrom the article - "Owens created a hypothetical attack that gave hackers access to the victim’s files. He said in an interview that it could have hypothetically allowed hackers to access corporate servers, if the target computer were used by a corporation." Perhaps Owens is lying. Perhaps this is misleading reporting, or otherwise occluding something. But on the surface of it, it sounds like no user intervention required.
- chongli 5y agoYeah so if he did as he claimed then he achieved the bypass Apple claims to be paying for. Now if Apple is lying and refusing to honour their bug bounty, that is another matter. My point is that just because you can get the user to execute your malicious executable under their user account does not grant you access to all their files, unlike what you would expect with traditional Unix permissions.
- sukta495 5y agoInternal at Apple Ivan took over the team and then gotrid of all MSRC managers and half employees before rewards program launched. Team drove into ground after and churn through manager after manager, everyone leave
- netsec_burn 5y agoYep, this lines up with my experience. I've been trying to work with Apple on a critical security vulnerability for over a year now that affects over 100 million systems. When I'd ask the payout ranges at the beginning, I've had multiple people just block me as a contact and Apple themselves refuse to answer. Apple has a strict stance of submitting all of the research up front with no expectations as far as payment. Today, I've been ghosted by Apple, no reply to multiple emails. The last message I have is them saying they're fixing it. I chose the ethical route at a steep cost, the average price of the vulnerability from the other buyers I was talking to was 475K. There have been attempts to hack me 2 days after requesting a quote from some buyers. The most I can hope from Apple is 1/4th that. It really is the poorest communication out of any program I've done with the exception of AT&T's, who patched an RCE in their employee portal I reported (two months later) and then emailed me 6 months later saying there was no RCE. I've been told Apple is getting better with their communication over time, and now their average turnaround is 10 months.
- jasonladuke0311 5y agoJust curious - do you have an ethical stance against selling to ZDI/Zerodium?
- lolpython 5y agoOP edited their post to answer your question
- netsec_burn 5y agoZDI, like Apple, doesn't tell you the average price of the vulnerabilities you can sell to them when you email them (yes, Apple has example payout ranges, but they aren't clear on classification). At Pwn2Own, ZDI paid roughly half of what Apple should pay. When you consider Apple themselves are 1/4th the market price, thereby making ZDI 1/8th, it becomes impossible to work to them. I raised my concerns with ZDI, no reply. I submitted some details (nothing technical, just the classification and affected platforms) of my vulnerability to Zerodium. Two days later someone tried to hack into all of my personal accounts and failed due to 2FA, and not many people have the email I used when I communicated with them. I've found other buyers outside the US, but I had ethical concerns and decided against them (at a 300K min loss).
- throwaway20371 5y agoIf I'm a hacker and I have an Apple 0-day, why the hell would I report it to Apple if I can quickly get a tidy payment on the black market?
- twox2 5y agoMaybe because you don't want to be an arms dealer? Or you don't want to risk prison.
- SXX 5y agoWhat law is there against selling vuln to a random person on internet? And yeah you don't really need "Black" market. There is plenty "legit" companies around the globe that absolutely immoral, but their business as legal as it's could be.
- caeril 5y agoPrecisely this. Zerodium will sell your bug to the FBI, who will be happy to use it to incarcerate more Americans. They'll also absolutely sell it to China, they'll just be quiet about it and use one of many Thailand-based intermediaries.
- twox2 5y agoIf you sell something to someone and they use it to commit a crime, you are culpable if you even had a wiff that it was going to be used for something illegal. So if you're selling 0days on the blackmarket, you can bet your ass they will come after you sooner or later. The companies that immoral & legal, have paved their own way, but since you're not going to be selling to governments directly, don't count on being able to get away with it.
- SXX 5y agoCan you provide some examples in US / EU of people being charged for selling vulns on "black market"? Otherwise it's just baseless FUD. I guess far bigger problem for researcher would be to actually not being scammed while selling and this is why companies like Zerodium have their marketshare. Yeah someone could pay to you in crypto, but chances that you'll just gonna be scammed are extremely high.
- aNoob7000 5y agoI'm always surprised by companies like Apple that have so much money that paying out bounties should be no issue at all. It feels like Apple doesn't like being on the weaker side of a negotiation. Maybe I'm a little naive, but I would set up a bounty program at Apple that was very lucrative for security researchers to report their bugs. The main goal would be to make the holders of security vulnerabilities concerned that someone might submit a bug report and make their million-dollar bug worth zero.
- WFHRenaissance 5y agoI have a CVE from Apple for a vulnerability in a consuming-facing mobile application RE improper data access & failed obfuscation of sensitive information. People think the CVE is cool and all, and it might help me get my next job, but for now it hasn't helped me put any food on the table. Maybe next time I'll call China, Russia, randoms on Twitter, go public before reporting to them, et cetera. Incentives are f'd up.
- creamytaco 5y agoI have had two close friends quit recently, within a few months of each other. They both blamed management and especially Ivan Krstić.