10 ms·
Apple security bounty upgraded
- deleted 4y ago[deleted]
- dagmx 4y agoThis is also part of a new Security Research page https://security.apple.com https://security.apple.com
- brian_herman 4y agoWow the Security research device looks awesome! https://security.apple.com/research-device https://security.apple.com/research-device
- ChrisMarshallNY 4y agoThey discussed that, at one of the latest dub-dubs. I think last year. It's basically an "officially cracked" iPhone.
- klabb3 4y agoLooking at the list of approved countries. Israel not present. Probably because of NSO. Quite hilarious.
- LegitShady 4y agothey made their own
- melony 4y agoI find it funny that most of the true cyber powers are left off the list but India is considered to be “safe choice”. India may be poor but it is hardly lacking in engineering prowess. Apple’s own employees are a testament to that.
- paxys 4y agoThis isn't really about skill. I imagine they want to only include countries that aren't big on cyber warfare.
- bawolff 4y agoWell they left USA on the list.
- blululu 4y agoThe laws around US citizens hacking the computers of US companies are straightforward and easily applied.
- bawolff 4y agoRight, but we aren't talking about private citizens but nation state actors with an interest in cyberwar capabilities. USA is probably near the top of that list.
- throwaway371057 4y agoIt's kind of a lost cause when the government could just directly compromise Apple itself though? Maybe they are also fine with helping their own country's cyberwar abilities.
- bawolff 4y agoI wonder what the selection criteria was. For example mexico is also not on the list
- rtev 4y agoMexico also abused Pegasus, right? I wonder if any national governments that are affiliated with NSO are restricted.
- onedognight 4y agoMexico used their government licensed NSO tools to target the children of activists working to pass a sugar sweetened beverage tax. https://deibert.citizenlab.ca/2017/02/mexico-nso-group-and-the-soda-tax/ https://deibert.citizenlab.ca/2017/02/mexico-nso-group-and-t...
- bawolff 4y agoIf you look at the list at https://en.wikipedia.org/wiki/Pegasus_Project_(investigation)#Regions_and_targets https://en.wikipedia.org/wiki/Pegasus_Project_(investigation... it seems like most of the countries that used pegasus are still on the allowed list, many of them much more extensively users than mexico was. I really dont think nso group client is the pattern.
- arihant 4y agoYou're right. Main political opposition in India was affected with Pegasus and it is part of this program. I think this has more to do with the level of Apple's presence in a country/jurisdiction and their ability to retrieve the device back in case of misuse.
- deleted 4y ago[deleted]
- blinkingled 4y agoYeah pretty ballsy move! (Android being always like this does put a bit of damper on it - shell, running tools, custom kernels yeah all of that ;)
- throwaway290 4y agoMaking a separate, 'researcher-friendly' device that is easier to own "without having to bypass its security features" on the surface seems so incredibly in line with Apple's general ethic yet so counter-productive in this particular context...
- capableweb 4y ago> Shell access is available, and you can run any tools, choose your own entitlements, and even customize the kernel. Wow, I want one of this just for fun, sounds like what I want my normal iPhone to be able to do > Have a proven track record of success in finding security issues on Apple platforms, or other modern operating systems and platforms. Well, that put a stop to my dream...
- camkego 4y agoThe quote mentioned above can be found here: https://security.apple.com/research-device/ https://security.apple.com/research-device/
- capableweb 4y agoI think two HN submissions got merged, I think the submission I made my comment to lead directly to that page. At least that's my excuse in case someone asks.
- wnissen 4y agoI remember when the iPhone tech remoted into my phone. I knew it had to be technically possible but it is reserved for Apple. Probably a good idea that it's not generally accessible, all my relatives who I recommend use their iPads for banking would be in trouble.
- KerrAvon 4y agoWhat do you mean by “remoted”?
- xnyan 4y agoI’ve seen this done for support. Apple seems to have an internal remote access tool similar to common VNC or RDP based tools that allows them to view a video stream of your display and send touch inputs to it as if they were physically using your device.
- AJRF 4y agoApples copywriters make everything the brand says sound smug. e.g; "iPad. Loveable. Drawable. Magical" "iPhone 14 Pro. Pro. Beyond" And now; Apple Security Bounty. Upgraded.
- movedx 4y agoThey're just better than you... /s hehe I know what you mean. But I just think they're very proud of their work, ya know?
- codetrotter 4y ago> I just think they're very proud of their work, ya know? And for good reason too. Apple is in a league of its own in quality.
- abudabi123 4y agoExcept the head of industrial design has decided to roll and the recent batch of hardware release doesn't look compatible in a hi-fashion sense collection. The latest ipad has been received by one reviewer as "weird" and that pen accessory is finicky in version type and connector type requirement.
- gjsman-1000 4y agoThe pencil is weird, granted. Especially on the, I will admit, convoluted iPad lineup. However, one reviewer said it was weird? Name the product, I’ll find someone who called it “weird.”
- culturestate 4y ago> Name the product, I’ll find someone who called it “weird.” "No wireless. Less space than a Nomad. Lame." If I were cmdrtaco I'd put in my will that this has to be the inscription on my gravestone.
- 4y ago
- bumblebritches5 4y ago
- londons_explore 4y ago> we’ve grown our team and worked hard to be able to complete an initial evaluation of nearly every report we receive within two weeks, and most within six days. At other big tech companies, an initial evaluation of a security report will be done in 15 minutes... And if it's important, people will be woken up and a workaround will probably be deployed in a matter of hours... For example, the Google security bug form[1] says "This option might really get someone out of bed." [1]: https://www.google.com/appserve/security-bugs/m2/new https://www.google.com/appserve/security-bugs/m2/new
- lapcat 4y agoThis statement did seem strange. However, I sent in a report to Apple Product Security a week ago, and I received a personal response within 48 hours saying that they reviewed my report.
- st3fan 4y agoThis is nonsense. Nobody verifies security reports of any significance in 15 minutes.
- londons_explore 4y agoNot 'verifies'. Simply read the report and decide on the priority. Filter out the reports saying "The padlock is missing on my gmail" from those that say "If you type TRUE into the gmail login password box, it will let you log in as any user, and 4chan has discovered it".
- bink 4y agoI think there's a difference between verifying a report and simply triaging it to the right team. Apple is doing the former while companies that respond in 15 mins are often doing the latter.
- newZWhoDis 4y agoThanks for the laugh! I can only Imagine the shenanigans that would come from such a bug
- runjake 4y agoIt's a lot of talk, but I doubt Apple's honesty here. See also Gui Rambo getting a measly $7,000 for a couple of fairly serious vulnerabilities. https://news.ycombinator.com/item?id=33348013 https://news.ycombinator.com/item?id=33348013
- twosdai 4y agoYeah I love the idea of bug bounties, however there is this issue created when the provider cannot offer the most competitive price for bounties. It's no secret that nation states will pay more than Apple will for vulnerabilities.
- tornato7 4y agoThere's no reason Apple couldn't pay more than nation-states for bug bounties; They have a ridiculous amount of money after all. In Crypto there exists a service called ImmuneFi, it's essentially a arbitrator between hackers and services offering bug bounties that provides an impartial third party ruling on the payout. They recently paid out a $10 million bug bounty. That really needs to move into Web2.
- JumpCrisscross 4y ago> recently paid out a $10 million bug bounty ImmuneFi have "paid out +$10,000,000 in bounties" [1]. Not $10mm for a single bounty. [1] https://immunefi.com/hackers/ https://immunefi.com/hackers/
- tornato7 4y agoThat is incorrect: https://www.globenewswire.com/news-release/2022/09/22/2521149/0/en/Leading-Web3-Bug-Bounty-Platform-Immunefi-Raises-24M-Series-A-led-by-Framework-Ventures.html https://www.globenewswire.com/news-release/2022/09/22/252114... > Immunefi has saved over $25 billion in users’ funds and has paid out $60 million in total bounties. The platform now supports 300 projects across multiple crypto sectors, and collectively offers $135 million in bounties to whitehat hackers. Immunefi has also facilitated the largest bug bounty payments in the history of software, including $10 million for a vulnerability discovered in Wormhole, a generic cross-chain messaging protocol, and $6 million for a vulnerability discovered in Aurora, a bridge and a scaling solution for Ethereum.
- fazfq 4y agoAnybody knows how much this costs (if anything)?
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- oliwary 4y ago> Device attack via physical access: $5,000: Limited extraction of sensitive data from the locked device after first unlock. As an example, you demonstrated the ability to extract some contact information from a user’s locked device after the first unlock. Uhhh I must be missing something here… I can trivially share a contact via email after my iPhone is unlocked?
- dcormier 4y agoThey mean that the device is in a state where it’s locked after having been unlocked at least once after booting. That first unlock after booting decrypts a bunch of things.
- radicality 4y agoI believe by “first unlock” they mean a login/unlock right after a reboot. So - turn on device, do first unlock, then lock again. Might be wrong, but afaik the very first unlock after a reboot is bit different then subsequent unlocks (I guess cached memory etc)
- lstamour 4y agoAn iPhone requests the user’s password upon restart, this would be referred to as “first unlock”. The reward is for an exploit that takes place against a _locked device_ but only after it has been unlocked once first. As in, an exploit that applies to the Lock Screen when the device was previously unlocked at least once. It is likely easier to trick a locked system into unlocking after it has already been unlocked the first time, due to password storage, credentialed background processes, and so on.
- dangerface 4y agoDo they actually pay out tho? I keep hearing security researchers having difficulty getting these bounties, seems like a great business strategy out source security audits, offer massive pay outs looks good, don't pay out and keep the pot growing larger to look even better.
- libdjml 4y agoThat would be a terrible business strategy. If someone comes forward with legitimate good security vulnerabilities and you don’t pay out, you’re massively encouraging them to go to shady brokers next time.
- saagarjha 4y agoI hear they do now but it can still be a pain (have to remind the several times, etc.)
- isusmelj 4y agoI just hope you get the money transferred to your bank account and not in Apple product vouchers.
- MauranKilom 4y agoOff-topic: This thread has a cool id (33363333)!