6 ms·
Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these
by toasterblender 3y ago
Here is what I do not understand:
Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff?
I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?
- entuno 3y agoSome of them wouldn't want to work for Google and Apple in the first place, regardless of the salary. But while they could try and poach them today, tomorrow there will be a whole load of new people working for those companies, and it'll just be a never-ending cycle.
- cco 3y ago> Some of them wouldn't want to work for Google and Apple in the first place, regardless of the salary. For moral reasons do you mean? I would be surprised to learn there are a lot of people that are open to selling 0 day exploits to "bad actors" (granted that this term is doing a lot of heavy lifting here), but wouldn't want to work for Google or Apple. > ...it'll just be a never-ending cycle I think the idea is you pay them so well that they can work for a handful of years and remove any cash incentive reason for them to continue selling 0 days to bad actors.
- eastbound 3y ago> “bad actors", but wouldn't want to work for Google or Apple - Everyone who doesn’t like US hegemony. Which happens about everywhere but US, in varied proportion, but even in Europe, and even worse in Middle-East, - Everyone who doesn’t like monopolies. Capitalism of competition (as opposed to state capitalism, when the state borrows a trillion per semester, ahem) requires that monopolies be broken down to avoid distortion of competition. Helping bad actors can be, under their viewpoint, less bad than the damage done to a billion consumers consumers at a time. Plus monopolies impose a monoculture of occidentalism, with certain values that a firm in Egypt might consider worse than sponsoring bad actors.
- toasterblender 3y agoIf the number of skilled 0-day hunters who will work for a paycheck is > 0, then yours is a moot point, since a poaching program would still make an impact even if there are some people who work for spyware companies who would not work for FAANG. I think you will also find that morals for many people are inversely proportional to the offered salary. An 0-day developer being compensated $130k may well abandon their particular morals if offered a $240k salary instead.
- toasterblender 3y ago> But while they could try and poach them today, tomorrow there will be a whole load of new people working for those companies, and it'll just be a never-ending cycle. The number of people who successfully find 0-click 0-days for iOS/Android is very small. It's not a vastly replenishable resource.
- hattmall 3y agoIt's a small group but a wide pool. It's not like the same person finds 10 0days. And until they do find their one exploit most of them have pretty much no credentials at all. So how do you avoid hiring 10,000 up and comers that never actually come up?
- toasterblender 3y agoThe same that it works in any other industry. By hiring those with proven track records, the best of the best. The goal is obviously not to hire 100% of the potential 0-day hunters, but by launching a concentrated poaching effort, to make a sufficient dent.
- throwaway38475 3y agoPeople have said Apple can buy companies like NSO for less than they probably spend on SEIMs in a year. But as soon as they do that there will be another startup doing the same thing. The company (GreyShift) that broke the secure enclave had ex-apple security engineers working for them.
- entuno 3y agoThey could certainly go out and try and hire some of the best iOS vuln researches. But if they hire the top 10 out there, then #11 gets a massive payrise to go and work for one of the spyware companies. And if Apple is paying huge amounts of money and getting into bidding wars with all the other companies out there for vuln researches, that'll attract a load more people to start hunting.
- astrange 3y ago
- jrvarela56 3y agoIsn't this akin to asking why Google and Apple end up acquiring companies at very high prices if they could just hire the founders and have them build the products in-house?
- toasterblender 3y agoPoaching founders is an entirely different kettle of fish than just poaching line employees.
- jrvarela56 3y agoOh, I thought finding these vulns was a highly open-ended endeavor with variable payouts.
- fullspectrumdev 3y agoIt depends. Some companies that buy exploits have public “price lists” for acquisitions. 100k+ for a Safari on iOS code exec, another 200k for the Safari sandbox escape, then another 500k+ for the kernel exploit? A full chain is real money. Especially when they resell this ability for 1-2M+ per user.
- toxik 3y agoGoogle absolutely “poach” promising startup devs tbh.
- kramerger 3y agoGoogle has one of the best teams money and prestige can buy: https://en.m.wikipedia.org/wiki/Project_Zero https://en.m.wikipedia.org/wiki/Project_Zero They also have excellent collaboration with independent researchers across the world. But given how much software is written everyday, they can still miss some issues.
- toasterblender 3y agoProject Zero is amazing, but they 1) seem like a very small team, and 2) their mandate is far too broad (essentially to search for 0-days in anything, versus a specific system). What I am talking about is more like Apple having a dedicated team of 10 vulnerability researchers all looking into iOS 0-days fulltime.
- throwaway38475 3y agoThey all do that. I've been in Offensive Security for 10+ years with several spent at FAANGS, and not only do they all have large security teams doing internal testing, they hire multiple contractors like Trail-of-Bits to audit every important service continuously throughout the year. Apple has way more than 10 full time researchers looking at iOS all day, trust me :). They also have a really generous bug bounty. There is always bugs though.
- kramerger 3y ago> Apple has way more than 10 full time researchers looking at iOS all day. Yes > They also have a really generous bug bounty. Hell no
- toxik 3y agoI think it’s many factors. 1. They do to some extent. 2. Which researchers are you going to hire? Lemon market, whoever wants to be hired is more likely a lemon. 3. Freelancing grayhat stuff is very rock n roll. 4. I bet some they try to hire and then the square and inflexible large corpo hiring process is just absolutely unfit for hiring such a person.
- fullspectrumdev 3y ago> Which researchers are you going to hire? Lemon market, whoever wants to be hired is more likely a lemon. Not really. Most people in that space who have a “day job” are almost always open to being hired for better TC/benefits/more interesting problems. Points 3 & 4 are largely correct. It’s very rock and roll, but a very unstable income and most of the brokerages are comically untrustworthy. Also you may develop a conscience and find it hard to sleep at night. Point 4… usually the people who can find such bugs reliably don’t work well in large corps past the short term. The unexplained gaps in a CV also aren’t conducive to getting past HR easily.
- saagarjha 3y agoPoach them to do what? There’s not much use to Apple or Google to have an implant developer around, and just having them do nothing is likely to be frustrating if the corporate lifestyle wasn’t enough already.
- toasterblender 3y ago> Poach them to do what? Poach them to discover 0-days in their software, as I said.
- saagarjha 3y agoThat’s not what implant developers do.
- permo-w 3y agowho's to say they're not doing this? there are a lot of security companies and researchers in the world though or alternatively: as lovely as the hacker -> employee fairytale sounds, a certain % of the "I would never work for Google/Apple" types would come in with the sole purpose of installing backdoors from the inside
- fullspectrumdev 3y agoA lot of the really good hackers won’t pass HR screening, or be able to cope with corporate bullshit beyond a year. So there’s also that.
- jklinger410 3y agoThey probably don't want to hire criminals to work at their companies.
- ziftface 3y agoAlready very well-paid criminals for that matter
- deleted 3y ago[deleted]
- tetrep 3y agoI think this is similar to looking at the budget of the US government and asking why they don't simply pay off all the potential criminals such that most crime in the US is then mitigated.
- callalex 3y agoThat’s not equivalent at all. Paying off criminals creates an incentive for there to be more criminals. Paying more security researchers does not incentivize people writing buggy C code to write even buggier C code.
- cuu508 3y agoRaising compensation creates an incentive for there to be more bug hunters.
- flangola7 3y agoWhich is good
- KirillPanov 3y agoYour analogy is all messed up: paying off criminals doesn't make houses harder to break into.
- alephnerd 3y ago> Why do Google and Apple not simply poach these staff They do. Plenty of white hat teams hire 8200 vets, but sometimes they'd rather make their own company instead of being a cog within an amaphorous foreign corporation.
- FirmwareBurner 3y agoThis. IIRC some famous security researcher responsible for iOS jail-breaks was poached by Apple only to leave after 3 months. Successful and skilled security people with a proven track record, don't have the paciente of putting up with the charade such large orgs require.
- reqo 3y agoGeorge Hotz
- deleted 3y ago[deleted]
- stepupmakeup 3y agoPlenty of jailbreak developers have been poached by Apple. Whether they're still at their A-game still is questionable, I follow one on Twitter and there's regular tweets about depression, suicide, debt and other gloomy topics.
- icelancer 3y agoMoney is just one input for why people choose to work at certain places.
- rehitman 3y agoThere is also a chance at play here. Many people are trying to find a hole, some are more lucky than the other. Google has a great team, so they get lucky more, that is why these things are not too common, but at some point a bad guy gets lucky too, even though he is not the smartest in the room.
- crtified 3y agoIt's a good idea, but in some ways, akin to the challenge that would be presented by attempting a similar-veined "why doesn't the world's richest country just hire all the world's best military generals, leaving zero for any other country?". The reasons why it's not possible are myriad, but boil down to the fact that the world and humanity are very big things, and one entity can't possibly get them all, or even most of them. There's too much diverse heterogenuity built into everything. Including many worldviews and loyalties that go beyond money.
- trollian 3y agoThese exploits are weapons. Look at what governments pay for weapons. That's hard to compete with.
- eviks 3y agoHow much do they pay for weapons at the level of an individual weapon designer/manufacturer's employee??
- OneLessThing 3y agoI am this person. I work as a researcher finding 0-days. From the employee perspective: Wages are equal. Big Tech work is less interesting (build big bug finding machines that find have high quantity of bugs) and report the bugs that sit into some bug tracker only to maybe be fixed in 3 months. Offensive security work is more interesting. It requires intimate knowledge of the systems you research, since you only need a handful and the shallow ones get found by Big Tech. You must go deep. Additionally offensive security requires the know-how to go from vulnerability to code execution. Exploitation is not an easy task. I can't explain why engineers work for companies that I deem immoral, but that's probably because they don't feel the same way as I do. From the employer perspective: How much does the rate of X vulnerabilities per year cost me? If our code has bugs but is still considered the securest code on the market, it may not benefit the company to increase the security budget. If the company expands the security budget then which division is getting cut because of it, and what is the net result to the company health? If you want to fix the vulnerabilities you need to make the price of finding and exploiting them higher than the people buying them can afford. And you must keep the price higher as advances in offensive security work to lower the price of finding and exploiting them. Since defensive companies don't primarily make money from preventing bugs and offensive companies do primarily make money by finding bugs, there is a mismatch. The ultimate vulnerability in a company, or any entity, is finite resources.
- saagarjha 3y agoI mean wages might be equal (are they, though? Big tech pays a lot as you go up) on average but there’s a lot of difference in how they pay out. Big tech usually provides compensation bands where your salary is pretty stable. Vulnerability research frequently has your compensation hinge on your performance to a much larger extent.
- manonthewall 3y ago[dead]
- eviks 3y agoYou don't need to cut any division, profits can also change
- callalex 3y agoBecause that would eat into profit margins, and at the end of the day very very few paying customers actually make their purchasing decisions based on security. On top of that almost nobody is really knowledgeable enough to make an informed decision in the first place. So the money doesn’t get spent.
- tagawa 3y agoIt’s not just money that motivates.
- fortran77 3y agoI want to fight terrorism. I’ll work for a company finding ways to get data from bad actors’ phones before I’d work for Google or Apple, at any price.
- eviks 3y agoWhy would you need to poach all of them, just enough to find bugs faster Though poaching all is simply impossible, by raising prices you'll incentivize more people to become vulnerability researches, so more will always be available to the spyware firms