I wonder how they're going to manage this. I could easily see some less than ethical researchers applying for this program and selling all the 0 days they find to the usual suspects rather than informing Apple.
I wonder how they're going to manage this. I could easily see some less than ethical researchers applying for this program and selling all the 0 days they find to the usual suspects rather than informing Apple.
I don't work in the security field nor am I a business number cruncher, but that was the gist I had of what these programs achieved.
Edit: see Despegar's reply, I should have RTFA! However worth pointing out that there would be some incentive for researchers to go to Apple instead of a third party, which might tip the scales in their favour.
When you consider it could be the likes of the three digit shoe inspectors over there in the US it could be a fair chunk of change
0days are used against hardened targets. Think “Iranian nuclear facilities” rather than “grandma’s PC”
It is nothing like that. It is the same as freelance development work, except there are very few customers and the developer writes something that may or may not have any value.
>Previously, a company called Zerodium was vocal about how much it will pay researchers, before handing them to its unknown government customers. In January, the secretive company announced it was offering $2 million for a remote hack of an iPhone.
So that's already more than what Apple offers. I tend to think they'll always be outbid.
I forget the influence until I see things like this.
How would that make any sense? It is ludicrous.
So $1M/exploit is priced significantly ahead of the $2M/hack.
Interesting this also means that an entire exploitable stack now becomes worth a lot more, while any given exploit is worth a lot less. And any stack of exploits becomes much more brittle, as a patch of a single one of N exploits can knock out the use of the stack.
Now, people who prosecute white hacks that practice responsible disclosure are technically known as "asshole"s but the end result is that there are a ton of laws even innocent computer usage breaks so your liability for any damage to end users usually doesn't need to be considered, there's enough book to throw at people already.
[1] Essentially if you touch a computer or computing device it's quite likely you've somehow violated the CFAA, it's _stuuupid_. https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
You don't need safe harbor because analyzing your own property is not a crime. Neither is telling people what you found. Also, please stop using the term responsible disclosure!
Do you own the OS you’re breaking into?
Unfortunately the intersection of "security researcher" and "right-to-repair advocate" is probably tiny, but that would be something I'd love to see: someone finds a crack that enables a lot of third-party-repair scenarios and sells it to that industry instead of to the black-hat criminals or even back to Apple itself.
The third-party repair/aftermarket industry is huge and would love to break through the proprietariness of the ecosystem. In that light, $1M seems rather small...
Based on personal experience, the intersection isn’t all that small.
Corporations had been unilaterally deciding what the payment for a reported bug would be. They were constantly undervaluing and wasting everyone's time. People would say the same rationale "low liability and clean money is more valuable than dirty money and needing to launder it".
Yeah, but not that much more valuable.
So now the bounties are reaching their market price.
I think one of the intentions here is to lessen the demand for black market dev-fused phones, which is already a huge problem for Apple. This is similar to the idea of officially allowing Linux on the PlayStation — give hackers no legitimate reason to pwn your console
>Some incorrectly speculate it was used as an attempt to help classify the PS2 as a computer to achieve tax exempt status from certain EU taxes that apply to game consoles and not computers (It was the Yabasic included with EU units that was intended to do that).[citation needed]
and Linux on the PS3 was used as a marketing point.
https://en.wikipedia.org/wiki/OtherOS - both these pages are really bad :/
I wish I remembered the specifics of the comment, but selling a 0day on the black market is not something a casual person can easily do, and even if someone figures out how, there's a lot that can go wrong, with many of those outcomes leading to jailtime.
It's vastly superior to participate in a bug bounty program legitimately, from a risk standpoint, especially if you're standing to make $1M. 0days are (and I'm not an expert on this) not generally going for enough more to justify all that extra risk.
Argue with 'tptacek, not me.
That's what has been happening so far. Here's a report from a couple of years ago about this: https://www.vice.com/en_us/article/gybppx/iphone-bugs-are-to...
The announcement today is actually raising the rewards 5x (from $200K to $1M) to make it more valuable to report this to Apple.
I’d say that the researchers have a pretty strong incentive not to screw around with Apple.
It doesn’t matter anyway, because Apple patches the bug, thus killing its black market value completely.
But maybe it depends on how you define “hacker” and what you call “random”. I’m saying that folks in the jailbreaking scene are some of the primary targets for this. It wouldn’t be worth launching if the plan was to exclude them. Some are already part of Apple’s bounty program.
“Apple Calls In Rock Star iPhone And Mac Hackers For Secret Bug Bounty Bash”
https://www.forbes.com/sites/thomasbrewster/2016/09/28/apple...
If they get some special "developer" devices on their hands, they might find some funny things...
How much do they make selling to China?
Aside from the Chinese part of the jb scene, it’s kind of disheartening to know that the rest of them are selling that capability to a hostile adversary (if that’s true). I’m surprised the five eyes aren’t offering enough to keep them out of China’s hands.
My guess is that they're not going to let just any rando h4xx0r into the program. They'll take on well-known security researchers and academics who have something to lose by leaking zero days.