The reality is that they only pay that much for bugs in the kernel that do not require a user interaction.
Other bugs that use a common action on an app that everybody uses, for example opening the stock mail application, may be enough in order to compromise almost all iPhones. Apple seems to pay "only" $100k for those problems.
I just scanned through the comments and clicked on some links so correct me if what I wrote is not accurate.
1. The buyer or someone the buyer trusts, then the buyer can log all the network traffic and find the incoming attack traffic and work out the exploit from there.
2. The seller or someone the seller trusts, can backdoor the software to fake it.
3. Someone they both trust, that would require they have some mutual contacts which while possible I wouldn't count on it.
4. A random victim, more possible, but neither party would want to risk prematurely burning the exploit.
And of course there are a ton of exploits that are not remote, all sorts of local privilege escalations, and there are partial exploits that are sold. Like a multistage exploits like say just the exploit to escape a sandbox, or even just an exploit that requires a memory leak could be sold without a memory leak, or just selling the memory leak. Obviously a fully weaponized exploit sells for the most, but there are buyers for stages also.
I was thinking about phones, not servers.
> then the buyer can log all the network traffic and find the incoming attack traffic and work out the exploit from there.
Is it really that easy? I'm not a security researcher, but I imagine that most exploits aren't just a magic byte sequence you send to the victim -- so I assumed that just a single observation of a successful attack is not enough to understand it easily.
that doesn't change things too much, it does introduce some potential difficulties with intercepting certain types of traffic/input to the phone. The question just becomes who controls the hardware being compromised.
> but I imagine that most exploits aren't just a magic byte sequence you send to the victim
Its not, and its not like you can just replay those very same bytes, but its not magic, it all has a meaning and a purpose. While its not easy, you can work out plenty from logs. The entire exploit necessarily is there, things will change, but all the instructions[0] that get injected to do later stages necessarily needs to be sent, or the instructions to generate/cause them.
Its not an easy skill, but its not unheard of.
[0] I'm simplifying a bit to avoid getting into various code execution techniques
So, when either party violates the agreement, it reflects poorly on that person who made the introduction, making it harder for them to make those connections in the future. And, these introductions matters, most sellers don't want to just sell to anyone, there needs to be some trust that who you're selling to will be selling it to friendly governments or whatever. Its not like a craigslist ad where you sell to just anyone who answers.
So that acts as a deterrent on the buyer side. It'll be harder to get new sellers if you have a poor, or no reputation.
On the seller side, you're not going to get too many people willing to vouch for you as you start burning bridges by selling non-working exploits.
And on that, the payment scheme acts as a deterrent, like teh great-grandparent said:
> grey-market sales are valued on continuous access; you get paid over a period of time, and if the bug you sold dies, you stop getting paid.
That is, you might get XX Thousand upfront, and then an agreed upon XXX thousand based on the exploit surviving XX days.
So trying to scam the buyer will net you a small amount of the total at best, but I mean, often times they'll hold payment until its confirmed and contracts are written and signed over these sales too, its not under the table payments or anything for the most part. Legitimate business transactions.
So, I guess to sum it up, reputation and a demonstrated, or atleast vouched for past record. There is a lot of trust on both sides.
Not all brokers are alike though, exploit survival is a gamble, but sensible end-buyers usually don't want to burn the exploits either so will use them sensibly. There are some brokers that don't sell exclusively (despite their claims), they have a reputation for exploits getting burned early.
I have not been involved with any iOS exploits, not really my area of interest, but lets say I was. Would I consider selling it off to Apple, yeah, it would be something to consider. I'd consider the market rates too of course, 1MM vs 1.5MM, sure Apple is enticing, 1MM vs 2MM, maybe not. Not sure where I would actually draw a line, but you are right that Apple doesn't need to compete directly with the market rate, just close enough.
I'm sure there are those that would rather just go for the bigger profits regardless.
Hacker: I have a no user-interaction RCE
Apple: ok yeah
Hacker: gimme a phone number
Apple: here you go
Hacker: …
iPhone: I am pwned
Apple: ok lets do the deal
Not reputation? Not the thrill of it? Not hatred of Apple? Not plain maliciousness?
Zerodium already pays double what Apple does. Where's the incentive?
https://law.stackexchange.com/questions/502/is-it-legal-to-s...
So to me, this isn't a PR stunt. It's a necessary "dumbing down" we see all too often. It's no different from journalists digesting and simplifying the content of an advancement in biology or physics.
I don't get this it is either A or B reasoning. Why can't it be also a PR stunt? Or also contain PR?
If a company wants to do something and PR gets involved and makes sure the messaging is good, that’s not a PR “stunt” anymore.
A stunt is a trick.
[0]: https://www.independent.co.uk/news/business/news/should-appl...
That's certainly not to say the HN audience is an elite (it's not) but it is comprised of outliers in the sense of people having abnormal jobs and/or abnormal interests compared to the average population in any city-sized slice taken pretty much anywhere in the real world.
¿Porque no los dos? Security and PR.
Now, by keeping these 0days off the market, Apple also gets to further burnish their reputation. It's a good play no matter how you look at it.
Of course, first Apple needed to be fairly certain that there aren't tens of thousands of vulns left to patch!
It’s true that Apple pins its rewards to specific outcomes, but I think a lot of bug bounty programs do something like this. For instance, Google’s top bounty for Android ($200k) is only awarded if you can provide an exploit compromises that the trusted execution environment (see https://www.google.com/about/appsecurity/android-rewards/).
I guess on average it will reduce those holding on. But it will not eliminate them.
Are independent discoveries of bugs common?
Also, somewhat famously, both Spectre and Meltdown were discovered independently by multiple teams in the same timeframe, who all coordinated disclosure with the CPU vendors etc. https://meltdownattack.com
We should also remember that there are tons of people outside the US who are into this. Africa, Asian, Eastern Europe. They don't have to worry about the legality of selling an exploit.
isn't that the point? sure, it makes selling on the black market more valuable for the hackers willing to do that, but it also makes purchasing an iPhone exploit less accessible for anybody else. that's a good thing.
This move from Apple makes people like me, working with human rights defenders and journalists, happy.
Why?
Because it drives up the costs for the NSO Groups, Hacking Teams and Gammas of this world. They either pass on (and take a hit reducing their revenue/internal capacity) or drive up their costs (making it harder for crappier regimes to afford / reducing the frequency that high end exploits will be used.
Besides that, earning a 1 million dollar reward for cracking the iOS kernel is probably a nice ticket to a pretty well paying gig at some security firm.
“The Cupertino, California-based company said in a lengthy memo posted to its internal blog that it "caught 29 leakers," last year and noted that 12 of those were arrested. "These people not only lose their jobs, they can face extreme difficulty finding employment elsewhere," Apple added.”
https://www.bloomberg.com/amp/news/articles/2018-04-13/apple...
Bloomberg.
Then Apple could buy and fix ASAP so the researcher get screwed. So yeah it’s cheaper but if someone notice just wait for the backfire! Guaranteed one time payement seem like the fair way to go.