Apple’s effort to court ‘ethical’ hackers draws poor reviews
washingtonpost.com
washingtonpost.com
I submitted some details (nothing technical, just the classification and affected platforms) of my vulnerability to Zerodium. Two days later someone tried to hack into all of my personal accounts and failed due to 2FA, and not many people have the email I used when I communicated with them. I've found other buyers outside the US, but I had ethical concerns and decided against them (at a 300K min loss).
I've found other buyers outside the US, but I had ethical concerns and decided against them (at a 300K min loss).
What type of buyers exist who are unable to fix the vulnerability (in this case, who are not Apple or the affected vendor or do not collaborate with Apple, etc.) but might be considered ethical to sell to?
I imagine some people think being rewarded for finding vulnerabilities is unethical entirely, but there seems to be a huge dose of pragmatism around the space.
Alternatively depending on how nationalistic someone feels NSA could be a eithical buyer for them as well.
How did you protect yourself against those?
Also, as a security researcher, are there alternatives you'd recommend more? Would Linux/Windows be more secure?
You tried to report to apple. You didn't like the way they "treated" you, so you decided to sell it on black market. The black market person tried to hack you. You then went to the fbi to complain about how your black market buyer treated you?
Am i missing something from this story? That seems like a really bad plan.
On a serious note, I'm glad researchers like you exist.
I've managed several programs for some very large companies and haggling over bounties with a researcher is a _really_ bad idea. You set your bounty amounts and stick to them. If people want to haggle over impact that's fine, but once you exceed your quoted bounty amount for one person then everyone expects it.
The bean counters also play a big role. Most companies aren't ready for big bounty payouts when a program first starts. They set a fixed budget and are more likely to end a program completely if the bottom line cost is too high, regardless of the security impact. Security teams are aware of this and try to walk a fine line.
For researchers who are having problems with programs I'd suggest trying to form a better relationship with the triage teams and security teams. Be helpful, not confrontational. Companies get their best bang-for-buck when they can court good researchers. They love getting quality researchers who report multiple findings and they'll do quite a lot to make them happy, including paying bonus bounties for future reports and being far more transparent with triage status.
At the beginning of a high profile bug bounty program I'd expect higher expenditure than in the following fiscal year due to the backlog of researchers who really want to "sell" to an official channel, not a slow start.
It’s not hard to read it as “we don’t negotiate with terrorists”, and Apple (or Google or Amazon…) know people think they have deep pockets
<Giant bold white letters fade in against a black background>
A R R O G A N C E
If they don't want to play ball, take it to someone that will appreciate your work. Should it be used nefariously, you are still helping because they might take you more seriously next time, as they should have in the first place.
carrot versus stick.
As far as exposing users, that makes assumptions about the actions of a number of people including the company in question which could, if it so desired, assemble the resources to push a fix within 48 hours.
simply put if Apple doesn't find a way to come to an agreement with this person in a timely manner, they are just saying they see the zero day and the consequences for their users as acceptable losses as preferable to the payment
But a hack that allows arbitrary, malicious applications to be installed doesn't count; even though it could send any user files on the computer (so any data that is not encrypted by its consuming application). That seems...a bit of a logical leap. I mean, yes, it can't let you access iCloud photos, but a random JPG on your computer is totally fair game, so even with their list, it feels like it should be included (let alone the excel file with revenue figures that are going to be broadcast at the next quarterly result meeting with shareholders, or the HR docs containing PII, or...)
Perhaps Owens is lying. Perhaps this is misleading reporting, or otherwise occluding something. But on the surface of it, it sounds like no user intervention required.
My point is that just because you can get the user to execute your malicious executable under their user account does not grant you access to all their files, unlike what you would expect with traditional Unix permissions.
You can't really generalize either way from one, or even a few anecdotes.
Maybe I'm a little naive, but I would set up a bounty program at Apple that was very lucrative for security researchers to report their bugs. The main goal would be to make the holders of security vulnerabilities concerned that someone might submit a bug report and make their million-dollar bug worth zero.
You can generate this snapshot on your own by using "Save Page Now" at: https://web.archive.org
If your web browser supports the extension, try Bypass Paywalls Clean:
- Firefox: https://addons.mozilla.org/en-US/firefox/addon/bypass-paywal...
- Chrome: https://gitlab.com/magnolia1234/bypass-paywalls-chrome-clean
I never knew that. I've often seen archive.org links posted like this but without realising you can actually initiate a snapshot! Thanks!
https://webcache.googleusercontent.com/search?q=cache:40fEbD...
It could be that 0-days are easier just to sell to black market and not bother with Apple's ridiculousness and red tape.
They'll also absolutely sell it to China, they'll just be quiet about it and use one of many Thailand-based intermediaries.
The companies that immoral & legal, have paved their own way, but since you're not going to be selling to governments directly, don't count on being able to get away with it.
I guess far bigger problem for researcher would be to actually not being scammed while selling and this is why companies like Zerodium have their marketshare.
Yeah someone could pay to you in crypto, but chances that you'll just gonna be scammed are extremely high.
There might not be a high profile "this dude sold a 0day and got arrested" case yet, but there are cases of folks selling software / hardware cracking tools getting indicted.
There's also this really interesting story:
https://www.wired.com/2013/03/alfred-anaya/
Dude caught serious prison time just for making hidden compartments in cars and they put him away based on the fact that he knew his customers where in the drug business.
Selling high impact 0days definitely seems like a risky business IMO.
How can I monetize ethics?
We live in a society. We try to abide by the mores.