The going rate for iOS full chain (iMessage, Safari, or BT/WiFi exploit + sandbox escape, protection bypass, and persistence) is over two million dollars. The brokers then sell them for 2x-5x that amount. Reporting that same vulnerability to Apple can net you up to a million.
If this is true, I'm super-curious about the economic incentives involved. According to Apple's Sept. 2020 balance sheet, they had over $143 billion in current assets on their books. They have deeper pockets than basically anyone else on Earth, including many state actors. They could 10x their current bounty and it would still basically be couch money for them.
So why are 0-day brokers and their customers able to outbid them? I would think that Apple has much more skin in the game than attackers do, and much more to lose from being the #2 bidder. But judging by the going rates you mentioned, that doesn't seem to be the case. The only thing I can think of is that the small minority of parties with both the means and motive to outbid Apple (the respective governments of the US, China, Russia, etc) are in fact the ones doing so.
What skin in the game do they have? As long as they aren’t viewed as way more insecure than Android vulnerabilities don’t really cost them anything.
It's also always worth pointing out, even though it's not relevant to this thread, that the vulnerabilities we're talking about all fit into a similar mold; they're all generally some form of drive-by or click-by clientside RCE (they're some of the harder vulnerabilities to find and weaponize, and, from what we can see in reporting, they're not the kinds of vulnerabilities we see lots of disputes about with vendors, though I'm happy to be corrected).
And, as always, I want to point out that even at these eye-watering figures, vulnerabilities are cheap. The market competition to RCE vulnerabilities and implant kits is human intelligence. You will pay more just in health insurance and benefits overhead to run a single human intelligence program against a target. Every government in the world, from Germany to the Seychelles, can afford what the IC pays for vulnerabilities, and there's probably no figure we can realistically drive vulnerabilities to in the near future that will change that --- Iran can pull this kind of money out from under its couch cushions, and NATO and China's couch cushions are stuffed with it.
Eh, it is very complicated. On one end of the spectrum you can take a cash payout up front for less money, on the other end you are under contract to keep an arsenal with specific coverage at a minimum fixed size. Brokers exist to trade risk for upside and shield parties from each other.
I think we are in alignment on your second point. Oil rich companies lack domestic talent but have massive war chests of money. I have some insights into the numbers they are throwing around to skilled foreign workers and while it is clear the numbers are stupid big, it is nothing in comparison to running a HUMINT asset or buying a drone.
I think there was a post on HN awhile back where the guy just got 100K for a a very major bug. So you will definitely get more money if you go rouge
Past that, who knows where they get exploits from? I imagine if they're renting servers with Bitcoins to perform computer attacks, these operatives are probably familiar with darknet sites for trading secrets as well.
Using exploits is complicated, expensive, and risky. In most cases - to quote XKCD - it's cheaper and easier to just hit the victim on the head w/ a proverbial $5 wrench until they cough up their password, e.g.: have them download your "secure messaging app" which is actually just your implant.
From the article:
> To get close to Donaghy, a Raven operative should attempt to “ingratiate himself to the target by espousing similar beliefs,” the cyber-mercenaries wrote. Donaghy would be “unable to resist an overture of this nature,” they believed. Posing as a single human rights activist, Raven operatives emailed Donaghy asking for his help to “bring hope to those who are long suffering,” the email message said. The operative convinced Donaghy to download software he claimed would make messages “difficult to trace.” In reality, the malware allowed the Emiratis to continuously monitor Donaghy’s email account and Internet browsing.