Apple security bounty upgraded
security.apple.com
security.apple.com
It's basically an "officially cracked" iPhone.
Israel not present. Probably because of NSO. Quite hilarious.
https://deibert.citizenlab.ca/2017/02/mexico-nso-group-and-t...
I really dont think nso group client is the pattern.
Wow, I want one of this just for fun, sounds like what I want my normal iPhone to be able to do
> Have a proven track record of success in finding security issues on Apple platforms, or other modern operating systems and platforms.
Well, that put a stop to my dream...
No they can't. They overlay a red arrow showing where they want you to push, and you (the user) are asked to push there.
Or even in the US, the courts you think will save you could be the very ones ordering your data because you are suspected of a crime because you typed a certain trigger phrase that activates an automated warrant like those Google has.
The 4th amendment only protects you when data is stored on your property. When it is in control of a corporation, the corporation gets the warrant, not you.
Or maybe Apple simply changes their terms of service to resemble that of TikTok or Facebook giving them more or less complete legal freedom over your data.
Or maybe it is just a rouge Apple system administrator that does not care about the rules.
You can not own an Apple device and the data on it is at the mercy of choices made by remote humans with incentives very different from yours.
Power that exists will always be abused. It is how humans work.
> Power that exists will always be abused.
I hate to break it to you, but power isn’t going anywhere, and it isn’t always abused.
Telling the difference is what matters.
No one has legal power to change their terms of service governing my data, or issue secret warrants, or extralegal power to outright take my digital property.
Would those situations ever have seriously impacted me in the first place? Probably not. Thing is though, they can and do affect a lot of people.
The more people that learn to take back control of their digital property, the safer we all are.
I was just making the point that Apple hardware and the data on it is not in your control. If you fully trust Apple and your politicians to never mistakenly target you or anyone you recommend the same practices to, then you are all good.
I cannot assume your jurisdiction, but if one were to believe what you have stated, these assumptions would need to be true:
1) you’ve never flown anywhere before 2) you do not belong to any single country (you need to be a nomad, as all modern countries have identification systems in place for their citizens) 3) you’re using internet at a cafe because if you are paying any bills to your ISP that’s game over
-
I find it highly improbable you speak the truth. I’m sorry to say, but it really seems like the type of comment made by an “ignorance is bliss” type of individual that has recently watched an episode of mr robot.
The data I post on HN is public. When I post data to a public place it is no longer mine. I am not a luddite, I simply have separation of concerns between public and personal life. Data that is not public, is mine.
When I fly, I accept this is a public event. All parties are transparent about this. You will however be hard pressed to buy a record of the local locations I frequent or what I purchase at a pharmacy without an expensive private investigator because I do not carry a cell phone and I pay cash.
The data that I consider mine, such as personal family photos, detailed location history, my IoT product usage, etc, lives in servers I physically own on property I own. Not unlike a box of photos in someones attic. If you want to rifle through it, get a warrant. No surveillance capitalism companies will have a chance at buying that data regardless.
I do sometimes use third party services to distribute private data, such as matrix.org. The privata data such as DMs can not be decrypted or controlled by the server operators, and only by my keys on devices I control all software on. That data is mine too.
You do not need to trust your ISP to have a useful level of digital sovereignty.
I don’t see how this is even close to true. Governments seize property all the time.
When the data lives with Apple or Google, they can just secretly take it, even in bulk. The NSA wire taps on Google and others were a real thing that actually happened. No pesky constitutional protections in the way for the data you freely give to corporations.
In principle, but not in practice. All they need is a witness for probably cause, and once they have your stuff, you aren’t going to get it back without a bankrupting fight, if at all.
If you think the government plays fair in the real world, you might want to have a discussion with a Mr Assange, currently a guest of King Charles III.
> When the data lives with Apple or Google, they can just secretly take it, even in bulk. The NSA wire taps on Google and others were a real thing that actually happened.
The NSA wire taps were ruled illegal. How satisfying.
Also, because I control my technology, and my encryption keys, the constitution gives me one other major protection. The right to not self-incriminate, or, the right to not give them additional rope to hang me with.
No one knows my decryption passwords but me, and no one can compel me to reveal them legally.
It is exactly because the government does not always play fair, as you point out, that every citizen owes it to themselves and each other to limit their power.
Meanwhile you give up all rights and control of your data when you agree to the terms of service of Apple or Google. They will hand over your plain text data without your knowledge or consent if you merely say the wrong trigger phrase.
They could publish a firmware that abuses your device, but they would have to ship this to everyone on that particular channel (e.g. general releases, public beta, developer beta)
Maybe judges do not realize they have that power yet, but they will eventually.
The CCP certainly understands this well, which is why they seized the HSMs governing encryption and binary signing for Chinese citizens.
It is a paid product (eg $x/hr cloud billing). Supposedly easier to obtain than the security research device.
If someone comes forward with legitimate good security vulnerabilities and you don’t pay out, you’re massively encouraging them to go to shady brokers next time.
Uhhh I must be missing something here… I can trivially share a contact via email after my iPhone is unlocked?
That first unlock after booting decrypts a bunch of things.
Without first PIN, most functions don't work because the writable flash areas storing third party apps and user data are still encrypted.
This is also why you have to enter your PIN on reset rather than a biometric; it is far more established to derive a symmetric key from a password than from biometric data.
See also Gui Rambo getting a measly $7,000 for a couple of fairly serious vulnerabilities.
In Crypto there exists a service called ImmuneFi, it's essentially a arbitrator between hackers and services offering bug bounties that provides an impartial third party ruling on the payout.
They recently paid out a $10 million bug bounty. That really needs to move into Web2.
ImmuneFi have "paid out +$10,000,000 in bounties" [1]. Not $10mm for a single bounty.
> Immunefi has saved over $25 billion in users’ funds and has paid out $60 million in total bounties. The platform now supports 300 projects across multiple crypto sectors, and collectively offers $135 million in bounties to whitehat hackers. Immunefi has also facilitated the largest bug bounty payments in the history of software, including $10 million for a vulnerability discovered in Wormhole, a generic cross-chain messaging protocol, and $6 million for a vulnerability discovered in Aurora, a bridge and a scaling solution for Ethereum.
Also, once the rewards increase past a certain point, security researchers would have no reason to work for apple, since one big hit would mean set for life.
"iPad. Loveable. Drawable. Magical"
"iPhone 14 Pro. Pro. Beyond"
And now;
Apple Security Bounty. Upgraded.
I know what you mean. But I just think they're very proud of their work, ya know?
And for good reason too. Apple is in a league of its own in quality.
However, one reviewer said it was weird? Name the product, I’ll find someone who called it “weird.”
"No wireless. Less space than a Nomad. Lame."
If I were cmdrtaco I'd put in my will that this has to be the inscription on my gravestone.
Case in point: Airdrop. Super convenient when it works, doubly annoying when it doesn't.
"You won't believe what's new in the iPad"
"Pros are jealous of these new iPhone features"
"5 new upgrades to Apple Security Bounty, and you won't believe number 2!"
It’s anything but lazy. You may not like the style, but it’s a very well-developed vocabulary and they’re extraordinarily diligent about making sure that they speak with one voice.
Imagine how operationally efficient their marketing group has to be as a point on the critical path of everything Apple does publicly.
At other big tech companies, an initial evaluation of a security report will be done in 15 minutes... And if it's important, people will be woken up and a workaround will probably be deployed in a matter of hours...
For example, the Google security bug form[1] says "This option might really get someone out of bed."
Filter out the reports saying "The padlock is missing on my gmail" from those that say "If you type TRUE into the gmail login password box, it will let you log in as any user, and 4chan has discovered it".
Edit: To clarify, especially in cloud environments (which is most stuff these days) it's really not hard for someone to verify something if it's well written.
That's not really the same thing.
For small- and mid-sized companies that do bug bounties (of which there seem to be fewer and fewer these days as a percentage) you can definitely wind up submitting directly to the right people and get really quick response times.
There are clearly 2 different levels of "evaluation" at play here.
Being able to "evaluate" every security bug submitted to you in 15 minutes implies relatively insignificant bugs, or it implies that you are not "evaluating" the bugs you claim you are "evaluating".
The first time a report came in on meltdown/spectre/heartbleed whatever, there is no way any serious security researcher could have fully evaluated that report in 15 minutes. Never having seen or heard tell of it previously. Heck, just pulling together the requisite hardware and getting the requisite software on it might take more than 15 minutes. I don't buy that it could be "evaluated" in 15 minutes.
Anyone serious got advanced notice of meltdown/spectre/heartbleed and had longer than 15 minutes to decide a course of action. Whether that's a good or bad thing about infosec as an industry, I can't decide.
Emphasis mine. What it means is that even reports that fail the initial “oh shit” gut check (which Apple definitely does BTW) will still get worked within 1-2 weeks. That’s pretty good.