Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
69,752
41,140



Exploit acquisition platform Zerodium has increased its reward for a successful jailbreak of iOS 10 to $1.5 million, far surpassing Apple's recent payout offer for discovering and reporting vulnerabilities in its software.

Late last year, Zerodium briefly offered and paid out $1 million to one hacking team for the successful creation of a browser-based jailbreak for iOS 9.1 and 9.2, but dropped the going rate for an exploit to $500,000.

zerodium.jpg

Rather than report the vulnerabilities to Apple, Zerodium said that it would sell the exploit to its customers, which include major technology, finance, and defense corporations, as well as government agencies.

Instead of being limited to a specific timeframe, the new $1.5 million reward is a permanent offer that aims to compensate for Apple's recently hardened security regime, said Zerodium founder Chaouki Bekrar.
We've increased the price due to the increased security for both iOS 10 and Android 7, and we would like to attract more researchers all year long, not just during a specific bounty period as we did last time.
At the same time, Zerodium's decision to up its bug bounty can be seen as a response to the imminent launch of Apple's own program.

Last month at the annual Black Hat Conference, Apple announced the launch of an invite-only Security Bounty Program that would offer rewards of up to $200,000 to researchers depending on the vulnerability discovered. Apple said the program would be limited to a few dozen researchers and would go live in September.

Earlier this week, several news media outlets were seemingly duped into reporting on an alleged 'secret' meeting of prominent hackers at Apple's Campus in Cupertino, which was supposed to include a briefing on the company's bug bounty program. The meeting was apparently a hoax perpetrated by the hackers themselves.

@qwertyoruiopz Forbes punk'd - franz (@neozeed) September 28, 2016


Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Article Link: Zero-Day Acquisition Platform Triples iOS 10 Bug Bounty to $1.5 Million
 
Hmmm... $1.5M from Zerodium, or [up to] $200,000 from Apple.... Let me think...

From Ars Technica:

To qualify for a Zerodium bounty, the chain must generally work almost flawlessly to surreptitiously give an attacker complete control over the targeted device. In the parlance of hackers, that's called a weaponized exploit. It's not enough that a researcher provides only a rough outline of the vulnerabilities with a less-than-perfect proof-of-concept exploit. The bounties paid by Apple and Google, by contrast, are much less demanding, and as a result, they generally require less work.
 
"Rather than report the vulnerabilities to Apple, Zerodium said that it would sell the exploit to its customers, which include major technology, finance, and defense corporations, as well as government agencies."

Did anybody not see this part ?

Hopefully, the way this will work, is some well-to-do company sympathetic to Apple or invested in its security will buy it and sell the exploits back to Apple for whatever they spent on it (assuming Zerodium wouldn't sell it to Apple).

Apple then releases an update to fix the exploit the next day.
 
  • Like
Reactions: JohnArtist
Weaponized iOS exploit: $1.500.000
Weaponized Android exploit: $200.000

1500/200 = 7.5x sounds about right as a difference in security and value of the two platforms.
Android is open source, so it's easier to look for security flaws.

In the meantime, Apple's source code includes things such as the goto fail bug, which speaks volumes about its security and value, and volumes about Apple's code review and sensitive code change practices.
 
Android is open source, so it's easier to look for security flaws.

In the meantime, Apple's source code includes things such as the goto fail bug, which speaks volumes about its security and value, and volumes about Apple's code review and sensitive code change practices.

Zerodium founder Chaouki Bekrar:

"Prices are directly linked to the difficulty of making a full chain of exploits... Asked why a string of iOS exploits commanded 7.5 times the price of a comparable one for Android he said: "That means that iOS 10 chain exploits are either 7.5 x harder than Android or the demand for iOS exploits is 7.5 x higher. The reality is a mix of both."
 
How is this even legal?

My thoughts exactly. This is a national security issue, not some business deal. We have the Patriot Act, but no legal requirement to report potential security vulnerabilities to the companies that make hardware and software?

Anybody who takes this 'bounty' should be held legally liable, along Zerodium, for any damages caused by a customer exploiting a bug...
 
Just because I don't like something doesn't automatically make it illegal.

All of this buying and selling of exploits amounts to a conspiracy to invade your property and your life.

There isn't a legitimate use for this information, which is why they all call themselves "researchers". Government has their own mechanisms. We absolutely should not farm out security to private contractors who are allowed to amass catalogues of undocumented exploits to important infrastructure. That would be totally ******* crazy.
 
Strange, because in this case the implications of such business model aren't very user friendly.

Could the act of selling an iPhone hack make you an accessory or accomplice to a crime if that hack was subsequently used to break the law? I confess that I am not knowledgeable enough to comment in that regard.

The closest analogy I can think of is that it would not be against the law to have the keys to your house duplicated, though it would certainly be breaking the law if I decided to use those keys to break into your house to burgle it. The only reasonable course of action you could take is to have all your locks changed.
 
  • Like
Reactions: abunawas
Zerodium founder Chaouki Bekrar:

"Prices are directly linked to the difficulty of making a full chain of exploits... Asked why a string of iOS exploits commanded 7.5 times the price of a comparable one for Android he said: "That means that iOS 10 chain exploits are either 7.5 x harder than Android or the demand for iOS exploits is 7.5 x higher. The reality is a mix of both."
You mistakenly interpret this as a difference in security, where it could simply reflect a price difference in the equipment required to discover security flaws.

For all we know, iOS could have many more security flaws that Android has, but they're more expensive to find due to its closed-source aspect.

Apple has shown itself careless and cavalier with security flaws both on OSX and iOS, and coasts on its "security through obscurity" belief, which is hardly any security at all.
 
  • Like
Reactions: begemotik228
Well this is better than the founder of modern day VR donating money to an alt-right group to troll the internet.
 
  • Like
Reactions: ignatius345
You mistakenly interpret this as a difference in security, where it could simply reflect a price difference in the equipment required to discover security flaws.

For all we know, iOS could have many more security flaws that Android has, but they're more expensive to find due to its closed-source aspect.

Apple has shown itself careless and cavalier with security flaws both on OSX and iOS, and coasts on its "security through obscurity" belief, which is hardly any security at all.

security through obscurity... what obscurity? iOS has a BILLION devices in use.

Zerodium's CEO words can't be more clear, let's requote them: "That means that iOS 10 chain exploits are either 7.5 x harder than Android or the demand for iOS exploits is 7.5 x higher. The reality is a mix of both"
 
Could the act of selling an iPhone hack make you an accessory or accomplice to a crime if that hack was subsequently used to break the law? I confess that I am not knowledgeable enough to comment in that regard.

The closest analogy I can think of is that it would not be against the law to have the keys to your house duplicated, though it would certainly be breaking the law if I decided to use those keys to break into your house to burgle it. The only reasonable course of action you could take is to have all your locks changed.

And in this analogy you can't just change the locks since you have no idea what is specifically wrong with the lock. That's why this is not very good. No one with good intentions would come to this zerodium and give them an exploit. If a find something i report it to the the company that made it and i make my device and all devices more secure.

Anyone who will deal with this "company" are immoral ***** in only for the money.
 
You know, if Apple played their cards right, they could contract someone to work on their behalf and get $1.5Million of of Zerodium's money and directly benefit Apple. In fact, a truly conniving company could create a hidden 'vulnerability', sell it to Zerodium, fix the code right away and sink the potentially sabotaging company.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.