news.volyx.in

We Hacked Apple for 3 Months (samcurry.net)

1454 points by samwcyo · 2181 days ago · 308 comments on HN

Article summary

A group of security researchers spent three months hacking Apple's systems and discovered 55 vulnerabilities, including 11 critical severity issues. They were able to fully compromise various Apple applications and services, including the Apple Distinguished Educators Program and the DELMIA Apriso Application. The vulnerabilities have been fixed and credited by Apple. The researchers found that Apple's infrastructure is massive and complex, making it challenging to secure.

Main themes

  • bug bounty programs
  • security vulnerabilities
  • internal network security
  • third-party protocols
  • security industry trends
  • researcher compensation and recognition

What commenters say

  • The discovery of these vulnerabilities highlights the importance of securing internal networks and systems, as a breach can have significant consequences.
  • The use of third-party protocols and software can introduce security risks that are difficult to mitigate.
  • Some commenters believe that the bug bounty program is a valuable way for researchers to gain experience and exposure, while others think it is a poorly paid and undervalued field.
  • The security industry's reliance on bug bounties and self-funded research may be unsustainable and unfair to researchers.
  • The complexity and scale of Apple's infrastructure make it difficult to secure, and vulnerabilities are likely to exist in any large organization.
  • The fact that these vulnerabilities were discovered by a small group of researchers suggests that other, potentially malicious, actors may have also found and exploited them.
  • The security industry's emphasis on credentials and formal education may be misguided, and hands-on experience and demonstrated skills may be more valuable.