Hacker News new | ask | show | jobs
by RajT88 22 days ago
I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.
2 comments

You don't even need to find a whole 0day, you can find step 3 of 14.

Just dump it anon or sell it, don't even try to claim a bounty or get a cve. Without elaborating, they will make sure you regret it

Same goes for games. If you find RCE, report it and move on. If it remains unfixed let a journalist know. Do NOT accept their invite to the studio, they want to have you arrested. Would have happened to me were it not for one dude with a conscience at the company warning me not to go

Do you have any evidence this is actually happening to good faith security researchers?

There are many examples of Microsoft and other large corporations treating security researchers well. Microsoft hosts BlueHat, where they invite external parties to talk about their findings. They thank researchers monthly who do contribute reports to MSRC. As I recall, they treated bunnie well, and I think they also treated “hoodie” (the original Xbox 360 hacker) well as well.

Now iOS 0-day is worth up to $2,000,000 on gray market so Apple kind a take it seriously.
If you find a real iOS zero day that you think has a market value of 2 million, how do you (a) find a legit buyer for it, and (b) ensure you get paid, presumably in your own choice of cryptocurrency?
Even if you dont count obvious dark markets there is plenty of well known companies mostly from Israel buying exploits.

You can even reach them via Linkedin and even demonstrate and sell in person with all paperwork. No risk here because they will re-sell them for much more.

Having it both fully anonymous, safe and in crypto will be harder. You need to have a trusted friend with right connections in industry not to get scammed.

Are you asking for step by step instructions?
no, I'm making the rhetorical point that the sort of persons that might have 2 million laying around to pay for an iOS zero day for blackhat type purposes might not be the most honorable or likely to actually pay you. And what recourse would you have?
This depends on what you consider black hat. Israeli company that sells surveillance malware to dictatorships around the globe isnt exactly moral, but its legal business.

Unlike Apple or Microsoft buying and selling exploits is their only source of income so they have no motivation not to pay. Reputation is much more important. Also legal system does work in Israel.

dictatorships are not there main customers. There are many, also western, governments and their agencies customers of such services.
He's asking for a friend
When someone says memory corruption is nothing special, they aren't the ones paying those amounts.

Naturally there are other kinds of bugs as well.

However reducing 70% of root causes, saves a bunch of money already.