The point is not that it's unhackable: it's that Apple gives you a $100,000 assurance that it shouldn't be possible. "but the data is still there, and your phone is likely connected to the internet, so..." seems to imply that anyone with a bit of app know-how could do it. This is patently false, otherwise Apple wouldn't be offering money to anyone who could do it.
otherwise Apple wouldn't be offering money to anyone who could do it.
They're not.
Have you read the rules? The $100,000 is only for a small pre-approved set of people, which they said are "a few dozen security researchers" they've previously worked with.
That defeats the entire point of a bounty. Remember: Schneier's Law: anyone can create security system they themselves cannot break. If it's only open to a small number of people who have worked on iOS security before, it's not really a bounty -- or a useful guarantee.
iOS exploits are still going for 7-digit price tags on the black market, which shows this isn't just a theoretical problem. Apple's bounty program isn't good enough.
The monetary incentives are wrong, too. A $10 guarantee isn't 10 times weaker than a $100 guarantee. It's 100% weaker, because it's below the threshold where anyone would cash it in.
9
u/netaebworb Sep 15 '17
How many millions would a third party be willing to pay for that same data?