frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Tachy0n: The Last 0day Jailbreak

https://blog.siguza.net/tachy0n/
140•todsacerdoti•5h ago

Comments

ivanjermakov•4h ago
If this is the case Apple employed an amazing strategy. By locking all ways to possibly root their devices they patch vulnerabilities discovered for free by jailbreak devs.
ejpir•4h ago
but they haven't, the article says the "private" community still has exploits and apple patches them. The public, like the dev, for some reason, don't anymore.
tptacek•3h ago
They're exclusive to private communities because they're very expensive, and getting more expensive over time; in other words, Apple's strategy has driven the cost of exploiting iOS up.

Anything public is dead, which is what you want to see.

bri3d•2h ago
I’m not sure I agree with the premise here, although I agree with the conclusion w.r.t Apple specifically.

I’m 100% positive from experience doing VR in several non-iOS spaces that increased exploit value leads to fewer published public exploits, but! This is not a sign that there are fewer available exploits or that the platform is more difficult to exploit, just a sign that multiple (and sometimes large numbers) of competing factions are hoarding exploits privately that might otherwise be released and subsequently fixed.

As a complementary axiom, I believe that exploit value follows target value more closely than it does exploit difficulty, because the supply of competent vulnerability researchers is more constrained than the number of available targets. That is to say, someone will buy a simple exploit that pops a high value target (hello, shitty Android phones) for much more money than a complex exploit that pops a low value target. There are plenty of devices with high exploit value and low exploit publication rate that also have garbage security.

With that said, Apple specifically are a special (and perhaps the only) case where they are “winning” and people are genuinely giving up on research because the results aren’t worth the value. I just don’t think this follows across the industry.

tptacek•26m ago
I don't think I reach the deeper questions here, and pretty much just get back to "if it was cheap, Apple would have killed it already"; in that set of circumstances there can't be viable public exploits (or broad workable bug classes to fish from) to work with.

Sucks if you're part of a public jailbreaking community, but, of course, good if you're a user.

hsbauauvhabzb•2h ago
Is this actually true? Jailbreaks are more or less the same exploits used by things like Pegasus, the exploits are probably worth more to the individuals that discover them than the ability to give their friends access to side loaded apps
burnt-resistor•20m ago
That's the rub of relative integrity. It's variably easier for some to rationalize taking the cash, even if that giant pile of coin is likely to lead to the imprisonment, deaths, and/or torturing of others for better or for worse.
hsbauauvhabzb•9m ago
My question wasn’t about ethics and I’d rather keep it that way.
numpad0•2h ago
Jailbreaks need an itch to scratch. There isn't one for Ubuntu Desktop.
weinzierl•3h ago
I've heard Apple pays a million for Jailbreaks now. That's the lower bound for the price on the free market.
ThinkBeat•1h ago
Is there a way to contact Apple to apply for millions of dollars if one has a jailbreak?

X: Hi AppLE I haz jailb8?

Or is it via one of the intermediaries?

Or is there an email or some such that is published? (That will not to straight to 1st level support and forgotten about)

charcircuit•1h ago
https://security.apple.com/bounty/
conradev•59m ago
> now

That boundary was broken in 2015, about a decade ago: https://www.dailymail.co.uk/sciencetech/article-3301691/New-...

lern_too_spel•18m ago
That's the market rate. https://cyberscoop.com/zerodium-android-zero-days-bounty/
andrepd•5m ago
Well TIL that there are zero-day market makers...
yjftsjthsd-h•3h ago
> The way he managed to beat a trillion dollar corporation was through the kind of simple but tedious and boring work that Apple sucks at: regression testing.

> Because, you see: this has happened before. On iOS 12, SockPuppet was one of the big exploits used by jailbreaks. It was found and reported to Apple by Ned Williamson from Project Zero, patched by Apple in iOS 12.3, and subsequently unrestricted on the Project Zero bug tracker. But against all odds, it then resurfaced on iOS 12.4, as if it had never been patched. I can only speculate that this was because Apple likely forked XNU to a separate branch for that version and had failed to apply the patch there, but this made it evident that they had no regression tests for this kind of stuff. A gap that was both easy and potentially very rewarding to fill. And indeed, after implementing regression tests for just a few known 1days, Pwn got a hit.

And now I wonder how many other projects are doing this. Is anyone running a CI farm running historical vulnerabilities on new versions of Linux/FreeBSD/OpenWRT/OpenSSH/...? It would require that someone wrote up each vulnerability in automated form (a low bar, I think), have the CI resources to throw at it (higher bar, though you could save by running a random selection on each new version), care (hopefully easy), and think of it (surprisingly hard).

KennyBlanken•2h ago
> And now I wonder how many other projects are doing this.

If by 'projects' you mean intelligence agencies, then I would say it's safe to assume at least the G10 intelligence agencies are doing this along with Russia, China, NK - and likely a huge number of private groups.

$200k and still no recovery from Google's algorithm

https://medium.com/@lucwiesman/looking-to-recover-from-the-google-helpful-content-update-or-any-algorithm-update-45c25d0d2b62
2•arlattimore•2m ago•0 comments

What if you could pay to own the top spot on a social platform?

1•brock_frisbie•4m ago•1 comments

Young Entrepreneurs Embracing Neurodiversity

https://www.bbc.com/news/articles/cm2xxxmx4g3o
2•flamingshorts•7m ago•1 comments

Show HN: Manifold is a platform for workflow automation using AI assistants

https://github.com/intelligencedev/manifold
1•Art9681•11m ago•0 comments

Mr. Bates vs. the Post Office [TV Series] (Horizon IT Scandal)

https://www.arte.tv/en/videos/RC-026307/mr-bates-vs-the-post-office/
2•exiguus•24m ago•1 comments

How the jax.jit() JIT compiler works in Jax-JS

https://ekzhang.substack.com/p/how-the-jaxjit-jit-compiler-works
1•ekzhang•24m ago•0 comments

Show HN: I made a OSS alternative to Weights and Biases

https://github.com/mlop-ai/mlop
2•LakeeSiv•29m ago•0 comments

CAPTCHAs are over (in ticketing)

https://behind.pretix.eu/2025/05/23/captchas-are-over/
6•pabs3•35m ago•1 comments

Show HN: Speak Chinese characters on the clipboard automatically while learning

https://github.com/C-Loftus/Mandarin-Clipboard-Speaker
2•C-Loftus•36m ago•0 comments

Cross-platform line editor in APL (similar to ed)

https://github.com/arcfide/ALE
2•secwang•36m ago•0 comments

The Other Homo Sapiens

https://aeon.co/essays/why-one-branch-on-the-human-family-tree-replaced-all-the-others
1•bikenaga•36m ago•0 comments

Piracy Operation COLLECTiVE Dismantled, Uploader 'Will1869' Arrested in UK

https://torrentfreak.com/piracy-group-collective-dismantled-uploader-will1869-arrested-by-uk-police-250520/
2•swat535•37m ago•0 comments

Failure Mechanisms in Democratic Regimes – An Army's Role

https://angrystaffofficer.com/2025/03/02/failure-mechanisms-in-democratic-regimes-an-armys-role/
5•tkgally•42m ago•0 comments

Convince OpenBSD developers to allow an executable get the path to itself (2020)

https://github.com/ziglang/zig/issues/6718
2•silasdb•44m ago•0 comments

Show HN: MongoDB on Cloudflare Workers with Do

https://github.com/eashish93/mongodb-with-do
2•eashish93•45m ago•0 comments

Spruce trees communicate during a solar eclipse

https://phys.org/news/2025-04-forest-sync-spruce-trees-communicate.html
1•geox•47m ago•0 comments

Sex, Drugs, Power, and Money

http://funcall.blogspot.com/2025/05/more-bullshit.html
1•dxs•50m ago•0 comments

Two disinformation experts have launched a DIY news outlet

https://www.poynter.org/fact-checking/2025/indicator-alexios-mantzarlis-craig-silverman/
3•gnabgib•59m ago•0 comments

On this Chinese island, patients are trying latest experimental drugs for cancer

https://www.scmp.com/news/china/science/article/3310623/chinese-island-patients-are-trying-latest-experimental-drugs-cancer
1•larrysalibra•1h ago•0 comments

Domain Theory Lecture Notes

https://liamoc.net/forest/dt-001Y/index.xml
3•todsacerdoti•1h ago•0 comments

Lessons in company building ft. Mr. Beast

https://www.jeetmehta.com/posts/mr-beast-handbook
1•j4mehta•1h ago•0 comments

Introducing Researcher and Analyst in Microsoft 365 Copilot

https://www.microsoft.com/en-us/microsoft-365/blog/2025/03/25/introducing-researcher-and-analyst-in-microsoft-365-copilot/
2•gfortaine•1h ago•0 comments

How MCP works as standalone client/Server and with LLM

https://github.com/oneness/ts-mcp-client-server
1•birkey•1h ago•1 comments

The Dawn of Liquid Content

https://genarrative.substack.com/p/the-dawn-of-liquid-content
1•gwintrob•1h ago•0 comments

MIT physicists discover a new type of superconductor that's also a magnet

https://news.mit.edu/2025/mit-physicists-discover-new-type-superconductor-also-magnet-0522
8•pseudolus•1h ago•0 comments

OpenAI Says It Will Build Massive Data Centers in the UAE

https://www.nytimes.com/2025/05/22/technology/openai-uae-data-centers.html
2•bookofjoe•1h ago•1 comments

Compressed-Air Car

https://en.wikipedia.org/wiki/Compressed-air_car
3•FridayoLeary•1h ago•0 comments

When you belong nowhere, you choose somewhere to call home

https://www.startingfromnix.com/p/when-you-belong-nowhere-you-choose
1•jger15•1h ago•0 comments

Improving performance of original dav1d video decoder

https://code.videolan.org/videolan/dav1d/-/merge_requests/1788
1•ycomb_anon•1h ago•1 comments

You've been looking at PC-98 graphics wrong your whole life (2024)

https://pleromanonx86.wordpress.com/2024/09/02/youve-been-looking-at-pc-98-graphics-wrong-your-whole-life/
1•zdw•1h ago•0 comments