Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For one thing, it's hard to imagine an amount of money that would be simultaneously large enough to entice an Apple engineer to risk his job and reputation, but small enough to not trigger questions about where it came from. You'd have to concoct elaborate schemes that convince the IRS to look the other way, or target someone who could be blackmailed without fear that they'll run immediately to the authorities or their boss. Not anywhere near as easy or safe as handing over a bag of cash.

If I were the NSA, a strategy with much lower variance would be to hire a lot of smart folks to do the intense security reviews and testing that Apple (and many other companies, presumably) fail to do, and try to find bugs before they're patched. As tptacek has pointed out, there are plenty of these, and an organization with the resources of the NSA can probably find them frequently enough for most purposes without sticking its neck out.



> If I were the NSA, a strategy with much lower variance would be to hire a lot of smart folks to do the intense security reviews and testing that Apple (and many other companies, presumably) fail to do, and try to find bugs before they're patched.

Very very good point.

Until you made it, I might have thought "well of course NSA looks for bugs to exploit", but I didn't think through the implications.

Here we have Apple open sourcing their security code. They made the NSA's job 10x easier than w/o the source. So of course the NSA will lint and review and test and exploit Apple's source code. Intensively. It's low-hanging fruit, of the Apple variety. :)


>it's hard to imagine an amount of money that would be simultaneously large enough to entice an Apple engineer to risk his job and reputation

The odds are that this engineer will never be revealed publicly, and it will not effect his/her reputation in any way.

>but small enough to not trigger questions about where it came from.

You don't think that the NSA has the ability to hide money?


Surely this hypothetical bribed engineer will be identified during Apple's post-mortem. Hopefully he's a good liar, otherwise the NSA risks exposure that way. Even if he's a terrific liar, of course his reputation will be hurt: His 'mistake' caused Apple a major PR hit and engineering scramble that likely cost millions of dollars.

And for what? The NSA can hide money, but you or I would quickly find ourselves talking with the IRS if our spending or bank accounts rose dramatically without a commensurate rise in reported income. We could probably hide a few thousand dollars a month under the table, but that doesn't sound like it would turn the head of even a particularly amoral Apple engineer already making six figures.

I'm not saying this scenario is impossible. But to be plausible, it requires both the perpetrator and the NSA to take on a degree of risk that doesn't seem to match the reward for either.

If this is standard procedure for the NSA and happens often, given the risk involved, why hasn't anyone been caught at it and publicly exposed?

If the NSA made an exception and executed some unusually elaborate cloak and dagger to seduce or blackmail an Apple employee for this change, why do we think it was for this vulnerability and not the dozens of others that are discovered annually?


Since we're at a nosebleed altitude of hypothetical here, I think now might be the time to point out that this thread is demanding that people prove a negative.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: