Live data from Hacker News

Apple to contribute to U.S. teen's education for spotting FaceTime bug

reuters.com

21–30 of 142 posts

Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug

#21
post #2

> "In addition to addressing the bug that was reported, our team conducted a thorough security audit of the FaceTime service..." Why would they have not done this in the first place? Apple has more money than they know what to do with, why not have teams of people banging away on this stuff? The actual exploit was incredibly simple.

What makes you think this was the first audit? Shipping a bug doesn't imply that zero QA was done.

Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug

#23
post #13

Nice. Still should have responded to them faster. Someone at Apple just dropped the ball when they got the report.

I don't think it is any specific "someone." I think Apple's policies/procedures itself are more at fault.

The fact that there's no way clear route to submitting security issues if you aren't a registered developer is problematic.

Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug

#24

Does offering to contribute to someone's education sound to anyone else like they're criticising his current level of education? Seems like an insult? Like 'we'll pay for you to get a better education so next time you'll know how to speak to us correctly.' Why don't they just give him cash compensation if they want to apologise?

There are laws around the ways in which you can compensate minors. This may be the most reasonable way to pay the kid. That said, I assume the decision to make it an educational grant was not made without consultation with the family.

Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug

#26
post #11

Does offering to contribute to someone's education sound to anyone else like they're criticising his current level of education? Seems like an insult? Like 'we'll pay for you to get a better education so next time you'll know how to speak to us correctly.' Why don't they just give him cash compensation if they want to apologise?

They don't want to set a precedent of people blackmailing with a bug like rumours say he tried. The bounty program sets a price an avoid exploitation on both sides. Respecting that was more important. Paying a scholarship allows Apple to send a valuable transfer but no cash, rewarding the discovery without setting a precedent.

> They don't want to set a precedent of people blackmailing with a bug like rumours say he tried.

You're creating rumors, not reporting them.

You can read the letter they sent to Apple. That wasn't even the first attempt at contact and all they asked about is if there were any bug bounties available.

Nobody tried to blackmail anyone by simply asking if the bug may be eligible for a bounty.

Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug

#27

Feels like the headline here should be related to bug itself, the amount of privacy it violated, and how long it took Apple to fix it! Clearly a good PR move for Apple.

[deleted]

Why do you expect some random member of the public to obey an arbitrary rule from the infosec community that they don't even all agree on?

Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug

#28

Earlier quoted context omitted.

It sounded to me like they're offering to contribute to an already-existing college fund or start one.

Right... but why that? Do they think there's a problem with his education specifically? Why not give him cash and let him put it in an education fund, or a pension fund, or whatever he wants? Why say 'and you'll want to use this to increase your education'? Like buying him a voucher for a facelift.

The US values education quite a bit (I suspect other places do too, but I can only speak for US experience), and there's a long history of rewarding children with educational funds for all kinds of things. This is very commonplace.

As to why it's commonplace, well, if the family can afford to send the kid to college, then this is basically the same as giving them cash, since the family now gets to do what they want with the money they would have spent on his college. And if they couldn't afford to send him to college, now they can (or now they have a bit more help with it, depending on how much money was given). It looks good for the company too, since no one (except possibly you) thinks giving a kid an educational fund is a bad thing. Finally, by having such an educational stipulation, it hopefully prevents the parents (or legal guardians) from spending or wasting it on other things so that the kid ultimately reaps the benefits, which I think is prudent.

Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug

#29

Feels like the headline here should be related to bug itself, the amount of privacy it violated, and how long it took Apple to fix it! Clearly a good PR move for Apple.

Has that not already been the headline a dozen times?

Certainly Apple has deserved that scrutiny, but I was also waiting to see whether they'd do the right thing here.

Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug

#30
Only in the land of philanthropy is such a headline a thing, or even a PR move. So instead of giving the guardian of said teenager 200k to do with as they/he/she pleases in the interest of the child, you set up a education funding scheme? But when the government does it, it's what?
Post reply on HN