> "In addition to addressing the bug that was reported, our team conducted a thorough security audit of the FaceTime service..." Why would they have not done this in the first place? Apple has more money than they know what to do with, why not have teams of people banging away on this stuff? The actual exploit was incredibly simple.
Apple to contribute to U.S. teen's education for spotting FaceTime bug
21–30 of 142 posts
Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug
#22Feels like the headline here should be related to bug itself, the amount of privacy it violated, and how long it took Apple to fix it! Clearly a good PR move for Apple.
Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug
#23Nice. Still should have responded to them faster. Someone at Apple just dropped the ball when they got the report.
The fact that there's no way clear route to submitting security issues if you aren't a registered developer is problematic.
Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug
#24Does offering to contribute to someone's education sound to anyone else like they're criticising his current level of education? Seems like an insult? Like 'we'll pay for you to get a better education so next time you'll know how to speak to us correctly.' Why don't they just give him cash compensation if they want to apologise?
Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug
#25Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug
#26Does offering to contribute to someone's education sound to anyone else like they're criticising his current level of education? Seems like an insult? Like 'we'll pay for you to get a better education so next time you'll know how to speak to us correctly.' Why don't they just give him cash compensation if they want to apologise?
They don't want to set a precedent of people blackmailing with a bug like rumours say he tried. The bounty program sets a price an avoid exploitation on both sides. Respecting that was more important. Paying a scholarship allows Apple to send a valuable transfer but no cash, rewarding the discovery without setting a precedent.
You're creating rumors, not reporting them.
You can read the letter they sent to Apple. That wasn't even the first attempt at contact and all they asked about is if there were any bug bounties available.
Nobody tried to blackmail anyone by simply asking if the bug may be eligible for a bounty.
Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug
#27Feels like the headline here should be related to bug itself, the amount of privacy it violated, and how long it took Apple to fix it! Clearly a good PR move for Apple.
[deleted]
Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug
#28Earlier quoted context omitted.
It sounded to me like they're offering to contribute to an already-existing college fund or start one.
Right... but why that? Do they think there's a problem with his education specifically? Why not give him cash and let him put it in an education fund, or a pension fund, or whatever he wants? Why say 'and you'll want to use this to increase your education'? Like buying him a voucher for a facelift.
As to why it's commonplace, well, if the family can afford to send the kid to college, then this is basically the same as giving them cash, since the family now gets to do what they want with the money they would have spent on his college. And if they couldn't afford to send him to college, now they can (or now they have a bit more help with it, depending on how much money was given). It looks good for the company too, since no one (except possibly you) thinks giving a kid an educational fund is a bad thing. Finally, by having such an educational stipulation, it hopefully prevents the parents (or legal guardians) from spending or wasting it on other things so that the kid ultimately reaps the benefits, which I think is prudent.
Re: Apple to contribute to U.S. teen's education for spotting FaceTime bug
#29Feels like the headline here should be related to bug itself, the amount of privacy it violated, and how long it took Apple to fix it! Clearly a good PR move for Apple.
Certainly Apple has deserved that scrutiny, but I was also waiting to see whether they'd do the right thing here.