Live data from Hacker News

Apple Security Bounty

developer.apple.com

1–10 of 19 posts

Re: Apple Security Bounty

#2
Facebook: https://www.facebook.com/whitehat

Amazon: https://aws.amazon.com/security/vulnerability-reporting/

Netflix: https://help.netflix.com/en/node/6657

Google: https://www.google.com/about/appsecurity/programs-home/

Microsoft: https://www.microsoft.com/en-us/msrc/bounty

More: https://www.ubuntupit.com/best-bug-bounty-programs-on-intern...

Re: Apple Security Bounty

#5

Facebook: https://www.facebook.com/whitehat Amazon: https://aws.amazon.com/security/vulnerability-reporting/ Netflix: https://help.netflix.com/en/node/6657 Google: https://www.google.com/about/appsecurity/programs-home/ Microsoft: https://www.microsoft.com/en-us/msrc/bounty More: https://www.ubuntupit.com/best-bug-bounty-programs-on-intern...

Facebook - No dollar amounts listed but "If we pay a bounty it will be a minimum $500"

Amazon and Netflix, no dollar amounts listed

Microsoft offers up to $250k for "Critical remote code execution, information disclosure and denial of services vulnerabilities in Hyper-V"

Ironically that google page dumped a bunch of html into my browser, including a "script nonce" and a function definition:

    (function(H){H.className=H.className.replace(/\bgoogle\b/,'google-js')})(document.documentElement)
I'll be waiting for a cheque from them, I suppose.

Re: Apple Security Bounty

#6
post #3

Is this new? Is that why it's being posted?

Prior to now this program was invite only. They are blowing it open to all security researchers as of today.

https://apple.news/A4h_BM9HqTjSpsWKsrVPGBw

Also, max payout has been bumped to $1.5m which is a pretty big change. Most of this was announced a few months ago, they are just making good on a previous announcement at this point.

Re: Apple Security Bounty

#7
post #3

Is this new? Is that why it's being posted?

Yeah this is old? https://www.theverge.com/2016/8/4/12380036/apple-bug-bounty-... This is 4 years old? (2016 should be added to title.

The bug bounty is no longer invite-only, and the maximum payouts have been increased.

Re: Apple Security Bounty

#9
post #3

Is this new? Is that why it's being posted?

Prior to now this program was invite only. They are blowing it open to all security researchers as of today. https://apple.news/A4h_BM9HqTjSpsWKsrVPGBw Also, max payout has been bumped to $1.5m which is a pretty big change. Most of this was announced a few months ago, they are just making good on a previous announcement at this point.

Thanks for the context. As a user of Apple devices, I'm excited about the increased attention to security!

Re: Apple Security Bounty

#10
Critically, there's no information about whether reporters are allowed to disclose, which usually means that Apple is going to hide any seriously damaging vulnerabilities...
Post reply on HN