iCloud hacker would have warned apple had it provided a bug bounty
1–7 of 7 posts
Re: iCloud hacker would have warned apple had it provided a bug bounty
#2Re: iCloud hacker would have warned apple had it provided a bug bounty
#3Re: iCloud hacker would have warned apple had it provided a bug bounty
#4I thought apple discovered it was a social hack, not a technical one... Or is this just PR?
Apple is misleading the public because if I brute force anything then I go to jail. iCloud accounts were 'hacked' due to bad security implementations.
Re: iCloud hacker would have warned apple had it provided a bug bounty
#5I thought apple discovered it was a social hack, not a technical one... Or is this just PR?
The article mentions ethical hackers and researchers. This guy posted an unpatched vulnerability to github. Even without a bug bounty program he could have submitted a report, waited for patch, and then wrote it up for some PR. Instead forbes gives him credibility he doesn't deserve.
Re: iCloud hacker would have warned apple had it provided a bug bounty
#6Here's a simple rule of thumb: if you only responsibly report vulnerabilities when they're going to pay you, and otherwise you just publish them to github for everyone to use, you're not an ethical hacker.
Troshichev frames it like 'it's not my fault I posted this exploit to the internet, there was no bounty in place to prevent it!' He could well have reported it to their security teams and been happy with having contributed to the world, but instead he not only discussed the bug publicly, but published a tool allowing people to easily exploit it.
There is no point of view here where Troshichev is any sort of ethical 'good guy'. This is extortion, a thug saying 'Oh, that's really too bad about your windshield. If only there was some way you could pay someone to keep this from happening again. Who knows how bad it could be next time.'