Live data from Hacker News

Apple says kernel vulnerability is not eligible for bounty

twitter.com

1–10 of 40 posts

Re: Apple says kernel vulnerability is not eligible for bounty

#3
Is this normal? I’m only ancillary to security stuff like this but without details of the exploit it’s hard to say whether or not this is scandalous or not. It’s possible Apple made a mistake here, but is that a more likely scenario than the vuln just not being exploitable enough to warrant a bounty?

Re: Apple says kernel vulnerability is not eligible for bounty

#5

Is this normal? I’m only ancillary to security stuff like this but without details of the exploit it’s hard to say whether or not this is scandalous or not. It’s possible Apple made a mistake here, but is that a more likely scenario than the vuln just not being exploitable enough to warrant a bounty?

Bug bounties are a social solution to a social problem. In many ways, the actual money is less important than being seen to earnestly engage with the programme.

Being hard-nosed about refusing to pay a bounty on a privilege escalation bug is a rookie mistake. It engenders ill will and cements your relationship with security researchers as adversarial rather than cooperative.

Re: Apple says kernel vulnerability is not eligible for bounty

#6
No idea why is Apple being greedy here. They have enough money and there are going to be buyers out there, who are going to have other intentions, which could become much more expensive for Apple. Save a cent to lose dollar kind of situation.

Re: Apple says kernel vulnerability is not eligible for bounty

#7
This kind of shit makes all of their customers less safe.

When people realise this is what they can expect from Apple they will just sell these exploits to intelligence agencies instead for who knows what purpose.

So congratulations Apple of fucking over not just this person but your entire customer base for years to come. Morons.

Re: Apple says kernel vulnerability is not eligible for bounty

#8

Is this normal? I’m only ancillary to security stuff like this but without details of the exploit it’s hard to say whether or not this is scandalous or not. It’s possible Apple made a mistake here, but is that a more likely scenario than the vuln just not being exploitable enough to warrant a bounty?

This is very much not normal and is absolutely a scandal.

Re: Apple says kernel vulnerability is not eligible for bounty

#9

Is this normal? I’m only ancillary to security stuff like this but without details of the exploit it’s hard to say whether or not this is scandalous or not. It’s possible Apple made a mistake here, but is that a more likely scenario than the vuln just not being exploitable enough to warrant a bounty?

It was notable enough to be mentioned in their release notes for iOS 17.5, https://support.apple.com/en-gb/HT214101. I think that if they have to patch it, it's serious enough to reward the researcher for it. Like, it's not charity, it's not a thank you, it's an investment in their own platform's security. By not paying out they are only hurting themselves.
Post reply on HN