Live data from Hacker News

Apple announces bug bounty program

techcrunch.com

11–20 of 107 posts

Re: Apple announces bug bounty program

#11
post #3

As mentioned the program is currently invite only currently (ie, https://twitter.com/i0n1c/status/761349794510036992 )

From the article:

>However, Apple won’t turn away new researchers if they provide useful disclosures, and plans to slowly expand the program.

I'm reading this as: if you find a serious bug and report it, you'll get the money.

Re: Apple announces bug bounty program

#12
post #4

I'm a bit surprised, because you'd think that they'd have been doing this already.

I had the.. pleasure.. of speaking to Comcast's CISO after doing a security risk exposure disclosure. Before talking to her, there were mentions of bug bounties, etc (neat). After talking to her, though, she said in a hand-wavy way that: 1. The exposure wasn't a "bug", so it's not worth a bug bounty. 2. The amount of effort it would take to start a bug bounty program would be far too cost prohibitive. In other words,…

That is Comcast's reasoning, not Apple's. As the article notes, it's the opposite problem: Apple's internal team is running out of vulns to find.

Re: Apple announces bug bounty program

#14
post #10

The question is will they pay $1,000,000 for an exploit that unlocks an iphone? http://www.reuters.com/article/us-apple-encryption-idUSKCN0X...

The article already addresses this:

  While $200,000 is certainly a sizable reward — one of the
  highest offered in corporate bug bounty programs — it won’t
  beat the payouts researchers can earn from law enforcement or
  the black market. The FBI reportedly paid nearly $1 million
  for the exploit it used to break into an iPhone used by Syed
  Farook, one of the individuals involved in the San Bernardino
  shooting last December.
Interestingly, for altruistic / independently wealthy researchers there's an incentive to report to Apple:

  In an unusual twist, Apple plans to encourage researchers to
  donate their earnings to charity. If Apple approves of a
  researcher’s selected institution, it will match their donation —
  so a $200,000 reward could turn into a $400,000 donation.

Re: Apple announces bug bounty program

#15
post #9

Wonder if they'll include their servers too; appears they're only doing the most recently released OS and hardware.

Towards the bottom of the article they note this:

  The program launches in September with five categories of risk and reward:

  Vulnerabilities in secure boot firmware components: Up to $200,000
  Vulnerabilities that allow extraction of confidential material from Secure Enclave: Up to $100,000
  Executions of arbitrary or malicious code with kernel privileges: Up to $50,000
  Access to iCloud account data on Apple servers: Up to $50,000
  Access from a sandboxed process to user data outside the sandbox: Up to $20,000

Re: Apple announces bug bounty program

#16
I'm not familiar with the market but these seem low when you consider:

- The effort required to find them

- The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales, e.g. The SEP implications for ApplePay

- The damage that can be inflicted on users and 3rd parties, e.g. imagine the amount of cash banks would be on the hook for if someone managed to say write a worm that used iMessage/SMS to propagate without user knowledge (e.g. with the recent TIFF vulnerability), and transfer funds from the user's bank account? Or made calls to the baseband to dial shady $10/minute premium rate numbers in some banana republic at 3AM every night?

- The amount of money TLAs and black market actors allegedly pay per the TC article.

- How much money Apple actually has, especially all the offshore cash that can't be repatriated to the US without incurring exorbitant capital gains. These bug bounties could be be remitted from any Apple subsidiary.

- Large bug bounties would de facto end jailbreaking

- Knowing Apple there would be endless NDAs and restrictive covenants before any payout is made.

IMO with all this considered the max payouts seem irrationally paltry.

Re: Apple announces bug bounty program

#17

I'm not familiar with the market but these seem low when you consider: - The effort required to find them - The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales, e.g. The SEP implications for ApplePay - The damage that can be inflicted on users and 3rd parties, e.g. imagine the amount of cash banks would be on the hook for if someone managed to say write a worm that us…

No doubt there's going to be some low-hanging fruit (speaking relative to the experience of the participants) that is going to get scooped up quickly, so why would they open the program at something higher? Just high enough to entice the experts to pick off the "easy" ones seems the intelligent thing to do.

When they go a year or two with no bugs found maybe you'll see them start upping the bid.

Re: Apple announces bug bounty program

#18
post #14
post #10

The question is will they pay $1,000,000 for an exploit that unlocks an iphone? http://www.reuters.com/article/us-apple-encryption-idUSKCN0X...

The article already addresses this: While $200,000 is certainly a sizable reward — one of the highest offered in corporate bug bounty programs — it won’t beat the payouts researchers can earn from law enforcement or the black market. The FBI reportedly paid nearly $1 million for the exploit it used to break into an iPhone used by Syed Farook, one of the individuals involved in the San Bernardino shooting last Decembe…

Smart move. That's not too shabby of a tax deduction.

Re: Apple announces bug bounty program

#19
post #12
post #4

Earlier quoted context omitted.

I had the.. pleasure.. of speaking to Comcast's CISO after doing a security risk exposure disclosure. Before talking to her, there were mentions of bug bounties, etc (neat). After talking to her, though, she said in a hand-wavy way that: 1. The exposure wasn't a "bug", so it's not worth a bug bounty. 2. The amount of effort it would take to start a bug bounty program would be far too cost prohibitive. In other words,…

That is Comcast's reasoning, not Apple's. As the article notes, it's the opposite problem: Apple's internal team is running out of vulns to find.

Well this guy has a bunch of ideas on how they can improve ;) https://twitter.com/i0n1c

Re: Apple announces bug bounty program

#20

I'm not familiar with the market but these seem low when you consider: - The effort required to find them - The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales, e.g. The SEP implications for ApplePay - The damage that can be inflicted on users and 3rd parties, e.g. imagine the amount of cash banks would be on the hook for if someone managed to say write a worm that us…

>- The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales

There is quite a bit of history where Apple has ignored security researchers who have identified vulnerabilities for quite some time before they were resolved.

Post reply on HN