Live data from Hacker News

Apple says kernel vulnerability is not eligible for bounty

twitter.com

11–20 of 40 posts

Re: Apple says kernel vulnerability is not eligible for bounty

#13

Not a great look when many responses are "if the provider won't protect people, then the researcher should contemplate hurting people".

We live in a capitalist society that the companies at the very top absolutely love to exploit. They also love to exploit "but think of the ,," and so on.

Fuck you, pay me applies.

Re: Apple says kernel vulnerability is not eligible for bounty

#15
post #2

You can still get some reward for it on the dark web, surely.

Next time it's where it should go. Clearly Apple doesn't mind.

Promise of getting more money is not a justification for selling exploits to the criminals. Even if Apple had no bug bounty program, reporting it responsibly is the moral thing to do.

Re: Apple says kernel vulnerability is not eligible for bounty

#18

Not a great look when many responses are "if the provider won't protect people, then the researcher should contemplate hurting people".

I pin the responsibility on Apple. They created a bounty system which incentivized people to build their livelihoods around finding these issues. They subsequently decided they wouldn't pay out those incentives essentially at random. If putting food on the table means getting paid for vulnerabilities, it's only rational to sell your work to whoever else is going to pay for it. Apple _created this market_ (and, you might argue, put the vulnerability into production). The only bad look here is Apple, imo.

Re: Apple says kernel vulnerability is not eligible for bounty

#19

Not a great look when many responses are "if the provider won't protect people, then the researcher should contemplate hurting people".

We live in a capitalist society that the companies at the very top absolutely love to exploit. They also love to exploit "but think of the , , " and so on. Fuck you, pay me applies.

By this logic, you're not even pretending you're better than this. You're not angry at Apple because they love to exploit, you're angry at them because you're not powerful enough to exploit others too.

Do you agree with this statement? If not, I think there's a contradiction. You are morally obliged to do the right thing even if there are entities who don't.

Re: Apple says kernel vulnerability is not eligible for bounty

#20

Earlier quoted context omitted.

Next time it's where it should go. Clearly Apple doesn't mind.

Promise of getting more money is not a justification for selling exploits to the criminals. Even if Apple had no bug bounty program, reporting it responsibly is the moral thing to do.

And that's the reason hacking does not exist
Post reply on HN