Live data from Hacker News

A major evolution of Apple Security Bounty

security.apple.com

11–13 of 13 posts

Re: A major evolution of Apple Security Bounty

#11
post #5

A "major evolution" would be for Apple to have informative two-way conversations with security researchers and to stop stiffing them for reports. I submitted a few macOS reports to the program, but Apple just sat on them forever, sometimes years, until I got frustrated enough to just publicly disclose the bugs. Needless to say, Apple never paid me a dime. For that reason, I don't actively look for macOS bugs anymore,…

I think it's just reacting to the market; with MIE the cost of full chains probably go up significantly, and individual chains are worth less than what it would be when included in a full chain.

Individual chains of course are still eligible for rewards:

> Individual chain components or multiple components that cannot be linked together will remain eligible for rewards, though these are proportionally smaller to match their relative impact.

Edit:

I think those that build a full chain and attempt to sell to the regular posse would rather just take the bug bounty from Apple. There's little information about the 0day market for chains but from what I've seen it is you need to provide long term support and hoard alternative methods when different parts get discovered or break down. With MIE and other mitigations and vigilant scanning of devices, there's more chance exploits and techniques are discovered, patched, and you as VR/ED will only get a small fraction of the contract (like say $8m over a couple of years). (Someone from the 0day industry feel free to correct me.)

Re: A major evolution of Apple Security Bounty

#12
Curious how this target flag thing will work. I'm guessing each flag in the OS would be unique and possibly easy to discover. It is just when you submit your exploit/bypass to Apple in their verification environment where the security controls can't be bypassed, if you reveal the right flag they confirm the bounty?

Re: A major evolution of Apple Security Bounty

#13
post #10
post #5

A "major evolution" would be for Apple to have informative two-way conversations with security researchers and to stop stiffing them for reports. I submitted a few macOS reports to the program, but Apple just sat on them forever, sometimes years, until I got frustrated enough to just publicly disclose the bugs. Needless to say, Apple never paid me a dime. For that reason, I don't actively look for macOS bugs anymore,…

Yeah: this is all just noise, lies heaped upon lies. At times I've at least felt as if a few of the people involved internally "mean well", despite the company as a whole being evil... but, then I had to realize: their entirely-useless "sort of meaning well" was just causing me to slightly stall on going scorched earth on the entire program, so they were actually just yet another part of the problem. Apple--as a whol…

Companies aren’t evil or good, they’re companies.

People can be evil or good.

Post reply on HN