Apple announces bug bounty program
101–107 of 107 posts
Re: Apple announces bug bounty program
#102I've once found security bug on OS X/Mac (low chance of occuring, however gives complete access), reported complete steps to reproduce and solutions - received moreless copy-pasted response - two years, two OS X versions later - the bug is still there, even though it looks like 5 minutes fix...
Re: Apple announces bug bounty program
#103Earlier quoted context omitted.
Are there? Are there really? Because my experience on the internet is a few happy Apple customers and a monstrous tidal wave of anti-Apple hate. And it's a different kind of hate too. Apple fans like to criticize Microsoft and Google, but Apple haters generally attack Apple fans , not Apple itself. It's very disheartening.
Well, to me it's more like the VI/Emacs rivalry. It's fun to poke at each other so long as things remains civil. But note--people make fun of Apple fans because they are crazy--have you seen the lines when the iPhone 6 came out? I mean seriously. :)
Its this kind of sweeping generalisation that brings the tone of the whole site down.
Re: Apple announces bug bounty program
#104I've once found security bug on OS X/Mac (low chance of occuring, however gives complete access), reported complete steps to reproduce and solutions - received moreless copy-pasted response - two years, two OS X versions later - the bug is still there, even though it looks like 5 minutes fix...
Report it again, take the bounty?
Re: Apple announces bug bounty program
#105Earlier quoted context omitted.
Yeah but, they do take credit like that. And I'm one of their biggest fans. Edit: oh, the downvotes, not because facts, but because dislike? "He will go through a process of looking at my ideas and say, ‘That’s no good. That’s not very good. I like that one.’ And later I will be sitting in the audience and he will be talking about it as if it was his idea. I pay maniacal attention to where an idea comes from, and I e…
Cherry picking
Re: Apple announces bug bounty program
#106Earlier quoted context omitted.
That setup doesn't make any sense to me. Either its an open program or a closed program. A closed program that allows submissions from others is an open program. What reasons what they have to do it this way? My first guess is to tick some checkbox.
It's pretty straightforward. Apple wants to start off slow, with a small group of people, and develop the quality of the program. By being explicitly closed, but implicitly open, they can focus their energy on the invited researchers, and ensure a high-level of support/response. If they had explicitly said that it was an open program, they would have had to scale up their efforts to support the entire world of vulner…
Thanks, that does make a lot of sense.
My main exposure to bug bounty programs has been through the blog post of submitters, that don't give much insight to the resources/support that e.g. Apple would need to give.
Re: Apple announces bug bounty program
#107Earlier quoted context omitted.
It's pretty straightforward. Apple wants to start off slow, with a small group of people, and develop the quality of the program. By being explicitly closed, but implicitly open, they can focus their energy on the invited researchers, and ensure a high-level of support/response. If they had explicitly said that it was an open program, they would have had to scale up their efforts to support the entire world of vulner…
> Put another way - if you are not part of the invited group, and you submit an issue, but do so poorly, or without a clear Proof-of-Concept, and concise description, you can reasonably expect to hear no response from Apple, with no grounds to complain that they ignored you. But, at the same time, if you have a clear exploit, well documented, with impact and proof-of-concept, then their is still an avenue to submit i…