Live data from Hacker News

Apple announces bug bounty program

techcrunch.com

101–107 of 107 posts

Re: Apple announces bug bounty program

#101
I've once found security bug on OS X/Mac (low chance of occuring, however gives complete access), reported complete steps to reproduce and solutions - received moreless copy-pasted response - two years, two OS X versions later - the bug is still there, even though it looks like 5 minutes fix...

Re: Apple announces bug bounty program

#102

I've once found security bug on OS X/Mac (low chance of occuring, however gives complete access), reported complete steps to reproduce and solutions - received moreless copy-pasted response - two years, two OS X versions later - the bug is still there, even though it looks like 5 minutes fix...

Report it again, take the bounty?

Re: Apple announces bug bounty program

#103

Earlier quoted context omitted.

Are there? Are there really? Because my experience on the internet is a few happy Apple customers and a monstrous tidal wave of anti-Apple hate. And it's a different kind of hate too. Apple fans like to criticize Microsoft and Google, but Apple haters generally attack Apple fans , not Apple itself. It's very disheartening.

Well, to me it's more like the VI/Emacs rivalry. It's fun to poke at each other so long as things remains civil. But note--people make fun of Apple fans because they are crazy--have you seen the lines when the iPhone 6 came out? I mean seriously. :)

> Apple fans because they are crazy

Its this kind of sweeping generalisation that brings the tone of the whole site down.

Re: Apple announces bug bounty program

#104
post #102

I've once found security bug on OS X/Mac (low chance of occuring, however gives complete access), reported complete steps to reproduce and solutions - received moreless copy-pasted response - two years, two OS X versions later - the bug is still there, even though it looks like 5 minutes fix...

Report it again, take the bounty?

the problem with current state of the bounty program is that it's invitation-only (i'm no security researcher) and ios-centered :/

Re: Apple announces bug bounty program

#105
post #65

Earlier quoted context omitted.

Yeah but, they do take credit like that. And I'm one of their biggest fans. Edit: oh, the downvotes, not because facts, but because dislike? "He will go through a process of looking at my ideas and say, ‘That’s no good. That’s not very good. I like that one.’ And later I will be sitting in the audience and he will be talking about it as if it was his idea. I pay maniacal attention to where an idea comes from, and I e…

Cherry picking

LOL.

Re: Apple announces bug bounty program

#106
post #66

Earlier quoted context omitted.

That setup doesn't make any sense to me. Either its an open program or a closed program. A closed program that allows submissions from others is an open program. What reasons what they have to do it this way? My first guess is to tick some checkbox.

It's pretty straightforward. Apple wants to start off slow, with a small group of people, and develop the quality of the program. By being explicitly closed, but implicitly open, they can focus their energy on the invited researchers, and ensure a high-level of support/response. If they had explicitly said that it was an open program, they would have had to scale up their efforts to support the entire world of vulner…

> Put another way - if you are not part of the invited group, and you submit an issue, but do so poorly, or without a clear Proof-of-Concept, and concise description, you can reasonably expect to hear no response from Apple, with no grounds to complain that they ignored you. But, at the same time, if you have a clear exploit, well documented, with impact and proof-of-concept, then their is still an avenue to submit it to Apple, but it's up to Apple to decide how they wish to prioritize.

Thanks, that does make a lot of sense.

My main exposure to bug bounty programs has been through the blog post of submitters, that don't give much insight to the resources/support that e.g. Apple would need to give.

Re: Apple announces bug bounty program

#107
post #106

Earlier quoted context omitted.

It's pretty straightforward. Apple wants to start off slow, with a small group of people, and develop the quality of the program. By being explicitly closed, but implicitly open, they can focus their energy on the invited researchers, and ensure a high-level of support/response. If they had explicitly said that it was an open program, they would have had to scale up their efforts to support the entire world of vulner…

> Put another way - if you are not part of the invited group, and you submit an issue, but do so poorly, or without a clear Proof-of-Concept, and concise description, you can reasonably expect to hear no response from Apple, with no grounds to complain that they ignored you. But, at the same time, if you have a clear exploit, well documented, with impact and proof-of-concept, then their is still an avenue to submit i…

The actual effort is pretty minimal - 2-3 FTEs for a closed bounty program, plus maybe another 15-20 FTEs or so to assist with triage once it's opened up - total cost for Apple to set up a bug bounty is on the order of $5million/year staffing. Its more the trying to scale up so you don't end up annoying people by not being responsive - it takes time to hire the people and train them.
Post reply on HN