Live data from Hacker News

Apple announces bug bounty program

techcrunch.com

21–30 of 107 posts

Re: Apple announces bug bounty program

#23
post #12
post #4

Earlier quoted context omitted.

I had the.. pleasure.. of speaking to Comcast's CISO after doing a security risk exposure disclosure. Before talking to her, there were mentions of bug bounties, etc (neat). After talking to her, though, she said in a hand-wavy way that: 1. The exposure wasn't a "bug", so it's not worth a bug bounty. 2. The amount of effort it would take to start a bug bounty program would be far too cost prohibitive. In other words,…

That is Comcast's reasoning, not Apple's. As the article notes, it's the opposite problem: Apple's internal team is running out of vulns to find.

Problem is - that's such an easy thing to say, whether it's true or false. For a device that's owned by millions, it's pretty grandiose of them to think that their internal team is all it takes. There's so much an internal team can do, so having an outside "team" is significantly better - even if it's just for a different view from a different vantage point. So, good on apple for doing this, but I'm questioning their past decisions. In particular their poor use of "they ran out of things to find" is worth discussing. The way this article is worded, their stance sounds incredibly naive, where a, "We don't have the same breadth as the infosec research community, and we would like to work with them." response might have been more appropriate.

That's just my personal impression, though.

edit: autocorrect fix

Re: Apple announces bug bounty program

#26
post #23
post #12

Earlier quoted context omitted.

That is Comcast's reasoning, not Apple's. As the article notes, it's the opposite problem: Apple's internal team is running out of vulns to find.

Problem is - that's such an easy thing to say, whether it's true or false. For a device that's owned by millions, it's pretty grandiose of them to think that their internal team is all it takes. There's so much an internal team can do, so having an outside "team" is significantly better - even if it's just for a different view from a different vantage point. So, good on apple for doing this, but I'm questioning their…

I think it's more like Apple is patient and waits to get things right. Bug bounty programs are relatively new (past few years). The article notes that Apple faced a more complicated landscape than your typical company, one where state actors are bidders. So they needed to craft a more targeted program.

Re: Apple announces bug bounty program

#28

I'm a bit surprised, because you'd think that they'd have been doing this already.

Apple has slowly been opening up, they used to be such an incredibly secretive company under Jobs there's no way this would've ever happened.

Whoops. I just said "Steve Jobs never would've let this happen" line. Oh well.

They're letting in third-party keyboards another extensions, small additions to Siri, releasing actual software on android, it's not too surprising that they might be willing to do this now. Been very open on swift.

Re: Apple announces bug bounty program

#29
I wonder if they are backfilling rewards to any of the external researchers who have been doing all of Apple's security research for the last decade. Just as an example, a single researcher from Google is credited with 11 separate vulnerabilities that would qualify for the $50k reward, in a single patchlevel of OS X (and the same person had five such credits in the patchlevel prior to that!). That's almost a million bucks worth of rewards in only half a year of disclosures.

Re: Apple announces bug bounty program

#30

I wonder if they are backfilling rewards to any of the external researchers who have been doing all of Apple's security research for the last decade. Just as an example, a single researcher from Google is credited with 11 separate vulnerabilities that would qualify for the $50k reward, in a single patchlevel of OS X (and the same person had five such credits in the patchlevel prior to that!). That's almost a million…

I don't think it would make economical sense for Apple to pay for something that they already got for free.
Post reply on HN