I wonder if they are backfilling rewards to any of the external researchers who have been doing all of Apple's security research for the last decade. Just as an example, a single researcher from Google is credited with 11 separate vulnerabilities that would qualify for the $50k reward, in a single patchlevel of OS X (and the same person had five such credits in the patchlevel prior to that!). That's almost a million…
I don't think it would make economical sense for Apple to pay for something that they already got for free.
Apple announces bug bounty program
31–40 of 107 posts
Re: Apple announces bug bounty program
#32Earlier quoted context omitted.
Problem is - that's such an easy thing to say, whether it's true or false. For a device that's owned by millions, it's pretty grandiose of them to think that their internal team is all it takes. There's so much an internal team can do, so having an outside "team" is significantly better - even if it's just for a different view from a different vantage point. So, good on apple for doing this, but I'm questioning their…
I think it's more like Apple is patient and waits to get things right. Bug bounty programs are relatively new (past few years). The article notes that Apple faced a more complicated landscape than your typical company, one where state actors are bidders. So they needed to craft a more targeted program.
Re: Apple announces bug bounty program
#33I'm not familiar with the market but these seem low when you consider: - The effort required to find them - The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales, e.g. The SEP implications for ApplePay - The damage that can be inflicted on users and 3rd parties, e.g. imagine the amount of cash banks would be on the hook for if someone managed to say write a worm that us…
Re: Apple announces bug bounty program
#34Re: Apple announces bug bounty program
#35Earlier quoted context omitted.
I don't think it would make economical sense for Apple to pay for something that they already got for free.
Sure, but it would be a gesture of goodwill and a way of making amends for years of freeloading.
Re: Apple announces bug bounty program
#36As mentioned the program is currently invite only currently (ie, https://twitter.com/i0n1c/status/761349794510036992 )
From the article: > However, Apple won’t turn away new researchers if they provide useful disclosures, and plans to slowly expand the program. I'm reading this as: if you find a serious bug and report it, you'll get the money.
No idea if that's right though.
Re: Apple announces bug bounty program
#37Can't wait for "We pioneered InfoSec by our first-of-kind innovative bug bounty program" @ next WWDC.
Re: Apple announces bug bounty program
#38Earlier quoted context omitted.
From the article: > However, Apple won’t turn away new researchers if they provide useful disclosures, and plans to slowly expand the program. I'm reading this as: if you find a serious bug and report it, you'll get the money.
I read that as: if you find a bug and report it, you may get invited into the formal bug bounty program (but may not get a payout on the first one). No idea if that's right though.
>Apple said it decided to limit the scope of the program at the advice of other companies that have previously launched bounty programs.
Those companies said that if they were to do it again, they would start by inviting a small list of researchers to join, then gradually open it up over time, according to Apple.
Security analyst Rich Mogull said that limiting participation would save Apple from dealing with a deluge of "low-value" bug reports.
"Fully open programs can definitely take a lot of resources to manage," he said.
http://www.reuters.com/article/us-cyber-blackhat-apple-idUSK...
Re: Apple announces bug bounty program
#39As mentioned the program is currently invite only currently (ie, https://twitter.com/i0n1c/status/761349794510036992 )
From the article: > However, Apple won’t turn away new researchers if they provide useful disclosures, and plans to slowly expand the program. I'm reading this as: if you find a serious bug and report it, you'll get the money.
If you do good work and report it, you'll get paid accordingly.
Re: Apple announces bug bounty program
#40Earlier quoted context omitted.
Sure, but it would be a gesture of goodwill and a way of making amends for years of freeloading.
That guy did 10 more after the first freebie. Could it be that something else was motivating him?