Live data from Hacker News

Apple announces bug bounty program

techcrunch.com

31–40 of 107 posts

Re: Apple announces bug bounty program

#31

I wonder if they are backfilling rewards to any of the external researchers who have been doing all of Apple's security research for the last decade. Just as an example, a single researcher from Google is credited with 11 separate vulnerabilities that would qualify for the $50k reward, in a single patchlevel of OS X (and the same person had five such credits in the patchlevel prior to that!). That's almost a million…

I don't think it would make economical sense for Apple to pay for something that they already got for free.

Sure, but it would be a gesture of goodwill and a way of making amends for years of freeloading.

Re: Apple announces bug bounty program

#32
post #26
post #23

Earlier quoted context omitted.

Problem is - that's such an easy thing to say, whether it's true or false. For a device that's owned by millions, it's pretty grandiose of them to think that their internal team is all it takes. There's so much an internal team can do, so having an outside "team" is significantly better - even if it's just for a different view from a different vantage point. So, good on apple for doing this, but I'm questioning their…

I think it's more like Apple is patient and waits to get things right. Bug bounty programs are relatively new (past few years). The article notes that Apple faced a more complicated landscape than your typical company, one where state actors are bidders. So they needed to craft a more targeted program.

This seems like a pretty generic reason that doesn't explain that much. Are state actors not bidders on gmail, android, facebook, firefox, chrome?

Re: Apple announces bug bounty program

#33

I'm not familiar with the market but these seem low when you consider: - The effort required to find them - The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales, e.g. The SEP implications for ApplePay - The damage that can be inflicted on users and 3rd parties, e.g. imagine the amount of cash banks would be on the hook for if someone managed to say write a worm that us…

As tptacek loves to point out, the point of bug bounty programs is not to compete on price with the black market. And in fact, according to the article, the $200k Apple is offering is one of the highest for corporate bug bounty programs already.

Re: Apple announces bug bounty program

#35

Earlier quoted context omitted.

I don't think it would make economical sense for Apple to pay for something that they already got for free.

Sure, but it would be a gesture of goodwill and a way of making amends for years of freeloading.

That guy did 10 more after the first freebie. Could it be that something else was motivating him?

Re: Apple announces bug bounty program

#36
post #11
post #3

As mentioned the program is currently invite only currently (ie, https://twitter.com/i0n1c/status/761349794510036992 )

From the article: > However, Apple won’t turn away new researchers if they provide useful disclosures, and plans to slowly expand the program. I'm reading this as: if you find a serious bug and report it, you'll get the money.

I read that as: if you find a bug and report it, you may get invited into the formal bug bounty program (but may not get a payout on the first one).

No idea if that's right though.

Re: Apple announces bug bounty program

#38
post #36
post #11

Earlier quoted context omitted.

From the article: > However, Apple won’t turn away new researchers if they provide useful disclosures, and plans to slowly expand the program. I'm reading this as: if you find a serious bug and report it, you'll get the money.

I read that as: if you find a bug and report it, you may get invited into the formal bug bounty program (but may not get a payout on the first one). No idea if that's right though.

The Reuters report has some details about why they limited it:

>Apple said it decided to limit the scope of the program at the advice of other companies that have previously launched bounty programs.

Those companies said that if they were to do it again, they would start by inviting a small list of researchers to join, then gradually open it up over time, according to Apple.

Security analyst Rich Mogull said that limiting participation would save Apple from dealing with a deluge of "low-value" bug reports.

"Fully open programs can definitely take a lot of resources to manage," he said.

http://www.reuters.com/article/us-cyber-blackhat-apple-idUSK...

Re: Apple announces bug bounty program

#39
post #11
post #3

As mentioned the program is currently invite only currently (ie, https://twitter.com/i0n1c/status/761349794510036992 )

From the article: > However, Apple won’t turn away new researchers if they provide useful disclosures, and plans to slowly expand the program. I'm reading this as: if you find a serious bug and report it, you'll get the money.

I haven't read the article, but I was at the announcement and your take is exactly how it was clarified in the room.

If you do good work and report it, you'll get paid accordingly.

Re: Apple announces bug bounty program

#40

Earlier quoted context omitted.

Sure, but it would be a gesture of goodwill and a way of making amends for years of freeloading.

That guy did 10 more after the first freebie. Could it be that something else was motivating him?

I believe the researcher in question works for project 0.
Post reply on HN