Live data from Hacker News

Apple says kernel vulnerability is not eligible for bounty

twitter.com

31–40 of 40 posts

Re: Apple says kernel vulnerability is not eligible for bounty

#31
post #25

Earlier quoted context omitted.

Here are the categories: https://security.apple.com/bounty/categories/ I'm not really sure what else you're asking for. Nobody in the world except Apple Product Security itself knows why Apple Product Security is refusing to pay a bounty in this case. It makes no sense.

Well. He knows more about the exploit. Maybe he could tell us what it is.

He did: https://twitter.com/R00tkitSMM/status/1790391961737711697

Satisfied now?

Re: Apple says kernel vulnerability is not eligible for bounty

#32

No idea why is Apple being greedy here. They have enough money and there are going to be buyers out there, who are going to have other intentions, which could become much more expensive for Apple. Save a cent to lose dollar kind of situation.

Apple is often very stingy and greedy, but I don't think this is an example of this.

This is 'just' a skill issue. Culturally, it's seems this is not a process they're very good at running. A bunch of similarities to their App Review process which isn't well regarded.

Re: Apple says kernel vulnerability is not eligible for bounty

#33

I think this is actually the security researcher's fault. If you read the small print, this kernel bug doesn't meet the Bug Bounty Qualification Criteria of being on an OS that Apple actually gives a shit about.

Apple doesn't give a shit about iOS?

Re: Apple says kernel vulnerability is not eligible for bounty

#34
post #31

Earlier quoted context omitted.

Well. He knows more about the exploit. Maybe he could tell us what it is.

He did: https://twitter.com/R00tkitSMM/status/1790391961737711697 Satisfied now?

Yep. It explains why he didn’t get paid.

Re: Apple says kernel vulnerability is not eligible for bounty

#35

I think this is actually the security researcher's fault. If you read the small print, this kernel bug doesn't meet the Bug Bounty Qualification Criteria of being on an OS that Apple actually gives a shit about.

What exactly is their fault?

They did Apple a solid, but not in accordance with the precise terms as laid out by Apple, so it's perfectly justified for Apple to take the researcher's work for nothing?

Re: Apple says kernel vulnerability is not eligible for bounty

#36
post #8

Is this normal? I’m only ancillary to security stuff like this but without details of the exploit it’s hard to say whether or not this is scandalous or not. It’s possible Apple made a mistake here, but is that a more likely scenario than the vuln just not being exploitable enough to warrant a bounty?

This is very much not normal and is absolutely a scandal.

It's pretty normal for Apple, tbh.

They have a long history of refusing to pay bug bounties.

Re: Apple says kernel vulnerability is not eligible for bounty

#37

Not a great look when many responses are "if the provider won't protect people, then the researcher should contemplate hurting people".

It is a great look! We are forwarding-thinking people that realize security happens when companies have healthy bug bounty programs.

Re: Apple says kernel vulnerability is not eligible for bounty

#38
post #31

Earlier quoted context omitted.

Well. He knows more about the exploit. Maybe he could tell us what it is.

He did: https://twitter.com/R00tkitSMM/status/1790391961737711697 Satisfied now?

Updated from his twitter: apple apparently confirmed i am right and that it’s not exploitable in real user software. Still outraged?

Re: Apple says kernel vulnerability is not eligible for bounty

#39
post #31

Earlier quoted context omitted.

He did: https://twitter.com/R00tkitSMM/status/1790391961737711697 Satisfied now?

Updated from his twitter: apple apparently confirmed i am right and that it’s not exploitable in real user software. Still outraged?

I literally saved the link to this story in my "look again in a couple days" folder, and lo and behold, the story makes sense again.

Re: Apple says kernel vulnerability is not eligible for bounty

#40
post #8

Earlier quoted context omitted.

This is very much not normal and is absolutely a scandal.

It's pretty normal for Apple, tbh. They have a long history of refusing to pay bug bounties.

One has to wonder how many of the exploits out there don’t end up making their way to Cupertino as a result and what the consequences of that will be.
Post reply on HN