Live data from Hacker News

Apple announces bug bounty program

techcrunch.com

41–50 of 107 posts

Re: Apple announces bug bounty program

#41
post #18
post #14

Earlier quoted context omitted.

The article already addresses this: While $200,000 is certainly a sizable reward — one of the highest offered in corporate bug bounty programs — it won’t beat the payouts researchers can earn from law enforcement or the black market. The FBI reportedly paid nearly $1 million for the exploit it used to break into an iPhone used by Syed Farook, one of the individuals involved in the San Bernardino shooting last Decembe…

Smart move. That's not too shabby of a tax deduction.

I don't understand how the deduction from giving X to a researcher and X to a charity is smarter than just giving X to the researcher?

Re: Apple announces bug bounty program

#42
post #24

Can't wait for "We pioneered InfoSec by our first-of-kind innovative bug bounty program" @ next WWDC.

Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.

Pretty sure it's been here the entire three years I have.

Re: Apple announces bug bounty program

#43
post #11
post #3

As mentioned the program is currently invite only currently (ie, https://twitter.com/i0n1c/status/761349794510036992 )

From the article: > However, Apple won’t turn away new researchers if they provide useful disclosures, and plans to slowly expand the program. I'm reading this as: if you find a serious bug and report it, you'll get the money.

I imagine if you find a good bug and aren't on their list, you could bring in someone who is to help out...

Re: Apple announces bug bounty program

#44
post #24

Can't wait for "We pioneered InfoSec by our first-of-kind innovative bug bounty program" @ next WWDC.

Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.

It's not just Reddit. Look at MacRumors, they are absolutely furious with Apple right now:

http://www.macrumors.com/2016/08/01/apple-new-ipad-pro-compu...

Re: Apple announces bug bounty program

#45
post #24

Can't wait for "We pioneered InfoSec by our first-of-kind innovative bug bounty program" @ next WWDC.

Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.

There's so many fanboys though :'(

Re: Apple announces bug bounty program

#46
post #24

Can't wait for "We pioneered InfoSec by our first-of-kind innovative bug bounty program" @ next WWDC.

Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.

Yeah but, they do take credit like that. And I'm one of their biggest fans.

Edit: oh, the downvotes, not because facts, but because dislike?

"He will go through a process of looking at my ideas and say, ‘That’s no good. That’s not very good. I like that one.’ And later I will be sitting in the audience and he will be talking about it as if it was his idea. I pay maniacal attention to where an idea comes from, and I even keep notebooks filled with my ideas. So it hurts when he takes credit for one of my designs."

Johnny Ive, on Steve Jobs. http://9to5mac.com/2011/10/24/isaacson-interviewed-jony-ive-...

Re: Apple announces bug bounty program

#48
post #38
post #36

Earlier quoted context omitted.

I read that as: if you find a bug and report it, you may get invited into the formal bug bounty program (but may not get a payout on the first one). No idea if that's right though.

The Reuters report has some details about why they limited it: >Apple said it decided to limit the scope of the program at the advice of other companies that have previously launched bounty programs. Those companies said that if they were to do it again, they would start by inviting a small list of researchers to join, then gradually open it up over time, according to Apple. Security analyst Rich Mogull said that lim…

True, but it's not like Apple doesn't have the resources to manage an open submission program.

Re: Apple announces bug bounty program

#49
post #24

Can't wait for "We pioneered InfoSec by our first-of-kind innovative bug bounty program" @ next WWDC.

Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.

they deserve all the bashing they are getting
Post reply on HN