I think it's more like Apple is patient and waits to get things right. Bug bounty programs are relatively new (past few years). The article notes that Apple faced a more complicated landscape than your typical company, one where state actors are bidders. So they needed to craft a more targeted program.
This seems like a pretty generic reason that doesn't explain that much. Are state actors not bidders on gmail, android, facebook, firefox, chrome?
What's the going rate for an Android vuln? The FBI paid ~$1M for an iOS one. Android has a lot more malware, unpatched old installs, etc., and there are myriad ways to attack email and web accounts, so my guess is the marketplace for iOS is on a whole different level.
The Reuters report has some details about why they limited it: >Apple said it decided to limit the scope of the program at the advice of other companies that have previously launched bounty programs. Those companies said that if they were to do it again, they would start by inviting a small list of researchers to join, then gradually open it up over time, according to Apple. Security analyst Rich Mogull said that lim…
True, but it's not like Apple doesn't have the resources to manage an open submission program.
They may have financial resources but I doubt their security engineers would want to deal with the deluge.
Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.
There's so many fanboys though :'(
Are there? Are there really? Because my experience on the internet is a few happy Apple customers and a monstrous tidal wave of anti-Apple hate.
And it's a different kind of hate too. Apple fans like to criticize Microsoft and Google, but Apple haters generally attack Apple fans, not Apple itself. It's very disheartening.
The Reuters report has some details about why they limited it: >Apple said it decided to limit the scope of the program at the advice of other companies that have previously launched bounty programs. Those companies said that if they were to do it again, they would start by inviting a small list of researchers to join, then gradually open it up over time, according to Apple. Security analyst Rich Mogull said that lim…
True, but it's not like Apple doesn't have the resources to manage an open submission program.
Maybe they want to invest cautiously. Seems smart to me.