Live data from Hacker News

Apple announces bug bounty program

techcrunch.com

51–60 of 107 posts

Re: Apple announces bug bounty program

#51
post #10

The question is will they pay $1,000,000 for an exploit that unlocks an iphone? http://www.reuters.com/article/us-apple-encryption-idUSKCN0X...

Odd. That's right around the same price zerodium is willing to pay.

https://www.zerodium.com/ios9.html

Ever notice, you never see Superman and Clark Kent in the same room? ;)

Re: Apple announces bug bounty program

#52
post #18

Earlier quoted context omitted.

Smart move. That's not too shabby of a tax deduction.

I don't understand how the deduction from giving X to a researcher and X to a charity is smarter than just giving X to the researcher?

Tax deduction for the researcher, not Apple (note the original GP was about "altruistic / independently wealthy researchers").

Re: Apple announces bug bounty program

#53
post #26

Earlier quoted context omitted.

I think it's more like Apple is patient and waits to get things right. Bug bounty programs are relatively new (past few years). The article notes that Apple faced a more complicated landscape than your typical company, one where state actors are bidders. So they needed to craft a more targeted program.

This seems like a pretty generic reason that doesn't explain that much. Are state actors not bidders on gmail, android, facebook, firefox, chrome?

What's the going rate for an Android vuln? The FBI paid ~$1M for an iOS one. Android has a lot more malware, unpatched old installs, etc., and there are myriad ways to attack email and web accounts, so my guess is the marketplace for iOS is on a whole different level.

Re: Apple announces bug bounty program

#54
post #38

Earlier quoted context omitted.

The Reuters report has some details about why they limited it: >Apple said it decided to limit the scope of the program at the advice of other companies that have previously launched bounty programs. Those companies said that if they were to do it again, they would start by inviting a small list of researchers to join, then gradually open it up over time, according to Apple. Security analyst Rich Mogull said that lim…

True, but it's not like Apple doesn't have the resources to manage an open submission program.

They may have financial resources but I doubt their security engineers would want to deal with the deluge.

Re: Apple announces bug bounty program

#55

Earlier quoted context omitted.

Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.

There's so many fanboys though :'(

Are there? Are there really? Because my experience on the internet is a few happy Apple customers and a monstrous tidal wave of anti-Apple hate.

And it's a different kind of hate too. Apple fans like to criticize Microsoft and Google, but Apple haters generally attack Apple fans, not Apple itself. It's very disheartening.

Re: Apple announces bug bounty program

#56

Earlier quoted context omitted.

Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.

they deserve all the bashing they are getting

How is this relevant to discussion. This shit ruins the site. At least provide any content to your comment.

Re: Apple announces bug bounty program

#57
post #38

Earlier quoted context omitted.

The Reuters report has some details about why they limited it: >Apple said it decided to limit the scope of the program at the advice of other companies that have previously launched bounty programs. Those companies said that if they were to do it again, they would start by inviting a small list of researchers to join, then gradually open it up over time, according to Apple. Security analyst Rich Mogull said that lim…

True, but it's not like Apple doesn't have the resources to manage an open submission program.

Maybe they want to invest cautiously. Seems smart to me.

Re: Apple announces bug bounty program

#58
post #56

Earlier quoted context omitted.

they deserve all the bashing they are getting

How is this relevant to discussion. This shit ruins the site. At least provide any content to your comment.

No, people with no sense of humor ruins everything. It is a good joke, that's why it is top comment.

Re: Apple announces bug bounty program

#60
post #24

Can't wait for "We pioneered InfoSec by our first-of-kind innovative bug bounty program" @ next WWDC.

Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.

I've seen much apple and microsoft bashing here. Google, not as much.

I don't know why. Personally, I've got devices running the spectrum of OSs and they all have their strengths and weaknesses.

Post reply on HN