Live data from Hacker News

Apple announces bug bounty program

techcrunch.com

81–90 of 107 posts

Re: Apple announces bug bounty program

#81
post #52

Earlier quoted context omitted.

Tax deduction for the researcher, not Apple (note the original GP was about "altruistic / independently wealthy researchers").

Hows donation of X for tax savings is better than 0.6X income?

It is meant to encourage donations to non-profits which is something pretty good that corporates could do.

So it effectively reduces to what you'd prefer: 0.6X for yourself, or 2X for a non-profit that you want to support.

Re: Apple announces bug bounty program

#82

Earlier quoted context omitted.

Getting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.

It's not just Reddit. Look at MacRumors, they are absolutely furious with Apple right now: http://www.macrumors.com/2016/08/01/apple-new-ipad-pro-compu...

Well in fairness that is a pretty stupid marketing plan. Seems like they are trying too hard to come up with pseudo-deep punchlines.

Re: Apple announces bug bounty program

#83
post #28

Earlier quoted context omitted.

Apple has slowly been opening up, they used to be such an incredibly secretive company under Jobs there's no way this would've ever happened. Whoops. I just said "Steve Jobs never would've let this happen" line. Oh well. They're letting in third-party keyboards another extensions, small additions to Siri, releasing actual software on android, it's not too surprising that they might be willing to do this now. Been ver…

There was a time if you had issues with hardware, and email to Steve Jobs actually resulted in a customer escalation. I had one of the 15" MBPs that had the Nvidia chip issue, but never experienced that. But had 3 other problems -- all handled (first time for me with Mac hardware). A polite email on a friday night after I did hit my 4th hardware issue, next trip to the apple store was for a "in kind" based on purchas…

[deleted]

Re: Apple announces bug bounty program

#84
post #28

Earlier quoted context omitted.

Apple has slowly been opening up, they used to be such an incredibly secretive company under Jobs there's no way this would've ever happened. Whoops. I just said "Steve Jobs never would've let this happen" line. Oh well. They're letting in third-party keyboards another extensions, small additions to Siri, releasing actual software on android, it's not too surprising that they might be willing to do this now. Been ver…

There was a time if you had issues with hardware, and email to Steve Jobs actually resulted in a customer escalation. I had one of the 15" MBPs that had the Nvidia chip issue, but never experienced that. But had 3 other problems -- all handled (first time for me with Mac hardware). A polite email on a friday night after I did hit my 4th hardware issue, next trip to the apple store was for a "in kind" based on purchas…

They still do. I email Tim Cook on issues and got a few replies. Sometimes I dont get a reply but a solution made to the problem months down the road.

I believe Apple has already been listening, not as bone head as many imagine. Its just they prioritize what is important and needs fixing first.

Re: Apple announces bug bounty program

#85
post #33

I'm not familiar with the market but these seem low when you consider: - The effort required to find them - The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales, e.g. The SEP implications for ApplePay - The damage that can be inflicted on users and 3rd parties, e.g. imagine the amount of cash banks would be on the hook for if someone managed to say write a worm that us…

As tptacek loves to point out, the point of bug bounty programs is not to compete on price with the black market. And in fact, according to the article, the $200k Apple is offering is one of the highest for corporate bug bounty programs already.

That $200k boot ROM bounty might be the single instance I know of where a stated bounty value might be lower than the actual market for the vulnerability. If you were slick, you might make more from that bug than Apple would pay with the bounty. That is a bug class with a current, existing, liquid market.

The rest of them seem more than reasonable.

None of them are adequate compensation for the full-time work of someone who can find those kinds of bugs. Nor are they meant to be. If you can, for instance, find a bug that allows you to violate the integrity of the SEP, you have a market value as a consultant significantly higher than that $100k bug bounty --- which will become apparent pretty quickly after Apple publicly thanks you for submitting the bug, as they've promised to do.

Re: Apple announces bug bounty program

#86

I wonder if they are backfilling rewards to any of the external researchers who have been doing all of Apple's security research for the last decade. Just as an example, a single researcher from Google is credited with 11 separate vulnerabilities that would qualify for the $50k reward, in a single patchlevel of OS X (and the same person had five such credits in the patchlevel prior to that!). That's almost a million…

Among the many reasons this is very unlikely to happen, the bounty values we see now account for the increased difficulty of finding these kinds of vulnerabilities in iOS since its earliest releases. This is an OS that was designed as a platform for secure applications --- that's part of the premise of apps on the Apple phone --- and it's gotten much harder to find and exploit vulnerabilities on the platform since that release.

Re: Apple announces bug bounty program

#87
post #66

Earlier quoted context omitted.

I haven't read the article, but I was at the announcement and your take is exactly how it was clarified in the room. If you do good work and report it, you'll get paid accordingly.

That setup doesn't make any sense to me. Either its an open program or a closed program. A closed program that allows submissions from others is an open program. What reasons what they have to do it this way? My first guess is to tick some checkbox.

>That setup doesn't make any sense to me. Either its an open program or a closed program.

Or it's something in between. Few things in life are or have to be binary -- that's a very CS mindset.

Apple wants to start it as closed, so they have full discretion as to what "others" they will accept (since they've already said they're not just accepting anybody).

This helps them build up their teams and infrastructure for it with the fewer, pre-selected, people, and gives them time to expand (or even evaluate if they need expanding to fully open anyway, perhaps a smaller/controlled list works well enough too).

At the same time, the "we might accept non-invited third parties" gives them the opportunity not to miss out on any important unexpected collaborators / bugs.

Re: Apple announces bug bounty program

#88
post #38

Earlier quoted context omitted.

The Reuters report has some details about why they limited it: >Apple said it decided to limit the scope of the program at the advice of other companies that have previously launched bounty programs. Those companies said that if they were to do it again, they would start by inviting a small list of researchers to join, then gradually open it up over time, according to Apple. Security analyst Rich Mogull said that lim…

True, but it's not like Apple doesn't have the resources to manage an open submission program.

It's not about throwing money or people at a problem, it's the overhead that lowers its efficiency and agility.

Re: Apple announces bug bounty program

#89

Earlier quoted context omitted.

It's not just Reddit. Look at MacRumors, they are absolutely furious with Apple right now: http://www.macrumors.com/2016/08/01/apple-new-ipad-pro-compu...

Well in fairness that is a pretty stupid marketing plan. Seems like they are trying too hard to come up with pseudo-deep punchlines.

You know that's not Apple but some advertising company, right?

Re: Apple announces bug bounty program

#90
post #89

Earlier quoted context omitted.

Well in fairness that is a pretty stupid marketing plan. Seems like they are trying too hard to come up with pseudo-deep punchlines.

You know that's not Apple but some advertising company, right?

Ad agencies usually present their plans to the client for approval before filming, and present the film to the client for approval before broadcasting.

It's not like this got broadcast without Apple's marketing team's sign off.

Post reply on HN