Live data from Hacker News

Apple announces bug bounty program

techcrunch.com

91–100 of 107 posts

Re: Apple announces bug bounty program

#91
post #89

Earlier quoted context omitted.

You know that's not Apple but some advertising company, right?

Ad agencies usually present their plans to the client for approval before filming, and present the film to the client for approval before broadcasting. It's not like this got broadcast without Apple's marketing team's sign off.

Sure, but this is not the same as a core product Apple makes...

Re: Apple announces bug bounty program

#92
post #76

Earlier quoted context omitted.

I imagine if you find a good bug and aren't on their list, you could bring in someone who is to help out...

... Or Apple could just be like every other bug bounty and pay out regardless of if you're on a white list or not.

Someone's always willing to pay.

It just might be in bitcoin on some .onion site :)

Re: Apple announces bug bounty program

#93
post #83

Earlier quoted context omitted.

There was a time if you had issues with hardware, and email to Steve Jobs actually resulted in a customer escalation. I had one of the 15" MBPs that had the Nvidia chip issue, but never experienced that. But had 3 other problems -- all handled (first time for me with Mac hardware). A polite email on a friday night after I did hit my 4th hardware issue, next trip to the apple store was for a "in kind" based on purchas…

[deleted]

Just trying to understand: do people begin off by writing to Tim Cook or do they use the usual channels and then end up writing to Tim?

Re: Apple announces bug bounty program

#94

Earlier quoted context omitted.

There's so many fanboys though :'(

Are there? Are there really? Because my experience on the internet is a few happy Apple customers and a monstrous tidal wave of anti-Apple hate. And it's a different kind of hate too. Apple fans like to criticize Microsoft and Google, but Apple haters generally attack Apple fans , not Apple itself. It's very disheartening.

Well, to me it's more like the VI/Emacs rivalry. It's fun to poke at each other so long as things remains civil.

But note--people make fun of Apple fans because they are crazy--have you seen the lines when the iPhone 6 came out? I mean seriously. :)

Re: Apple announces bug bounty program

#96
This is definitely a step in the right direction. They say they're worried that their bounties won't be enough to dissuade anyone only interested in money from disclosing vulnerabilities to malicious sources. Honestly I think that a lot of people who discover these vulnerabilities would rather be paid slightly less money by disclosing to Apple and have the rep/CV fodder of "I broke Apple" that comes with a responsible public disclosure, than going through secret channels to make slightly more money at the risk of potential legal trouble.

And anyways, 200 grand is an astoundingly high ceiling for bug bounties; highest I've ever seen paid out was a "meager" 20k by Uber, and I thought that was a lot of money for a bug program at the time.

Re: Apple announces bug bounty program

#97
post #69
post #28

Earlier quoted context omitted.

Apple has slowly been opening up, they used to be such an incredibly secretive company under Jobs there's no way this would've ever happened. Whoops. I just said "Steve Jobs never would've let this happen" line. Oh well. They're letting in third-party keyboards another extensions, small additions to Siri, releasing actual software on android, it's not too surprising that they might be willing to do this now. Been ver…

Just for the sake of discussion: Are they opening up because they need to do this to survive? And they need to do this to survive because their products aren't as good as they used to be and they can't live in an enclosed environment?

My guess is management just sees it as a sensible way forward. Lot of value from engaging more with outside world. (See also: Swift.) Previous management was a bit more secretive, the culture is changing under the new boss.

I don't think it's a "we have to do this to survive" situation, just a "this seems a good idea" situation.

Re: Apple announces bug bounty program

#98
post #14
post #10

The question is will they pay $1,000,000 for an exploit that unlocks an iphone? http://www.reuters.com/article/us-apple-encryption-idUSKCN0X...

The article already addresses this: While $200,000 is certainly a sizable reward — one of the highest offered in corporate bug bounty programs — it won’t beat the payouts researchers can earn from law enforcement or the black market. The FBI reportedly paid nearly $1 million for the exploit it used to break into an iPhone used by Syed Farook, one of the individuals involved in the San Bernardino shooting last Decembe…

Yea, I was just kidding. Also, selling the exploit to Apple is more of a guarantee than waiting around to see if the government needs it (assuming you want to stay legal).

Re: Apple announces bug bounty program

#100
post #80

Earlier quoted context omitted.

Seems pretty simple to me: There was a joke. It was at least tangentially related to the article at hand. Then someone got offended and made the very first irrelevant comment here. He could have just let it slide, but no. More irrelevant comments were made in response to the first irrelevant comment. Yours included. I really don't think people care to read about your opinion on what ruins the site here. Does it reall…

Downvotes don't change anything. Only pointing out problems improves discussion. I am sorry this offends you.

Thanks, you really added to the discussion there.
Post reply on HN