Live data from Hacker News

Apple announces bug bounty program

techcrunch.com

1–10 of 107 posts

Re: Apple announces bug bounty program

#4

I'm a bit surprised, because you'd think that they'd have been doing this already.

I had the.. pleasure.. of speaking to Comcast's CISO after doing a security risk exposure disclosure. Before talking to her, there were mentions of bug bounties, etc (neat). After talking to her, though, she said in a hand-wavy way that:

1. The exposure wasn't a "bug", so it's not worth a bug bounty.

2. The amount of effort it would take to start a bug bounty program would be far too cost prohibitive. In other words, "Everything's broken. We know it. If we start paying people to find what's broken, we'd go bankrupt." Heh.

So yeah. Don't be surprised.

Re: Apple announces bug bounty program

#6
post #4

I'm a bit surprised, because you'd think that they'd have been doing this already.

I had the.. pleasure.. of speaking to Comcast's CISO after doing a security risk exposure disclosure. Before talking to her, there were mentions of bug bounties, etc (neat). After talking to her, though, she said in a hand-wavy way that: 1. The exposure wasn't a "bug", so it's not worth a bug bounty. 2. The amount of effort it would take to start a bug bounty program would be far too cost prohibitive. In other words,…

I suspect for large companies most bug bounty programs are net economic positives, especially weighed against cost of probable breaches or the comparable spend required on in-house engineering to find all the bugs otherwise cheaply and quickly identified by the bounty. The problem is social/political for senior executives to accept that discussion of flaws in the open is a good thing.
Post reply on HN