Live data from Hacker News

Researcher Won't Disclose MacOS Keychain 0 Day Without Apple Bug Bounty Program

threatpost.com

1–10 of 21 posts

Re: Researcher Won't Disclose MacOS Keychain 0 Day Without Apple Bug Bounty Program

#5

He’s not holding the vulnerability hostage. The bug bounty is not worth his time to consult and report the vulnerability to Apple.

He doesn’t have to do it, but not worth his time? Sending his code to product-security@apple.com in whatever state it is shouldn’t take him more than 10 minutes.

And yes, he may have spent millions in hours to find this issue, but that’s a sunk cost now.

Re: Researcher Won't Disclose MacOS Keychain 0 Day Without Apple Bug Bounty Program

#6
post #5

He’s not holding the vulnerability hostage. The bug bounty is not worth his time to consult and report the vulnerability to Apple.

He doesn’t have to do it, but not worth his time? Sending his code to product-security@apple.com in whatever state it is shouldn’t take him more than 10 minutes. And yes, he may have spent millions in hours to find this issue, but that’s a sunk cost now.

It's definitely not worth his time if Apple isn't going to pony up a bounty, especially if he could recoup his sunk costs easily by selling the exploit to a security research / defense contractor.

Re: Researcher Won't Disclose MacOS Keychain 0 Day Without Apple Bug Bounty Program

#7

When there's no bounty program, or the bounty program is unreliably administrated, people have a right to sell their research to the highest bidder, whomever that may be.

You do not really think that? At least ethically speaking that sure can't be. Then I also suspect you would be frown upon for selling exploits to North Korea or Iran buyers for instance.

Re: Researcher Won't Disclose MacOS Keychain 0 Day Without Apple Bug Bounty Program

#8

When there's no bounty program, or the bounty program is unreliably administrated, people have a right to sell their research to the highest bidder, whomever that may be.

People deserve to be compensated for their work, however, to suggest selling it to the highest bidder is completely unethical. If you undertake work without a prior agreement to be paid for it, you can't go and hold the security of the userbase hostage in demanding payment.

Re: Researcher Won't Disclose MacOS Keychain 0 Day Without Apple Bug Bounty Program

#10

When there's no bounty program, or the bounty program is unreliably administrated, people have a right to sell their research to the highest bidder, whomever that may be.

They decided to spend time on finding a bug knowingly that there is no bug bounty program for OSX, this is essentially blackmail.

The other possibility is that this bug is so trivial e.g. the press enter a lot bug that you can hardly argue that a reward is warranted for their effort.

Post reply on HN