Apple says kernel vulnerability is not eligible for bounty
1–10 of 40 posts
Re: Apple says kernel vulnerability is not eligible for bounty
#2Re: Apple says kernel vulnerability is not eligible for bounty
#3Re: Apple says kernel vulnerability is not eligible for bounty
#4You can still get some reward for it on the dark web, surely.
Re: Apple says kernel vulnerability is not eligible for bounty
#5Is this normal? I’m only ancillary to security stuff like this but without details of the exploit it’s hard to say whether or not this is scandalous or not. It’s possible Apple made a mistake here, but is that a more likely scenario than the vuln just not being exploitable enough to warrant a bounty?
Being hard-nosed about refusing to pay a bounty on a privilege escalation bug is a rookie mistake. It engenders ill will and cements your relationship with security researchers as adversarial rather than cooperative.
Re: Apple says kernel vulnerability is not eligible for bounty
#6Re: Apple says kernel vulnerability is not eligible for bounty
#7When people realise this is what they can expect from Apple they will just sell these exploits to intelligence agencies instead for who knows what purpose.
So congratulations Apple of fucking over not just this person but your entire customer base for years to come. Morons.
Re: Apple says kernel vulnerability is not eligible for bounty
#8Is this normal? I’m only ancillary to security stuff like this but without details of the exploit it’s hard to say whether or not this is scandalous or not. It’s possible Apple made a mistake here, but is that a more likely scenario than the vuln just not being exploitable enough to warrant a bounty?
Re: Apple says kernel vulnerability is not eligible for bounty
#9Is this normal? I’m only ancillary to security stuff like this but without details of the exploit it’s hard to say whether or not this is scandalous or not. It’s possible Apple made a mistake here, but is that a more likely scenario than the vuln just not being exploitable enough to warrant a bounty?
Re: Apple says kernel vulnerability is not eligible for bounty
#10You can still get some reward for it on the dark web, surely.