Live data from Hacker News

A major evolution of Apple Security Bounty

security.apple.com

1–10 of 13 posts

Re: A major evolution of Apple Security Bounty

#5
A "major evolution" would be for Apple to have informative two-way conversations with security researchers and to stop stiffing them for reports.

I submitted a few macOS reports to the program, but Apple just sat on them forever, sometimes years, until I got frustrated enough to just publicly disclose the bugs. Needless to say, Apple never paid me a dime. For that reason, I don't actively look for macOS bugs anymore, and if I happen to find anything by accident, I'll just 0day.

I think that demanding full exploit chains is an excuse to ignore bugs and to discourage researchers from reporting them. What if a full exploit chain exists, but the links of the chain are known by different researchers? The researchers are incentivized to withhold bug reports without the full chain, and meanwhile an attacker who happens to have the full chain won't withhold their attack. Apple is practically making the black market for bugs more valuable.

It's basically the same as Apple demanding a sysdiagnose before they'll even look at a non-security bug report. Typo in the developer documentation? Please attach a sysdiagnose! It's ridiculous.

Re: A major evolution of Apple Security Bounty

#6
post #4

Paying $1,000 for low-impact issues is a nice move which might make me contribute to their program again.

Don't bother. They'll find an excuse to pay $0. This is all at Apple's inscrutable discretion.

aren't all bug bounty program at the sponsor's inscrutable discretion?

Re: A major evolution of Apple Security Bounty

#7
post #6
post #4

Earlier quoted context omitted.

Don't bother. They'll find an excuse to pay $0. This is all at Apple's inscrutable discretion.

aren't all bug bounty program at the sponsor's inscrutable discretion?

Yes, but Apple tends to be more inscrutable than anyone else.

Re: A major evolution of Apple Security Bounty

#8
post #4

Paying $1,000 for low-impact issues is a nice move which might make me contribute to their program again.

Don't bother. They'll find an excuse to pay $0. This is all at Apple's inscrutable discretion.

At least it seems that they won't assign CVE IDs and credit researchers without compensating them at all (which is what happened when I reported CVE-2024-27811, for example):

> We want those researchers to have an encouraging experience — so in addition to CVE assignment and researcher credit as before, we will now also reward such reports with a $1,000 award.

Re: A major evolution of Apple Security Bounty

#10
post #5

A "major evolution" would be for Apple to have informative two-way conversations with security researchers and to stop stiffing them for reports. I submitted a few macOS reports to the program, but Apple just sat on them forever, sometimes years, until I got frustrated enough to just publicly disclose the bugs. Needless to say, Apple never paid me a dime. For that reason, I don't actively look for macOS bugs anymore,…

Yeah: this is all just noise, lies heaped upon lies. At times I've at least felt as if a few of the people involved internally "mean well", despite the company as a whole being evil... but, then I had to realize: their entirely-useless "sort of meaning well" was just causing me to slightly stall on going scorched earth on the entire program, so they were actually just yet another part of the problem. Apple--as a whole, including the people who work there, including the people who feel like they are different--just simply doesn't care about end-user security: they only care about maintaining control.
Post reply on HN