TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Apple security bounty upgraded

263 pointsby creckerover 2 years ago

11 comments

brian_hermanover 2 years ago
Wow the Security research device looks awesome! <a href="https:&#x2F;&#x2F;security.apple.com&#x2F;research-device" rel="nofollow">https:&#x2F;&#x2F;security.apple.com&#x2F;research-device</a>
评论 #33371640 未加载
评论 #33364685 未加载
评论 #33367072 未加载
评论 #33365111 未加载
capablewebover 2 years ago
&gt; Shell access is available, and you can run any tools, choose your own entitlements, and even customize the kernel.<p>Wow, I want one of this just for fun, sounds like what I want my normal iPhone to be able to do<p>&gt; Have a proven track record of success in finding security issues on Apple platforms, or other modern operating systems and platforms.<p>Well, that put a stop to my dream...
评论 #33368761 未加载
评论 #33365550 未加载
评论 #33366328 未加载
评论 #33365795 未加载
dangerfaceover 2 years ago
Do they actually pay out tho? I keep hearing security researchers having difficulty getting these bounties, seems like a great business strategy out source security audits, offer massive pay outs looks good, don&#x27;t pay out and keep the pot growing larger to look even better.
评论 #33369736 未加载
评论 #33369614 未加载
dagmxover 2 years ago
This is also part of a new Security Research page <a href="https:&#x2F;&#x2F;security.apple.com" rel="nofollow">https:&#x2F;&#x2F;security.apple.com</a>
oliwaryover 2 years ago
&gt; Device attack via physical access: $5,000: Limited extraction of sensitive data from the locked device after first unlock. As an example, you demonstrated the ability to extract some contact information from a user’s locked device after the first unlock.<p>Uhhh I must be missing something here… I can trivially share a contact via email after my iPhone is unlocked?
评论 #33366995 未加载
评论 #33366986 未加载
评论 #33366997 未加载
评论 #33376030 未加载
评论 #33367003 未加载
评论 #33367055 未加载
评论 #33366987 未加载
isusmeljover 2 years ago
I just hope you get the money transferred to your bank account and not in Apple product vouchers.
MauranKilomover 2 years ago
Off-topic: This thread has a cool id (33363333)!
runjakeover 2 years ago
It&#x27;s a lot of talk, but I doubt Apple&#x27;s honesty here.<p>See also Gui Rambo getting a measly $7,000 for a couple of fairly serious vulnerabilities.<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=33348013" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=33348013</a>
评论 #33365229 未加载
评论 #33365002 未加载
评论 #33366331 未加载
AJRFover 2 years ago
Apples copywriters make everything the brand says sound smug. e.g;<p>&quot;iPad. Loveable. Drawable. Magical&quot;<p>&quot;iPhone 14 Pro. Pro. Beyond&quot;<p>And now;<p>Apple Security Bounty. Upgraded.
评论 #33366780 未加载
评论 #33365448 未加载
评论 #33369269 未加载
londons_exploreover 2 years ago
&gt; we’ve grown our team and worked hard to be able to complete an initial evaluation of nearly every report we receive within two weeks, and most within six days.<p>At other big tech companies, an initial evaluation of a security report will be done in 15 minutes... And if it&#x27;s important, people will be woken up and a workaround will probably be deployed in a matter of hours...<p>For example, the Google security bug form[1] says &quot;This option might really get someone out of bed.&quot;<p>[1]: <a href="https:&#x2F;&#x2F;www.google.com&#x2F;appserve&#x2F;security-bugs&#x2F;m2&#x2F;new" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;appserve&#x2F;security-bugs&#x2F;m2&#x2F;new</a>
评论 #33365138 未加载
评论 #33365125 未加载
评论 #33366797 未加载
评论 #33365213 未加载
评论 #33366100 未加载
fazfqover 2 years ago
Anybody knows how much this costs (if anything)?