TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Apple announces bug bounty program

344 点作者 nos4A2将近 9 年前

14 条评论

joebergeron将近 9 年前
This is definitely a step in the right direction. They say they&#x27;re worried that their bounties won&#x27;t be enough to dissuade anyone only interested in money from disclosing vulnerabilities to malicious sources. Honestly I think that a lot of people who discover these vulnerabilities would rather be paid slightly less money by disclosing to Apple and have the rep&#x2F;CV fodder of &quot;I broke Apple&quot; that comes with a responsible public disclosure, than going through secret channels to make slightly more money at the risk of potential legal trouble.<p>And anyways, 200 grand is an astoundingly high ceiling for bug bounties; highest I&#x27;ve ever seen paid out was a &quot;meager&quot; 20k by Uber, and I thought that was a lot of money for a bug program at the time.
jtl999将近 9 年前
As mentioned the program is currently invite only currently<p>(ie, <a href="https:&#x2F;&#x2F;twitter.com&#x2F;i0n1c&#x2F;status&#x2F;761349794510036992" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;i0n1c&#x2F;status&#x2F;761349794510036992</a>)
评论 #12229391 未加载
hurricaneSlider将近 9 年前
I&#x27;m a bit surprised, because you&#x27;d think that they&#x27;d have been doing this already.
评论 #12229680 未加载
评论 #12229323 未加载
评论 #12229523 未加载
sjtgraham将近 9 年前
I&#x27;m not familiar with the market but these seem low when you consider:<p>- The effort required to find them<p>- The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales, e.g. The SEP implications for ApplePay<p>- The damage that can be inflicted on users and 3rd parties, e.g. imagine the amount of cash banks would be on the hook for if someone managed to say write a worm that used iMessage&#x2F;SMS to propagate without user knowledge (e.g. with the recent TIFF vulnerability), and transfer funds from the user&#x27;s bank account? Or made calls to the baseband to dial shady $10&#x2F;minute premium rate numbers in some banana republic at 3AM every night?<p>- The amount of money TLAs and black market actors allegedly pay per the TC article.<p>- How much money Apple actually has, especially all the offshore cash that can&#x27;t be repatriated to the US without incurring exorbitant capital gains. These bug bounties could be be remitted from any Apple subsidiary.<p>- Large bug bounties would de facto end jailbreaking<p>- Knowing Apple there would be endless NDAs and restrictive covenants before any payout is made.<p>IMO with all this considered the max payouts seem irrationally paltry.
评论 #12229762 未加载
评论 #12229472 未加载
评论 #12229521 未加载
honkhonkpants将近 9 年前
I wonder if they are backfilling rewards to any of the external researchers who have been doing all of Apple&#x27;s security research for the last decade. Just as an example, a single researcher from Google is credited with 11 separate vulnerabilities that would qualify for the $50k reward, in a single patchlevel of OS X (and the same person had five such credits in the patchlevel prior to that!). That&#x27;s almost a million bucks worth of rewards in only half a year of disclosures.
评论 #12229704 未加载
评论 #12230688 未加载
godzillabrennus将近 9 年前
Next they need to offer a bounty program for usability issues. iOS needs a lot of love since Forstall got squeezed out.
评论 #12230033 未加载
nxzero将近 9 年前
Wonder if they&#x27;ll include their servers too; appears they&#x27;re only doing the most recently released OS and hardware.
评论 #12229438 未加载
alfanick将近 9 年前
I&#x27;ve once found security bug on OS X&#x2F;Mac (low chance of occuring, however gives complete access), reported complete steps to reproduce and solutions - received moreless copy-pasted response - two years, two OS X versions later - the bug is still there, even though it looks like 5 minutes fix...
评论 #12233869 未加载
skizm将近 9 年前
The question is will they pay $1,000,000 for an exploit that unlocks an iphone?<p><a href="http:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-apple-encryption-idUSKCN0XQ032" rel="nofollow">http:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-apple-encryption-idUSKCN0X...</a>
评论 #12229419 未加载
评论 #12229922 未加载
评论 #12229395 未加载
pepijndevos将近 9 年前
Am I reading it correctly that this is only iOS, and not other Apple software?
0xmohit将近 9 年前
Charlie Miller must be happy.<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;0xcharlie" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;0xcharlie</a>
jordache将近 9 年前
how about you fix bugs that are already well known, like how the sd reader dies after a while in el cap?
评论 #12229917 未加载
jrcii将近 9 年前
Finally, I&#x27;m going to be rich!
hoodoof将近 9 年前
I wish Apple would just fix the myriad ordinary bugs, let alone focus on security.