4 ms·
Does anybody have any info on how much Apple would've been likely to pay for a responsible disclosure in this case, given the scope and severity of the issue?
by alexwebb2 9y ago
Does anybody have any info on how much Apple would've been likely to pay for a responsible disclosure in this case, given the scope and severity of the issue?
I'm just curious how much of a payday this guy missed out on by not disclosing responsibly.
- pault 9y agoThat was my first thought. Based on some bounty reports I've seen recently I would assume at least high five figures.
- alexwebb2 9y agoOuch. This guy's going to kick himself pretty hard. The 15 minutes of infamy seems like a pretty bad tradeoff.
- sounds 9y agoDo you honestly believe Apple will pay out the same to someone located in Turkey?
- alexwebb2 9y agoI wouldn't think they'd care about the geography of it - a good tip is a good tip, and they want to encourage responsible disclosure.
- thanatropism 9y agoDo they release statistics on bug bounty payouts?
- FireBeyond 9y agoThey barely acknowledge bugs being submitted to Radar...
- lawnchair_larry 9y agoFor a local root with physical access? Not a chance. Maybe low 4 figures.
- rcruzeiro 9y agoIf the mac has screen sharing enabled, physical access is not required
- ken 9y agoAFAICT, Apple's security bounty program is officially only for their preselected group of security researchers. In the course of developing my current application, I've discovered a couple security bugs in macOS, which I reported to Apple product security in PGP-encrypted emails. The only thing offered to me was to have my name/company listed in the release notes (which they are, for the latest 10.13 update, along with a CVE#).