4 ms·
Researcher reveals huge Mac password flaw to protest Apple bug bounty
- forgottenpass 8y ago>Generally, white hat security researchers publicly reveal flaws like this only after informing the company and giving it ample time to fix the issues. But Henze is refusing to assist Apple because it doesn’t offer paid bug bounties This is starting to look really bad for the infosec "community." Without rehashing all the old arguments around disclosure, and the sorta-recent arguments around bug bounties, we're now at the point where this doesn't not look like extortion. "That's an awfully nice operating system you've got there. It'd be a shame if someone were to disclose a security flaw without giving you ample opportunity to fix it."
- 51lver 8y agoThis isn't the mob burning someones shop down. This is more like pointing out, hey dude, your door is open, you should close it. They don't owe apple anything, and they are not causing the damage (apple's negligence did). If apple doesn't want to handle this in private, they will have to handle this in public. I don't see the problem. Coordinated disclosure is a courtesy, not a rule.
- forgottenpass 8y agoYou don't have to convince me. You have to convince the technically disinclined that know nothing about disclosure, but know plenty about people acting in ways that "ensure their job security."
- Apocryphon 8y agoIf large cap corporations refuse to pay researchers for finding security problems, then clearly they do not take security seriously enough. How else to publicly shame them for their penny-pinching?
- jiveturkey 8y agoFalse dichotomy.
- Apocryphon 8y agoIt has precedence: https://www.helpnetsecurity.com/2018/11/07/virtualbox-guest-to-host-escape-0day/ https://www.helpnetsecurity.com/2018/11/07/virtualbox-guest-... > Zelenyuk has responsibly disclosed to Oracle (via the SecuriTeam Secure Disclosure program) another VirtualBox vulnerability over a year ago, but apparently Oracle took a very long time to fix it and ultimately failed to credit Zelenyuk for the discovery. --- https://news.ycombinator.com/item?id=16000550 https://news.ycombinator.com/item?id=16000550 archived: https://web.archive.org/web/20180202100849/https://medium.com/bread-and-circuses/how-i-got-paid-0-from-the-uber-security-bug-bounty-aa9646aa103f https://web.archive.org/web/20180202100849/https://medium.co... I Got Paid $0 from the Uber Security Bug Bounty --- https://techcrunch.com/2013/08/18/security-researcher-hacks-mark-zuckerbergs-wall-to-prove-his-exploit-works/ https://techcrunch.com/2013/08/18/security-researcher-hacks-... Security Researcher Hacks Mark Zuckerberg’s Wall To Prove His Exploit Works
- jiveturkey 8y agoabsolutely. but it isn't an either-or.