4 ms·
Researcher Won't Disclose MacOS Keychain 0 Day Without Apple Bug Bounty Program
- username3 8y agoHe’s not holding the vulnerability hostage. The bug bounty is not worth his time to consult and report the vulnerability to Apple.
- Someone 8y agoHe doesn’t have to do it, but not worth his time? Sending his code to product-security@apple.com in whatever state it is shouldn’t take him more than 10 minutes. And yes, he may have spent millions in hours to find this issue, but that’s a sunk cost now.
- sithadmin 8y agoIt's definitely not worth his time if Apple isn't going to pony up a bounty, especially if he could recoup his sunk costs easily by selling the exploit to a security research / defense contractor.
- bcheung 8y agoGranting a license to software that a company has invested millions of dollars in takes less than 10 minutes as well, but that doesn't mean they are obligated to give it to anyone who might find it useful for free. Sunk cost is an orthogonal issue. It's reasonable to expect compensation for your work. Caveat that they don't sell it to someone who will exploit it. Building or acquiring something of value in the hopes of profiting from it later is a fundamental part of life. It is why we go to school, invest in machinery, develop products, do research, etc.
- droithomme 8y agoWhen there's no bounty program, or the bounty program is unreliably administrated, people have a right to sell their research to the highest bidder, whomever that may be.
- sheepdestroyer 8y agoYou do not really think that? At least ethically speaking that sure can't be. Then I also suspect you would be frown upon for selling exploits to North Korea or Iran buyers for instance.
- droithomme 8y agoAt no point did anyone advocate engaging in illegal criminal acts such as you are here blatantly advocating. It's very offensive to take a discussion of fair pay for honest work and try to twist it into a scenario of engaging in overtly criminal acts when that was never the case. You should be ashamed for even attempting such an unethical propaganda maneuver. Everyone has a right to be paid for their work provided that work is valuable to others and is not criminal. For independent contractors and free agents they have an intrinsic and fundamental right to sell their work to the highest bidder in a legal manner. To suggest otherwise is completely unethical, depraved, and inhuman.
- RickS 8y ago> people have a right to sell their research to the highest bidder, whomever that may be. > whomever that may be. I think most readers, myself included, read that additional qualifier on "highest bidder" to mean "even if such a bidder is unexpected or unscrupulous". If you meant "unless selling to such a bidder were illegal", then you should have said that. Your words were not only very different from that, but they specifically cover the case you claim not to be endorsing. To say nothing of the fact that if you're informed enough to have a discussion on the sale of 0 days, it can be assumed you know the market is full of bad actors and state actors, so even if nobody mentioned it upfront, it's a topic that's on the table from the outset, IMO. It's not uncouth to bring up illegal behavior when it's a routine part of what's being discussed. I think it's a bit much that you attack that person's character for making what seems like a pretty sane reading of your post. Especially when it seems the person you're yelling at was right – the thing you said is not the thing you really think.
- tccc 8y agoPeople deserve to be compensated for their work, however, to suggest selling it to the highest bidder is completely unethical. If you undertake work without a prior agreement to be paid for it, you can't go and hold the security of the userbase hostage in demanding payment.
- mishurov 8y agoMakes a lot of sense. Only monkeys use Apple, they don't deserve a free lunch. People use FreeBSD and Linux.
- amanzi 8y agoWhy doesn't Apple have a bug bounty program for macOS?
- dvfjsdhgfv 8y agoBecause someone at Apple decided to concentrate on the iPhone only. Their behavior towards the general computing line has been quite consistent in the last years, and I doubt it will ever change.
- vuln 8y agoI wonder which nation state will bid the most?
- RunawayGalaxy 8y agoI think that there's a point where negligence becomes culpable. Given that, I'm considering 2 questions: 1) Suppose Apple sells potentially vulnerable software to users and knowingly refuses to curb market demand for potential exploits to the benefit of their bottom line. When a zero-day is discovered and sold to the highest bidder, what percentage of the blame does Apple deserve? 2) How does that percentage change with respect to the following? (a) potential number of users affected (b) cost of a bounty program as a percentage of total profit from sale of the vulnerable software