3 ms·
Before this, some people complained that Apple’s bug bounty rewards were too low. Now they’re higher and a different set of people are complaining that they onl
by d35007 7y ago
Before this, some people complained that Apple’s bug bounty rewards were too low. Now they’re higher and a different set of people are complaining that they only did it for PR. It seems like a bit of a “damned if you do, damned if you don’t” scenario.
It’s true that Apple pins its rewards to specific outcomes, but I think a lot of bug bounty programs do something like this. For instance, Google’s top bounty for Android ($200k) is only awarded if you can provide an exploit compromises that the trusted execution environment (see https://www.google.com/about/appsecurity/android-rewards/ https://www.google.com/about/appsecurity/android-rewards/).
- Mirioron 7y agoDoes it really matter if it's for PR or not? It seems to me like Apple is hitting two birds with one stone.