4 ms·
Apple Security Bounty
- killjoywashere 7y agoFacebook: https://www.facebook.com/whitehat https://www.facebook.com/whitehat Amazon: https://aws.amazon.com/security/vulnerability-reporting/ https://aws.amazon.com/security/vulnerability-reporting/ Netflix: https://help.netflix.com/en/node/6657 https://help.netflix.com/en/node/6657 Google: https://www.google.com/about/appsecurity/programs-home/ https://www.google.com/about/appsecurity/programs-home/ Microsoft: https://www.microsoft.com/en-us/msrc/bounty https://www.microsoft.com/en-us/msrc/bounty More: https://www.ubuntupit.com/best-bug-bounty-programs-on-internet/ https://www.ubuntupit.com/best-bug-bounty-programs-on-intern...
- ghostpepper 7y agoFacebook - No dollar amounts listed but "If we pay a bounty it will be a minimum $500" Amazon and Netflix, no dollar amounts listed Microsoft offers up to $250k for "Critical remote code execution, information disclosure and denial of services vulnerabilities in Hyper-V" Ironically that google page dumped a bunch of html into my browser, including a "script nonce" and a function definition: (function(H){H.className=H.className.replace(/\bgoogle\b/,'google-js')})(document.documentElement) I'll be waiting for a cheque from them, I suppose.
- _bxg1 7y agoIs this new? Is that why it's being posted?
- brian_herman 7y agoYeah this is old? https://www.theverge.com/2016/8/4/12380036/apple-bug-bounty-program-vulnerability-security https://www.theverge.com/2016/8/4/12380036/apple-bug-bounty-... This is 4 years old? (2016 should be added to title.
- saagarjha 7y agoThe bug bounty is no longer invite-only, and the maximum payouts have been increased.
- ogre_codes 7y agoPrior to now this program was invite only. They are blowing it open to all security researchers as of today. https://apple.news/A4h_BM9HqTjSpsWKsrVPGBw https://apple.news/A4h_BM9HqTjSpsWKsrVPGBw Also, max payout has been bumped to $1.5m which is a pretty big change. Most of this was announced a few months ago, they are just making good on a previous announcement at this point.
- _bxg1 7y agoThanks for the context. As a user of Apple devices, I'm excited about the increased attention to security!
- dsalzman 7y agoReal $ amounts! This is how you beat the black market.
- deleted 7y ago[deleted]
- zemnmez 7y agoCritically, there's no information about whether reporters are allowed to disclose, which usually means that Apple is going to hide any seriously damaging vulnerabilities...
- saagarjha 7y agoThere's this: > Not disclose the issue publicly before Apple releases the security advisory for the report. (Generally, the advisory is released along with the associated update to resolve the issue). See terms and conditions. No guarantees, then.
- jc_811 7y agoI see the biggest bounty is for &1,000,000USD and says:” Zero-click kernel code l execution with persistence and kernel PAC bypass” As someone who doesn’t speak this language, what does thismean? And are there examples in history of this type of exploit affecting a large company?
- dsalzman 7y agoAn exploit that allows full control of the device that installs with no user interaction, zero-click, and is persistent even after rebooting or power cycling the device.
- jc_811 7y agoThis is a great explanation, thanks!
- nicwilson 7y ago> Zero-click No user interaction required. > kernel code l execution with persistence Persistent malware with root privilege. > kernel PAC bypass I think PAC is some protection measures.
- djcapelis 7y agoI think PAC is some protection measures. Pointer Authentication Code It’s a form of pointer integrity checking that you can read about in the Platform Security Guide (this used to be called the iOS Security Whitepaper) released today: https://support.apple.com/en-sg/guide/security/seca5759bf02/web https://support.apple.com/en-sg/guide/security/seca5759bf02/... Google’s Project Zero also wrote a post about this mechanism, including a detailed case study of where they were able to bypass it: https://googleprojectzero.blogspot.com/2019/02/examining-pointer-authentication-on.html?m=1 https://googleprojectzero.blogspot.com/2019/02/examining-poi...
- saagarjha 7y agoPAC generally protects against return-oriented and other control-flow hijacking attacks.
- pabs3 7y agoI heard a rumor that Apple has never paid out any money in their invite-only bug bounty days. This 2018 article seems to suggest that is true. Does anyone have any data to the contrary? https://www.vice.com/en_us/article/7xqdxe/google-project-zero-hacker-iphone-bug-bounty https://www.vice.com/en_us/article/7xqdxe/google-project-zer...