8 ms·
> Once all steps are complete, we will reimburse you the cost of creating this account. Seems they'll refund the paid account, still a weird thing to do.
by rmkrmk 5y ago
> Once all steps are complete, we will reimburse you the cost of creating this account.
Seems they'll refund the paid account, still a weird thing to do.
- deleted 5y ago[deleted]
- camkego 5y agoThey are saying, in effect, you must sign/agree to our 81-page developer agreement to receive the reward.
- sneak 5y agoLots of bug bounties are really just hush money, that you have to sign an NDA to get. Always just publish your research. You can optionally offer it privately to the affected party in advance, but don't agree to any TOSes to do free work. Full disclosure is responsible, too.
- Leparamour 5y agoI assume lots of bug hunters (especially those from third world countries or those currently unemployed) depend on the bounty money to support their livelihoods.
- rapind 5y agoThis is why I think a third party bug bounty middleman service is inevitable. They will be better equipped to exact appropriate remuneration and develop relationships. Companies should be trying really hard to avoid this happening by offering better rewards with less hoops to jump through.
- belter 5y agoAgree. It is a business opportunity. It will have to be a US based company as only those will have enough funding to both fight the legal fights and lobby for legal protection. For the first few years the company will be considered a level just above common criminals. After a few while, they will be considered an essential consumer protection service.
- sombremesa 5y agoThat’s a bit like hitting the slots to support your family. Not only do you have slim chances to find anything that pays out a worthwhile sum, even if you do find such a bug they might come back with a “sorry, already reported”. If they get back to you, that is. It’s not something to rely on at all.
- underdeserver 5y agoYep, you should really give up significant income from companies that do responsible vulnerability disclosure in the name of a random HN's commenter's values.
- sneak 5y agoAt no point did I say you should give up income.
- underdeserver 5y ago"Always just publish your research." In most bug bounty programs I've seen (including Apple's and Facebook's) payouts are contingent on not publishing the research without consent.
- throwaway4400 5y agoAny corporate is going to make you sign something to receive the cash. The terms would not normally be as strong as an NDA though, otherwise we wouldn't see any bounty reports.
- josteink 5y ago> Once all steps are complete, we will reimburse you the cost of creating this account. That literally sounds like a Nigerian email scam.
- dolmen 5y agoIt is. But the subscription money is not the worst. You also have to agree to the terms of the developer account to open the account. Which means it will change the terms of your relationship with Apple before even getting any penny.
- drclau 5y agoMaybe it’s their way of validating the identity of the person making the claim.
- pdpi 5y agoThey have a mechanism to pay external developers, and they want to use that instead of creating a vulnerability-specific mechanism.