3 ms·
That program, at least when it was introduced, required participants not to report security vulnerabilities publicly until Apple allowed them to do so, with no
by robryk 5y ago
That program, at least when it was introduced, required participants not to report security vulnerabilities publicly until Apple allowed them to do so, with no limits on how long that can be (see https://news.ycombinator.com/item?id=23920454 https://news.ycombinator.com/item?id=23920454 for a discussion from that time).
That makes this program particularly useless for the purpose of auditing whether Apple is adhering to its promises.
- dwaite 5y agoFor security issues where the participants basically make their living indirectly by getting credit for security vulnerabilities, this carrot-and-stick potentially motivates them to stay quiet. Meanwhile, researchers have gotten wise to notary techniques (like publishing document hashes to twitter) which would let them severely and publicly shame Apple should they sit on something that ultimately turns out to be a zero day, with much delight from/participation by the media. For privacy/societal issues where Apple is a deliberate bad actor, they would presumably either directly be willing to break the terms of the agreement to go public, or would release information indirectly and rely on herd privacy with other researchers.