2 ms·
As bad as this is for people who use iOS, I think it's good in the long run. People here are getting boggled down in details about how is it possible for this
by throwawayswede 5y ago
As bad as this is for people who use iOS, I think it's good in the long run.
People here are getting boggled down in details about how is it possible for this to happen and what sort of policies apple has internally for it to be possible, but that doesn't really matter. Any company even 10% the size of APple should not be given the benefit of the doubt because obviously they'd all prefer not to have the major/minor embarrassment, if they can. Bounty programs exist not because they care about security of their customers only, but it's also a way to promote the company as security-conscious and avoid having 0days sold on the black market.
But to overcome this you can just continue publishing 0-days straight to the public. Put really easy to use sourcecode on github/bucket/srht/etc... allowing script-kiddies and copy-pasters to make use of them easily. This will either drive people to lose trust or force Apple to scramble to release fixes, either way it will push them to respect researchers and fix their bounty program or setup better security guidelines in general.
Props to the author for following through and releasing.