3 ms·
"Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they f
by polack 5y ago
"Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they failed to credit his analyticsd bug report."
"Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories."
They didn't give him credit in the last 5 advisories. Really no excuse for that imho. If Apple keeps this up then why would anyone report bugs to them when you can just post it online and get credit for it right away? Or sell it on some 0-day site.
- efleurine 5y agoObviously credit is important for them as a proof of competence. If the company does not give them credits how can they build their business, portfolio. You can jus say I was the one who discovered this. Every field works in a certain way and when it comes to bounty you want to make a name for yourself. You can't just pull up and say you are the one But yeah may be they should just sell it to third-parties
- glenstein 5y agoExactly, that's the issue. This is a RT*A scenario.
- tptacek 5y agoIf credit is what you care about, it's straightforward to ensure you get credit without working with Apple's bounty program. You can do what P0 does and provide a fixed timeline after which you're publishing, and nobody credible is going to hold that against you (in part because P0 has established this norm).