3 ms·
Project Zero is amazing, but they 1) seem like a very small team, and 2) their mandate is far too broad (essentially to search for 0-days in anything, versus a
by toasterblender 3y ago
Project Zero is amazing, but they 1) seem like a very small team, and 2) their mandate is far too broad (essentially to search for 0-days in anything, versus a specific system). What I am talking about is more like Apple having a dedicated team of 10 vulnerability researchers all looking into iOS 0-days fulltime.
- throwaway38475 3y agoThey all do that. I've been in Offensive Security for 10+ years with several spent at FAANGS, and not only do they all have large security teams doing internal testing, they hire multiple contractors like Trail-of-Bits to audit every important service continuously throughout the year. Apple has way more than 10 full time researchers looking at iOS all day, trust me :). They also have a really generous bug bounty. There is always bugs though.
- kramerger 3y ago> Apple has way more than 10 full time researchers looking at iOS all day. Yes > They also have a really generous bug bounty. Hell no
- lima 3y agoNot only is it not generous (relatively speaking), but actually getting paid can be extremely annoying. Used to be even worse.
- tholdem 3y agoAgree. Not long ago, Apple used to sue people reporting vulnerabilities to them. Imagine punishing people doing free work for you. Not a good look.
- 77pt77 3y agoGetting punished is the default. If you refer come across anything, keep your mouth shut.