back to article Apple joins the bug bounty party with $200,000 top prize

Security researchers can win up to US$200,000 in Apple's new bug bounty program, announced by the company on Thursday at the Black Hat security convention in Las Vegas. “We’ve had great help from researchers like you and the security mechanisms we build have gotten stronger,” said Apple’s head of security engineering and …

  1. Sandtitz Silver badge
    Meh

    IOS only, invite only...

    Why don't they extend this to OS X macOS too? Are they not confident about it?

    But 200k is nothing to sneeze at.

    1. Ryan Kendall
      Trollface

      Re: IOS only, invite only...

      $200K that's the price of 4 macbooks.

      1. Anonymous Coward
        Anonymous Coward

        Re: IOS only, invite only...

        I'll bet if you found one of those $200K exploits and asked nicely, they'd allow you to take SIX Macbooks in exchange for the cash!

  2. Naselus

    Doesn't seem like much of a bug bounty program tbh

    By making it invite only, they've more or less dropped all the advantages to having a bounty program. The entire point is to harness the Open Source-style many-eyes advantage.

    1. Anonymous Coward
      Anonymous Coward

      Re: Doesn't seem like much of a bug bounty program tbh

      They said it won't be an exclusive club and they'll let in others later. They probably want to sort of "beta test" the process with a small number of researchers they've worked with in the past before opening the floodgates.

      1. Naselus

        Re: Doesn't seem like much of a bug bounty program tbh

        Sure, I get the idea. Doesn't change the fact that, until they actually do open those floodgates, this utterly misses the whole point of a bug bounty program. It's presently just an unpaid QA team.

  3. Mark Simon

    Do they plan on inviting the FBI? Or would the FBI prefer to keep quiet … ?

  4. Anonymous Coward
    Anonymous Coward

    While those prize amounts won't get all bugs

    Since some will be worth more on the black market, there's really no way they could offer enough to get them all.

    If the black market price for a 0 day kernel exploit that Apple will pay $50K for is $1 million, it makes sense to sell them on the black market unless you're a white hat. So let's say Apple ups the award to $2 million and gets every single 0 day in the world, the black market doesn't have any left. A month or two after the release of the "secure" iOS version that includes all those fixes someone finds a new 0 day, and learns the black market price has gone up to $5 million because of their recent scarcity...

    1. Justin Clift

      Re: While those prize amounts won't get all bugs

      Sure. It could become an "arms race" towards whoever has the deepest pockets.

      Bearing in mind that although the various three letter agencies have deep pockets, Apple does too.

      In the meantime, the phones could likely become increasingly secure. With the side benefit of various hats out there dedicating quite a lot of time to making that happen (through looking for the holes).

      1. Anonymous Coward
        Anonymous Coward

        Re: While those prize amounts won't get all bugs

        I suppose for the more expensive bugs, Apple could use an intermediary to buy the bugs on the black market, rather than openly offering a bounty that essentially puts a floor on the black market price. Not to mention that those selling bugs would ask a lot more if they knew they were dealing with Apple, because they have the deepest pockets there are.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like