{"id":33579,"date":"2021-09-09T16:26:05","date_gmt":"2021-09-09T20:26:05","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=33579"},"modified":"2021-09-10T16:42:14","modified_gmt":"2021-09-10T20:42:14","slug":"security-researchers-unhappy-with-apples-bug-bounty-program","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/09\/09\/security-researchers-unhappy-with-apples-bug-bounty-program\/","title":{"rendered":"Security Researchers Unhappy With Apple&rsquo;s Bug Bounty Program"},"content":{"rendered":"<p><a href=\"https:\/\/www.macrumors.com\/2021\/09\/09\/security-researchers-apple-bug-bounty-complaints\/\">Juli Clover<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2021\/09\/09\/security-researchers-apple-bug-bounty-complaints\/\"><p>Apple offers a bug bounty program that&rsquo;s designed to pay security researchers for discovering and reporting critical bugs in Apple operating systems, but researchers are not happy with how it operates or Apple&rsquo;s payouts in comparison to other major tech companies, reports <em><a href=\"https:\/\/www.washingtonpost.com\/technology\/2021\/09\/09\/apple-bug-bounty\/\">The Washington Post<\/a><\/em>.<\/p>\n<p>In interviews with more than two dozen security researchers, <em>The Washington Post<\/em> collected a number of complaints. Apple is slow to fix bugs, and doesn&rsquo;t always pay out what&rsquo;s owed.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.washingtonpost.com\/technology\/2021\/09\/09\/apple-bug-bounty\/\">Reed Albergotti<\/a> (<a href=\"https:\/\/twitter.com\/ReedAlbergotti\/status\/1435972101723201537\">tweet<\/a>, <a href=\"https:\/\/news.ycombinator.com\/item?id=28469193\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.washingtonpost.com\/technology\/2021\/09\/09\/apple-bug-bounty\/\"><p>Ultimately, they say, Apple&rsquo;s insular culture has hurt the program and created a blind spot on security.<\/p>\n<p>&ldquo;It&rsquo;s a bug bounty program where the house always wins,&rdquo; said Katie Moussouris, CEO and founder of Luta Security, which worked with the Defense Department to set up its first bug bounty program. She said Apple&rsquo;s bad reputation in the security industry will lead to &ldquo;less secure products for their customers and more cost down the line.&rdquo;<\/p>\n<p>[&#8230;]<\/p>\n<p>&ldquo;The Apple Security Bounty program has been a runaway success,&rdquo; Ivan Krsti&#x107;, head of Apple Security Engineering and Architecture, said in an emailed statement.<\/p>\n<p>[&#8230;]<\/p>\n<p>Payment amounts aren&rsquo;t the only factor for success, however. The best programs support open conversations between the hackers and the company. Apple, already known for being tight-lipped, limits communication and feedback on why it chooses to pay or not pay for a bug[&#8230;] Apple also has a massive backlog of bugs that it hasn&rsquo;t fixed, according to the former employee and a current employee, who also spoke on the condition of anonymity because of an NDA.<\/p>\n<p>[&#8230;]<\/p>\n<p>Tian Zhang, an iOS software engineer, first reported a bug to Apple in 2017. After months of waiting for Apple to fix the bug, Zhang lost patience and decided to blog about his discovery. The second time he reported a security flaw, he says Apple fixed it but ignored him. In July, Zhang submitted another bug to Apple that he says was eligible for a reward. The software was quickly fixed, but Zhang didn&rsquo;t receive a reward. Instead, he was kicked out of the Apple Developer Program.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.loopinsight.com\/2021\/09\/09\/washington-post-on-apples-bug-bounty-program\/\">Dave Mark<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.loopinsight.com\/2021\/09\/09\/washington-post-on-apples-bug-bounty-program\/\"><p>This is a long article, filled with bug bounty stories, many of them anonymously told. Hard to truly know whether this is the squeaky wheel getting all the attention, or something more problematic. [&#8230;] Definitely reads like Apple puts less money into bug bounties, shines less of a light onto bug researcher efforts and successes than its competitors.<\/p><\/blockquote>\n\n<p>We&rsquo;ve been hearing a steady stream of these stories, and it almost doesn&rsquo;t matter whether they&rsquo;re representative. The perception is that Apple is stingy and a pain to deal with, and that will affect whether researchers choose to deal with Apple at all. Why, other than ethics, go through a process that sounds worse than App Review when you can blog about it for fame or quickly sell to another party for more money?<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/07\/13\/more-trouble-with-the-apple-security-bounty\/\">More Trouble With the Apple Security Bounty<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/06\/23\/password-reset-icloud-account-vulnerability\/\">Password Reset iCloud Account Vulnerability<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/05\/19\/apple-vs-security-researchers\/\">Apple vs. Security Researchers<\/a><\/li>\n<\/ul>\n\n<p id=\"security-researchers-unhappy-with-apples-bug-bounty-program-update-2021-09-10\">Update (2021-09-10): <a href=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1436073063729225731\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/lapcatsoftware\/status\/1436073063729225731\">\n<p>We don&rsquo;t know for sure that the stories are representative, but we <em>would<\/em> know a lot more if Apple published any information whatsoever about the bounty payments. Compare the Google Chrome release announcement.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Juli Clover: Apple offers a bug bounty program that&rsquo;s designed to pay security researchers for discovering and reporting critical bugs in Apple operating systems, but researchers are not happy with how it operates or Apple&rsquo;s payouts in comparison to other major tech companies, reports The Washington Post. In interviews with more than two dozen security [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-09-09T20:26:09Z","apple_news_api_id":"04494cf8-b755-48da-afff-fa22a9e837a0","apple_news_api_modified_at":"2021-09-10T20:42:17Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAQ==","apple_news_api_share_url":"https:\/\/apple.news\/ABElM-LdVSNqv__oiqeg3oA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[38,2098,131,31,1837,30,1891,48],"class_list":["post-33579","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apple","tag-apple-security-bounty","tag-bug","tag-ios","tag-ios-14","tag-mac","tag-macos-11-0","tag-security"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/33579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=33579"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/33579\/revisions"}],"predecessor-version":[{"id":33597,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/33579\/revisions\/33597"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=33579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=33579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=33579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}