Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So the short end of the stick, Apple is trying to be stingy on the rewards paid for finding these issues and is complaining that they're not competitive?


It's more like the exploit buyers will always pay more than what Apple would, so if Apple raises its bounties the exploit buyers will raise their amount too. Zerodium could just offer 2x as much as Apples bounty, and Apple can never win on price. It's a losing game for apple to play.

What Apple can compete on are the non-monetary incentives, such as prestige, rewards, access, etc.


>Zerodium could just offer 2x as much as Apples bounty, and Apple can never win on price.

I'm a die-hard Android fan, but even I'm forced to admit that iPhone has much better security. And security is a big selling point.

Raising the bug bounty to $10 million and it would still be pocket change to Apple, but it would result in:

1. Free advertisement

2. Good PR

3. Outbid the black market for iOS exploits

4. Encourage more white hats to look into iOS security


> 3. Outbid the black market for iOS exploits

That will never work. Zerodium and others are just middlemen that sell to the US/CA/UK/AU/NZ government. They aren't selling these exploits to random companies or underground hackers.

The NSA will pay an unlimited amount of money to have iOS remote 0days sitting on the shelf because they might have a small window where say, an ISIS leader's kid left his iPhone in the room during an important meeting.


Why do you think that organized crime and governments can't afford $10 million per zero day?

There are amounts that they can't afford, but those amounts would stretch Apple's wallet as well.


Governments certainly can afford such amounts. If you're developing a cyberweapon with an important purpose (e.g. Stuxnet) then putting in 3-5 zerodays at $10m each is within your budget, it's comparable to the cost of physical military hardware that they'd gladly buy and use (and destroy) for goals of similar importance.


> It's more like the exploit buyers will always pay more than what Apple would, so if Apple raises its bounties the exploit buyers will raise their amount too.

That is not how supply and demand work.

(Furthermore, it's also not as simple as exploit buyers paying more, because there are reasons for researchers to sell their exploits to Apple even if other buyers might pay more - the problem described (badly) in the article is that the disparity is currently too high).


The demand in this particular marketplace is, at times, extremely high.


http://www.cnbc.com/2017/05/02/apples-cash-hoard-swells-to-r...

I don't know, but I'm fairly sure, that Apple _could_ outbid the other exploit buyers if they chose.


For a company with $250B in cash sitting on its books this seems like a battle they can win versus any actors even most nation states :)


+1

Apple (and the others) controls how much they invest in writing secure code, and how they manage the trade-offs with, for example, investment in shiny new functionality.

So when they make a security slip up and write code that contains an exploit, it's a good thing that the market punishes them.


As far as I know, Apple's bug bounties are the highest in the industry. They're not competitive with the black market, but I don't think they should try to be.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: