It's not though, since the alternative to disclosing the bug to apple is to either hoard it for yourself or sell it to someone, both of which keep the attack vector open and millions of users at risk. That's where the ethical discussion comes in, and there's not really a parallel to the case with the photographer/graphic artist.
(And just to be clear, I do think that fair compensation is a part of that ethics discussion, but it doesn't trump other concerns.)
I was not addressing the ethical question involved - just the logic behind "Apple thanks you, therefore you should be happy".
If Apple is not providing reasonable money compensation to white hat security researchers then they are willingly leaving this space opened for black hats.
I read that more as "Apple thanks you, at which point you realize you were smart enough to have made more money doing something else", not "therefore you should be happy".
You are trying to read the comment as positive of Apple's thank you and exposure, when it sounded to me much more like a reality check: I would go so far as to say Thomas's point might have been "when Apple thanks you you will come to regret wasting your time--which you now know was always valuable--on them". That isn't "you should thank Apple for making you realize that"...
> hoard it for yourself or sell it to someone, both of which keep the attack vector open and millions of users at risk.
I think this logic is inherently flawed.
If there was no monetary incentive and the only ROI was a thanks from Apple, maybe the bug in question would not have been found in the first place. Becoming aware of a bug does not suddenly put people at any more risk than they were previously in, prior to bug discovery.
>Becoming aware of a bug does not suddenly put people at any more risk than they were previously in, prior to bug discovery.
I agree, which is why I said "keep[s] [...] millions of users at risk" not "puts millions of users at risk". An unfound bug is still a potential zero-day. With something as valuable as an iphone exploit, we know multiple entities are desperately looking for it, so I wouldn't err on the side of assuming that any exploit would not be found. (or put more succintly: If you've found it, someone else might've to)
(And just to be clear, I do think that fair compensation is a part of that ethics discussion, but it doesn't trump other concerns.)
(edit: typo)