【】
Apple is launching its first security bounty. The news comes on the heels of a presentation from Apple’s Ivan Krstic at the annual Black Hat USA security conference in Las Vegas.
Krstic runs security engineering and architecture at Apple and presented an in-depth look at iOS security. This was Apple’s first appearance at Black Hat in four years.
SEE ALSO:Apple opens up on how it approaches security following FBI battleSince its battle with the FBI this spring, Apple has been more outwardly focused on discussing its commitment to security. To that end, Apple is opening up its first security bounty program. The program, which will roll out in September, will accept security submissions in a number of areas. Depending on the type of exploit found, researchers and their organizations will get more money.
The categories and issues up for consideration, along with their bounties, are as follows:
Secure boot firmware components – up to $200,000.
Extraction of confidential material protected by the Secure Enclave Processor – up to $100,000.
Execution of arbitrary code with kernel privileges – up to $50,000.
Unauthorized access to iCloud account data on Apple servers – up to $50,000.
Access to sandboxed processes to user data outside of the sandbox – up to $25,000.
Organizations can accept the money Apple offers or they can donate it to a charity of their choice. Apple says that if researchers choose to donate to a charity, they will consider matching that donation.
Apple tells meit may also award researchers who share significant critical vulnerabilities not outlined above.
Unlike many security bounty programs, this program is notopen to the public. For now, Apple is partnering with a dozen or so security researchers and organizations to focus on finding flaws.
But Apple tells me that this isn’t an attempt to be exclusive. The plan is to open it up to more individuals and organizations over time. Apple also says that if someone not associated with an invited organization responsibly discloses a vulnerability, that feedback will be welcome and they may be invited to join the formal process.
Apple says that it spoke to a number of other companies who have already run successful security bounties and that advice – which was to start small (as to reduce the signal/noise ratio) and then ramp up – contributed to the decision to only involve a few organizations and researchers at the start.
A long time coming
Although it’s great that Apple is introducing a security bounty, it's worth noting that the company has taken its time getting here. Nearly every other major tech company – including Microsoft, Google and Facebook – have offered security bounties for years.
So what took so long?
Apple tells me that although it has been working with outside researchers for years, it has consistently received feedback – from experts inside and outside of the company – that it is more difficult to identify significant security vulnerabilities without a bounty program.
As a result, it makes sense that the company would look (finally!) to outside organizations and researchers to offer their own feedback.
It probably doesn’t hurt that the focus on Apple’s security is now more pointed than ever before. With more eyes on Apple security – and more people trying to bypass it (whether it’s law enforcement or hackers), it makes sense to get more eyes focused on finding flaws.
I understand the need to limit -- at least initially -- involvement in the bounty program, but I do hope Apple commits to expanding the individuals and groups involved quickly. iOS as a platform deserves as many eyes on it as possible.
For now, the focus of the bounty is on iOS, but Apple says that it is open to expanding the bounty program to other platforms (including macOS) and other areas, once the program ramps up.
Have something to add to this story? Share it in the comments.
TopicsAppleCybersecurityiOSiPhone
相关文章

Watch MTV's Video Music Awards 2016 livestream
It's MTV Video Music Awards night. Are you ready?Kanye's going to be there, and he's going to say th2025-12-14
腎髒是身體很重要的一個部位,但是很多的女性朋友會有腎虛的表現,那麽女性腎虛吃什麽?女性腎虛也會有很多的症狀 ,女性腎虛的症狀有哪些呢?有的女性經常會掉頭發,掉頭發是腎虛嗎?一起來看一看 。腎虛吃什麽1、2025-12-14
不善的飲食習慣性、欠佳的生活習慣待會讓人體腸胃越來越愈來愈弱,長此以往就非常容易造成消化道健身運動功能問題 ,乃至可引起胃腸道痙攣 ,當此類情況產生後,病人不但要承擔極大的人體上的痛楚 ,另外日常生活和工作2025-12-14
我們平時食用的涼菜中,涼拌木蘭芽可以說是一道不錯的美味,這種涼菜還可以讓人們增加食欲,當然也要知道木蘭芽哪些人群不能吃 。由於木蘭芽是一種涼性菜 ,所以寒氣太重和脾胃虛弱的人群不能食用。另外 ,有胃病的人也2025-12-14
MashReads Podcast: What makes a good summer read?
Summer is coming to a close and that means one thing -- last-minute vacations!。SEE ALSO:'Ice Cream B2025-12-14
一些人由於長期作息時間表不規律性,並且在飲食搭配上都沒有抑製。長期得話,人體會出現各式各樣的問題 。這假如要想防止這類狀況 ,就務必要提早吃一些保健品來調養我們的人體。那麼黑桑葚桃仁膠襄實際效果如何呢?桑2025-12-14

最新评论