How does the economy of bug bounty programs work for the company? $100,500 is probably not much for Apple but it's still some engineer's salary. Do the responsible engineer get a pay cut for this bug? Or this kind of 0day bugs are not bugs, but secret features left open from the beginning?
This time, the bug gives the attacker full access to every website ever visited by the victim. That means in addition to turning on your camera, my bug can also hack your iCloud, PayPal, Facebook, Gmail, etc. accounts too.
Agreed, of all the places you could have sold that information the official channel by FAR pays the worst (Apple in particular being a notoriously terrible company to deal with for security problems but by no means are the only ones) which is a huge problem that people should be making a lot more noise about.
I kind of shudder to think of how many of these bugs have been out there for years and only ever ended up in the hands of governments and shady groups like NSO.
I found a bug in Cash App that exposes SSNs, but their max bug bounty is $8000, so fuck 'em. The other option for people finding bugs is to sell it to "the other side" if they pay more money.
No. Fuck-em would be actually selling it, not throwing a hissy fit and publicly outing yourself as potential source of the discovery. They DGAF about that bug, their only concern is very low probability of negative consequences in case of data leak with full attribution, but bugcrowd presence gives CISO full ass coverage.
I have not heard of companies who operate bug bounties punishing engineers. Apple certainly does not do this either. Most companies do the math and decide that it's cheaper for them to deal with paying a research than it is to deal with the possible fallout of an in-the-wild exploit or researchers just dumping zero days on twitter.
A bounty incentivizes people — bad actors included — to responsibly disclose critical bugs. It has the side effect of luring in good actors to find them, but the cost remains negligible compared to the damage they might cause otherwise.
This is overhead; cost of doing business. Finding out you have a bug so you can fix it is much cheaper than not finding out until your customers have been attacked. Trying to get those customers back or get new customers is much much more expensive.
There are certainly much worse bugs than $100k. Think of if Apple itself had been hacked due to a bug. The remediation costs would be very high.
A bug in Knight Capital's stock trader lost $460M in 45 minutes.
A bug in the Ariane 5 rocket caused it to crash, a loss of $370M.
A bug in the Therac-25 radiation machine killed 3 people.
secret features left open from the beginning?
Are you saying Apple engineers are inserting backdoors? What's the motivation? Security bugs are very easy to accidentally introduce when you have complex interacting systems (in this case a browser, a complicated URL parsing syntax, some ancient barely-known file types, and a file sharing application). Occam's razor (and Hanlon's) says it's an accident.
Comments
How does the economy of bug bounty programs work for the company? $100,500 is probably not much for Apple but it's still some engineer's salary. Do the responsible engineer get a pay cut for this bug? Or this kind of 0day bugs are not bugs, but secret features left open from the beginning?
Honestly, $100,000 for this is too low.
Agreed, of all the places you could have sold that information the official channel by FAR pays the worst (Apple in particular being a notoriously terrible company to deal with for security problems but by no means are the only ones) which is a huge problem that people should be making a lot more noise about.
I kind of shudder to think of how many of these bugs have been out there for years and only ever ended up in the hands of governments and shady groups like NSO.
I found a bug in Cash App that exposes SSNs, but their max bug bounty is $8000, so fuck 'em. The other option for people finding bugs is to sell it to "the other side" if they pay more money.
https://bugcrowd.com/cashapp
No. Fuck-em would be actually selling it, not throwing a hissy fit and publicly outing yourself as potential source of the discovery. They DGAF about that bug, their only concern is very low probability of negative consequences in case of data leak with full attribution, but bugcrowd presence gives CISO full ass coverage.
This bug would, in the wrong hands, let someone steal a lot more than $100k.
It should be at least 10x higher, this bug affects a billion users
I have not heard of companies who operate bug bounties punishing engineers. Apple certainly does not do this either. Most companies do the math and decide that it's cheaper for them to deal with paying a research than it is to deal with the possible fallout of an in-the-wild exploit or researchers just dumping zero days on twitter.
A bounty incentivizes people — bad actors included — to responsibly disclose critical bugs. It has the side effect of luring in good actors to find them, but the cost remains negligible compared to the damage they might cause otherwise.
This is overhead; cost of doing business. Finding out you have a bug so you can fix it is much cheaper than not finding out until your customers have been attacked. Trying to get those customers back or get new customers is much much more expensive.
There are certainly much worse bugs than $100k. Think of if Apple itself had been hacked due to a bug. The remediation costs would be very high.
A bug in Knight Capital's stock trader lost $460M in 45 minutes.
A bug in the Ariane 5 rocket caused it to crash, a loss of $370M.
A bug in the Therac-25 radiation machine killed 3 people.
Are you saying Apple engineers are inserting backdoors? What's the motivation? Security bugs are very easy to accidentally introduce when you have complex interacting systems (in this case a browser, a complicated URL parsing syntax, some ancient barely-known file types, and a file sharing application). Occam's razor (and Hanlon's) says it's an accident.
Apple’s Q4 2022 net profit was 20 billion US dollars.
They can afford the bounty.