时间:2025-01-18 13:53:42 来源:网络整理编辑:探索
Apple is launching its first security bounty. The news comes on the heels of a presentation from App
Apple is launching its first security bounty. The news comes on the heels of a presentation from Apple’s Ivan Krstic at the annual Black Hat USA security conference in Las Vegas.
Krstic runs security engineering and architecture at Apple and presented an in-depth look at iOS security. This was Apple’s first appearance at Black Hat in four years.
SEE ALSO:Apple opens up on how it approaches security following FBI battleSince its battle with the FBI this spring, Apple has been more outwardly focused on discussing its commitment to security. To that end, Apple is opening up its first security bounty program. The program, which will roll out in September, will accept security submissions in a number of areas. Depending on the type of exploit found, researchers and their organizations will get more money.
The categories and issues up for consideration, along with their bounties, are as follows:
Secure boot firmware components – up to $200,000.
Extraction of confidential material protected by the Secure Enclave Processor – up to $100,000.
Execution of arbitrary code with kernel privileges – up to $50,000.
Unauthorized access to iCloud account data on Apple servers – up to $50,000.
Access to sandboxed processes to user data outside of the sandbox – up to $25,000.
Organizations can accept the money Apple offers or they can donate it to a charity of their choice. Apple says that if researchers choose to donate to a charity, they will consider matching that donation.
Apple tells meit may also award researchers who share significant critical vulnerabilities not outlined above.
Unlike many security bounty programs, this program is notopen to the public. For now, Apple is partnering with a dozen or so security researchers and organizations to focus on finding flaws.
But Apple tells me that this isn’t an attempt to be exclusive. The plan is to open it up to more individuals and organizations over time. Apple also says that if someone not associated with an invited organization responsibly discloses a vulnerability, that feedback will be welcome and they may be invited to join the formal process.
Apple says that it spoke to a number of other companies who have already run successful security bounties and that advice – which was to start small (as to reduce the signal/noise ratio) and then ramp up – contributed to the decision to only involve a few organizations and researchers at the start.
Although it’s great that Apple is introducing a security bounty, it's worth noting that the company has taken its time getting here. Nearly every other major tech company – including Microsoft, Google and Facebook – have offered security bounties for years.
So what took so long?
Apple tells me that although it has been working with outside researchers for years, it has consistently received feedback – from experts inside and outside of the company – that it is more difficult to identify significant security vulnerabilities without a bounty program.
As a result, it makes sense that the company would look (finally!) to outside organizations and researchers to offer their own feedback.
It probably doesn’t hurt that the focus on Apple’s security is now more pointed than ever before. With more eyes on Apple security – and more people trying to bypass it (whether it’s law enforcement or hackers), it makes sense to get more eyes focused on finding flaws.
I understand the need to limit -- at least initially -- involvement in the bounty program, but I do hope Apple commits to expanding the individuals and groups involved quickly. iOS as a platform deserves as many eyes on it as possible.
For now, the focus of the bounty is on iOS, but Apple says that it is open to expanding the bounty program to other platforms (including macOS) and other areas, once the program ramps up.
Have something to add to this story? Share it in the comments.
TopicsAppleCybersecurityiOSiPhone
Is Samsung's Galaxy Note7 really the best phone?2025-01-18 13:19
【波盈足球】 梅西老戰友:世足摘冠仍無法結束GOAT爭論 ( 梅西,冠軍 )2025-01-18 13:13
【波盈足球】 足球梅西與PSG再續約1年 挑戰C羅歐冠進球紀錄 ( 梅西,巴黎 )2025-01-18 13:00
【波盈足球】 世足梅西捧盃照突破7千萬讚 攝影師歪打正著完成經典之作 ( 梅西,照片 )2025-01-18 13:00
Florida hurricane forecast remains uncertain, but trends in state's favor2025-01-18 12:42
2022世界杯小組賽 日本vs西班牙 前瞻與分析(日本西班牙足球預測)2025-01-18 12:35
2022世界杯半決賽預測來了(世界杯2022賽程及結果)2025-01-18 12:20
世界杯之旅第六天:小組賽的二輪懸念即將揭曉(世界杯預選賽共幾輪)2025-01-18 12:18
Tourist survives for month in frozen New Zealand wilderness after partner dies2025-01-18 12:18
【波盈足球】 梅西老戰友:世足摘冠仍無法結束GOAT爭論 ( 梅西,冠軍 )2025-01-18 12:10
This chart shows just how high Simone Biles can jump2025-01-18 13:38
【波盈足球】 又有怪物誕生 ?姆巴佩15歲弟弟比賽畫麵破百萬觀看 被比法國球星 ( 他的,巴黎 )2025-01-18 13:35
為什麽守門員的球衣號碼是1號 ?世界杯8強隊伍門將號碼盤點(足球守門員的規則和攻略)2025-01-18 13:02
【波盈足球】 足球批C羅成球隊累贅 前皇馬主帥:他狼狽不堪是自作自受 ( 曼聯,美聯社 )2025-01-18 13:01
Photos show the Blue Cut fire blazing a path of destruction in California2025-01-18 12:45
【波盈足球】 聖誕氣氛滿滿 安聯小小世界盃決戰台北田徑場 ( 足球,台北 )2025-01-18 12:34
【波盈足球】 世足想拿第2座冠軍?阿根廷名將爆:梅西有意再戰2026年 ( 梅西,阿根廷 )2025-01-18 12:28
【波盈足球】 世足法媒提梅西進球不算 主裁判秀手機截圖打臉 ( 尼亞,進球 )2025-01-18 11:39
Darth Vader is back. Why do we still care?2025-01-18 11:35
【波盈足球】 又有怪物誕生 ?姆巴佩15歲弟弟比賽畫麵破百萬觀看 被比法國球星 ( 他的,巴黎 )2025-01-18 11:16