时间:2026-01-08 06:44:43 来源:网络整理编辑:探索
Apple is launching its first security bounty. The news comes on the heels of a presentation from App
Apple is launching its first security bounty. The news comes on the heels of a presentation from Apple’s Ivan Krstic at the annual Black Hat USA security conference in Las Vegas.
Krstic runs security engineering and architecture at Apple and presented an in-depth look at iOS security. This was Apple’s first appearance at Black Hat in four years.
SEE ALSO:Apple opens up on how it approaches security following FBI battleSince its battle with the FBI this spring, Apple has been more outwardly focused on discussing its commitment to security. To that end, Apple is opening up its first security bounty program. The program, which will roll out in September, will accept security submissions in a number of areas. Depending on the type of exploit found, researchers and their organizations will get more money.
The categories and issues up for consideration, along with their bounties, are as follows:
Secure boot firmware components – up to $200,000.
Extraction of confidential material protected by the Secure Enclave Processor – up to $100,000.
Execution of arbitrary code with kernel privileges – up to $50,000.
Unauthorized access to iCloud account data on Apple servers – up to $50,000.
Access to sandboxed processes to user data outside of the sandbox – up to $25,000.
Organizations can accept the money Apple offers or they can donate it to a charity of their choice. Apple says that if researchers choose to donate to a charity, they will consider matching that donation.
Apple tells meit may also award researchers who share significant critical vulnerabilities not outlined above.
Unlike many security bounty programs, this program is notopen to the public. For now, Apple is partnering with a dozen or so security researchers and organizations to focus on finding flaws.
But Apple tells me that this isn’t an attempt to be exclusive. The plan is to open it up to more individuals and organizations over time. Apple also says that if someone not associated with an invited organization responsibly discloses a vulnerability, that feedback will be welcome and they may be invited to join the formal process.
Apple says that it spoke to a number of other companies who have already run successful security bounties and that advice – which was to start small (as to reduce the signal/noise ratio) and then ramp up – contributed to the decision to only involve a few organizations and researchers at the start.
Although it’s great that Apple is introducing a security bounty, it's worth noting that the company has taken its time getting here. Nearly every other major tech company – including Microsoft, Google and Facebook – have offered security bounties for years.
So what took so long?
Apple tells me that although it has been working with outside researchers for years, it has consistently received feedback – from experts inside and outside of the company – that it is more difficult to identify significant security vulnerabilities without a bounty program.
As a result, it makes sense that the company would look (finally!) to outside organizations and researchers to offer their own feedback.
It probably doesn’t hurt that the focus on Apple’s security is now more pointed than ever before. With more eyes on Apple security – and more people trying to bypass it (whether it’s law enforcement or hackers), it makes sense to get more eyes focused on finding flaws.
I understand the need to limit -- at least initially -- involvement in the bounty program, but I do hope Apple commits to expanding the individuals and groups involved quickly. iOS as a platform deserves as many eyes on it as possible.
For now, the focus of the bounty is on iOS, but Apple says that it is open to expanding the bounty program to other platforms (including macOS) and other areas, once the program ramps up.
Have something to add to this story? Share it in the comments.
TopicsAppleCybersecurityiOSiPhone
These glasses hide a fitness tracker on your face2026-01-08 06:33
作為C羅的小粉絲,姆巴佩的“身價”和偶像還差多少?(姆巴佩致敬c羅)2026-01-08 06:25
蘇炳添首秀6秒52奪冠 他60米前十成績更新了 !平均值突破6秒50(世錦賽60米蘇炳添6秒42摘銀創曆史)2026-01-08 06:22
2023英超聯賽第23輪:西漢姆聯VS切爾西賽前情報2026-01-08 06:13
Richard Branson 'thought he was going to die' in bike accident2026-01-08 05:54
傳奇球衣號碼背後的故事,除了情懷我們還能聊點啥?(姆巴佩巔峰時期的c羅)2026-01-08 05:50
杜蘭特抱團勇士並不能證明自己的偉大 換保羅2026-01-08 05:08
【早報】7分領跑開啟2023!阿森納新年讓英超換新天?2026-01-08 04:35
U.S. government issues warning on McDonald's recalled wearable devices2026-01-08 04:32
強勁!C羅康概送戰靴給葡萄牙U17女足 ,薩裏豪言總裁難達成(姆巴佩與c羅合影)2026-01-08 04:05
Man stumbles upon his phone background in real life2026-01-08 06:20
ESPN最新實力榜出爐 !勇士第一太陽第二,籃網第三湖人跌至第16位(籃網傷勢)2026-01-08 06:15
太陽梭哈,籃網隱忍 ,湖人天怎麽又亮了?(保羅和總冠軍獎杯p圖)2026-01-08 06:12
官方實力榜雄鹿領跑 勇士第2火箭第6湖人跌至第22(籃網2021)2026-01-08 05:59
Cat gets stuck in the most awkward position ever2026-01-08 05:42
!恭喜保羅 !KD大交易正式官宣 ,西部要變天了(保羅有沒有拿過總冠軍)2026-01-08 05:18
英超第12輪補賽 :曼城32026-01-08 05:18
中韓同在A組 ,2023年亞洲羽毛球混合團體錦標賽小組賽抽簽出爐2026-01-08 04:52
Michael Phelps says goodbye to the pool with Olympic gold2026-01-08 04:48
生涯至今無緣總冠軍 ,保羅是否配得上名人堂 ?杜蘭特給出看法(保羅nba冠軍)2026-01-08 04:16