7 comments

[ 7.1 ms ] story [ 52.9 ms ] thread
>Generally, white hat security researchers publicly reveal flaws like this only after informing the company and giving it ample time to fix the issues. But Henze is refusing to assist Apple because it doesn’t offer paid bug bounties

This is starting to look really bad for the infosec "community." Without rehashing all the old arguments around disclosure, and the sorta-recent arguments around bug bounties, we're now at the point where this doesn't not look like extortion.

"That's an awfully nice operating system you've got there. It'd be a shame if someone were to disclose a security flaw without giving you ample opportunity to fix it."

This isn't the mob burning someones shop down. This is more like pointing out, hey dude, your door is open, you should close it.

They don't owe apple anything, and they are not causing the damage (apple's negligence did). If apple doesn't want to handle this in private, they will have to handle this in public. I don't see the problem. Coordinated disclosure is a courtesy, not a rule.

You don't have to convince me.

You have to convince the technically disinclined that know nothing about disclosure, but know plenty about people acting in ways that "ensure their job security."

If large cap corporations refuse to pay researchers for finding security problems, then clearly they do not take security seriously enough. How else to publicly shame them for their penny-pinching?
False dichotomy.
It has precedence:

https://www.helpnetsecurity.com/2018/11/07/virtualbox-guest-...

> Zelenyuk has responsibly disclosed to Oracle (via the SecuriTeam Secure Disclosure program) another VirtualBox vulnerability over a year ago, but apparently Oracle took a very long time to fix it and ultimately failed to credit Zelenyuk for the discovery.

---

https://news.ycombinator.com/item?id=16000550

archived: https://web.archive.org/web/20180202100849/https://medium.co...

I Got Paid $0 from the Uber Security Bug Bounty

---

https://techcrunch.com/2013/08/18/security-researcher-hacks-...

Security Researcher Hacks Mark Zuckerberg’s Wall To Prove His Exploit Works

absolutely. but it isn't an either-or.