5 ms·
A $100,500 bounty seems pretty cheap compared to the severity of the issue, or is it common?
by Mougatine 5y ago
A $100,500 bounty seems pretty cheap compared to the severity of the issue, or is it common?
- runjake 5y agoIt's the most that Apple's paid out for a bug bounty, as far as I know. The previous highest was $500 less ($100,000).
- tptacek 5y agoIt's also an interaction-required bug, apparently.
- ffhhj 5y agoNow imagine how much money they saved by not researching those bugs themselves.
- jtbayly 5y agoNow imagine how much the researcher gave up by not selling it to Cellebrite.
- saagarjha 5y agoCellebrite doesn't really have a use for a browser vulnerability.
- tptacek 5y agoYou mean to say someone like NSO Group, not Cellebrite. But you should know that it's possible driving up the price of bugs helps companies like NSO, rather than hurting them. They're middlemen, taking a cut of the value of transactions between exploit developers and downstream customers. Those downstream customers, for shops like NSO, are overwhelmingly government agencies that aren't especially price-sensitive to the cost of individual bugs.
- Thorrez 5y agoI assume NSO group operates in their own best interest. If them buying a bug and reselling it hurts them, then I think they won't do it. Although I guess one reason they might buy a bug that would lead to financial harm is to prevent a competitor from getting it, which might be an even worse financial harm.