|
|
|
|
|
by chrisfinazzo
2971 days ago
|
|
The bounty security program (announced at BlackHat 2016) was created to deal with these kinds of scenarios. They will pay depending on the severity of the bug and the affected subsystem. Of course, now that this mechanism exists, I'm just waiting for Apple to sue GreyKey and Cellebrite out of existence, confiscate all the devices, and charge the founders with aiding industrial espionage or overreach related to pursuing terrorism. (I'd also like to see the same thing happen with the NRA, but alas that doesn't seem to be in the cards for the current circus in Washington) The difference between more legit researchers and these guys is that they will work with anybody as long as they cut a check. Real R&D has more scruples than to do that. |
|