Hacker News new | ask | show | jobs
by henryackerman 1904 days ago
Agreed, what's going on should be completely transparent. The security of the system must only depend on the private keys and implementation correctness.
1 comments

While security by obscurity is not ideal, it is an additional hurdle. Apple knows that security flaws in their stuff is very valuable for both nefarious and state hackers, so the chances of someone finding an issue and reporting it to them to resolve it are kinda low.
Not if the bounty is high enough and payable to an anonymous recipient (perhaps vis cryptocurrency).
I don't think state-affiliated hackers really care about money.
Good point, though I imagine a large bounty payable to an anonymous bitcoin address could encourage individuals within such an organization to divulge vuln info.