Hacker News new | ask | show | jobs
by enlightenedfool 741 days ago
Does Kaspersky care at all about the monetary aspect of the bounty? I think they are ethically bound and probably already know they will not get paid.
1 comments

according to TFA, they care:

“We found zero-day, zero-click vulnerabilities, transferred all the information to Apple, and did a useful job,” Dmitry Galov, head of the Russian research center at Kaspersky Lab, told Russian news outlet RTVI. “Essentially, we reported a vulnerability to them, for which they must pay a bug bounty.”

Galov even proposed that Kaspersky donate the bounty to charity, but Apple rejected this, citing internal policies without explanation. It’s not uncommon for research firms to donate bounty payments from large companies to charity. Some perceive it as an extension of their ethical obligation, but it undeniably contributes to a positive reputation within the security community.

“Considering how much information we provided them and how proactively we did it, it is unclear why they made such a decision.”

>”…for which they must pay a bug bounty”

Galov’s statement is plainly wrong. The very first line in Apple’s bug bounty program terms and conditions states that awards are granted solely at their exclusive discretion.

There is no “must.”

Was the quote in English or a translation?
> “Considering how much information we provided them and how proactively we did it, it is unclear why they made such a decision.”

It is because you uncovered the backdoor, stupid. They worked hard to hide it. /s