Apple to offer bug bounty program


Wired:

Pressure for Apple to do this has been mounting for months. In the fallout from its battle with the FBI, for example, Apple took flack from some in the security community. They speculated that the FBI had only ultimately been able to find a third party to exploit iPhone security because Apple had no incentive in place to encourage researchers to share that information directly with Apple.

It's interesting there's a service industry around bug/security hunting.

Starting in September, Apple will offer up to $200,000 for its biggest vulnerabilities, which are those affected Apple's secure boot firmware. Also reported will pay up to $100,000 for leaks from its Secure Enclave Processor. Apple will also offer up to $50,000 for kernel privilege exploits and weaknesses to iCloud account data. Lastly, up to $25,000 vulnerabilities leading to the breaking out of sandboxed processes that expose user data.