Apple new bounty program offers higher price and expands the scope of service for researchers (Image via: Cult of Mac)

Apple Offers Big Reward For iPhone Security Flaws Researchers

Apple just made a beneficial announcement at the annual Black Hat security conference in Las Vegas on Thursday. The company said that it will provide $1 million to detect flaws in iPhones. The $1 million bounty reward would apply only to remote access to the iPhone kernel without any action from the phone’s user. The company already set price for bounty previously for $200,000 to report bug that can be fixed with software updates. This was to prevent it to be exposed to criminals and spies.The bounty program created amid the rising concern of hackers who are hired by the governments.

Governments often break into the mobile devices of dissidents, journalists, and human rights advocates. Their contractors and brokers are willing to pay for $2 million to get the best hacking techniques in obtaining information from devices. The price that Apple offered is in the same range with some published prices from contractors. One of the private companies that sells hacking techniques to the government is Israel’s NSO Group. Although there’s a denial from the group saying that the development of its technology is licensed to intelligence and law enforcement agencies. So the group said it is used only for preventing and investigating terror and crime

Despite all of the hackers from governments, there are also people who have bad intention outside of it. Therefore, any kind of security flaw needs to be identified. Recently, a security researcher identified a macOS flaw, but refused to submit it to Apple until the company pays researchers for Mac security flaws. Now Apple also stated that the company will expand the opening of its bug bounty program to all researchers. So the researchers are going to be rewarded for identifying any flaw found in iOS, iCloud, tvOS, iPadOS, watchOS, and macOS.

Source: https://www.theverge.com/2019/8/8/20756638/apple-macos-security-bug-bounty-rewards-program