Apple announced today that it is expanding its BUG bounty
program, making it open to all security researchers, and expanding the size of
its bug-reporting devices, according to cnbeta.
At
the black hat security conference in Las Vegas in August, apple announced that
it would expand its BUG bounty program, inviting security experts to submit
security vulnerabilities found in apple products.
Previously, apple only offered BUG rewards to selected
security researchers by invitation, and only accepted security vulnerabilities
on iOS.Starting today, the company
will receive bug reports for a wider range of products, which also include
iPadOS, macOS, tvOS, watchOS and iCloud.
In addition, the company increased its maximum bug bounty
from $200,000 to $1.5 million, based on the danger and complexity of bugs.
Apple
today detailed the rules of bug bounty on its website, which is now in effect.
The rules are so strict that researchers must submit clear reports in order to
win the top prizes and bonuses.Include:
A detailed description of the problems reported;Any preconditions and steps to bring the system into the
affected state;Reasonable and reliable
utilization of reported problems;Enough
information to allow apple to reasonably reproduce the problem.
If the reported bugs are unprecedented, affecting multiple
platforms, involving multiple hardware and software, and affecting sensitive
components, researchers have a better chance of winning up to $1.5 million.
As we known,smart phone is the most important daily necessities
of modern people, many important things are done through the mobile phone, so
the security of mobile phone system becomes very important.
www.grashine.com
Comments
Post a Comment