I've managed several programs for some very large companies and haggling over bounties with a researcher is a _really_ bad idea. You set your bounty amounts and stick to them. If people want to haggle over impact that's fine, but once you exceed your quoted bounty amount for one person then everyone expects it.
The bean counters also play a big role. Most companies aren't ready for big bounty payouts when a program first starts. They set a fixed budget and are more likely to end a program completely if the bottom line cost is too high, regardless of the security impact. Security teams are aware of this and try to walk a fine line.
For researchers who are having problems with programs I'd suggest trying to form a better relationship with the triage teams and security teams. Be helpful, not confrontational. Companies get their best bang-for-buck when they can court good researchers. They love getting quality researchers who report multiple findings and they'll do quite a lot to make them happy, including paying bonus bounties for future reports and being far more transparent with triage status.
At the beginning of a high profile bug bounty program I'd expect higher expenditure than in the following fiscal year due to the backlog of researchers who really want to "sell" to an official channel, not a slow start.
It’s not hard to read it as “we don’t negotiate with terrorists”, and Apple (or Google or Amazon…) know people think they have deep pockets
<Giant bold white letters fade in against a black background>
A R R O G A N C E
If they don't want to play ball, take it to someone that will appreciate your work. Should it be used nefariously, you are still helping because they might take you more seriously next time, as they should have in the first place.
carrot versus stick.
As far as exposing users, that makes assumptions about the actions of a number of people including the company in question which could, if it so desired, assemble the resources to push a fix within 48 hours.
simply put if Apple doesn't find a way to come to an agreement with this person in a timely manner, they are just saying they see the zero day and the consequences for their users as acceptable losses as preferable to the payment
How did you protect yourself against those?
Also, as a security researcher, are there alternatives you'd recommend more? Would Linux/Windows be more secure?
You tried to report to apple. You didn't like the way they "treated" you, so you decided to sell it on black market. The black market person tried to hack you. You then went to the fbi to complain about how your black market buyer treated you?
Am i missing something from this story? That seems like a really bad plan.
On a serious note, I'm glad researchers like you exist.
I submitted some details (nothing technical, just the classification and affected platforms) of my vulnerability to Zerodium. Two days later someone tried to hack into all of my personal accounts and failed due to 2FA, and not many people have the email I used when I communicated with them. I've found other buyers outside the US, but I had ethical concerns and decided against them (at a 300K min loss).
I've found other buyers outside the US, but I had ethical concerns and decided against them (at a 300K min loss).
What type of buyers exist who are unable to fix the vulnerability (in this case, who are not Apple or the affected vendor or do not collaborate with Apple, etc.) but might be considered ethical to sell to?
I imagine some people think being rewarded for finding vulnerabilities is unethical entirely, but there seems to be a huge dose of pragmatism around the space.
Alternatively depending on how nationalistic someone feels NSA could be a eithical buyer for them as well.