Not part of the security industry so not sure what is common or not, but I would understand Apple being worried about sharing too much with a researcher they may not be familiar with.
I would also understand the researcher's point of view that this fell through the cracks or Apple is not willing to fix; and is likely what happened.
Apple will pay a million bucks? Fine, NSA TAO will pay $10m. Apple can't pay $10m or $100m a bug on a regular basis, for the customers whom this matters the check is basically blank, as much as it takes.
>One person who will share those sales numbers is a South African hacker who goes by the name “the Grugq” and lives in Bangkok. For just over a year the Grugq has been supplementing his salary as a security researcher by acting as a broker for high-end exploits, connecting his hacker friends with buyers among his government contacts. He says he takes a 15% commission on sales and is on track to earn more than $1 million from the deals this year. “I refuse to deal with anything below mid-five-figures these days,” he says. In December of last year alone he earned $250,000 from his government buyers. “The end-of-year budget burnout was awesome.”
https://www.forbes.com/sites/andygreenberg/2012/03/21/meet-t...
It should probably be pointed out that once you do this, you’re in the weapons industry. Your work will likely be used, directly or indirectly, to put a bomb through someone’s roof or put them in prison for a very long time. Make sure you’re okay with the ethics of it.
By this logic, americans should stop using cars at all, cause all that oil is coming from middle east, saudi arabia.
Also, I'm not sure that saying "we have discovered a deeper problem that here beyond what you reported" really delivers much information beyond perhaps telling the researcher to keep investigating (although if they're already getting the bounty, the additional investigation wouldn't really be useful).
Having an e-mail from the company confirming the bug is serious and systemic massively raises its market value. Security is necessarily trust less. These game dynamics are unavoidable.
That is a very mistaken assumption. Even NDAs backed by threats from nation state intelligence agencies aren’t sufficient to keep exploits from being resold multiple times.
Or maybe that someone in the first buyer's organization resold it?
Damn strange feature that allows me to compromise any screen-locked mac.
If you get a certain key combination in before focus switches, it stays on the desktop, and you can continue to input - fire up a terminal, do whatever you fancy. It’s all blind, but still perfectly dangerous.
Certain full screen apps, if they have focus when you lock, retain focus indefinitely. Paradox interactive games, for instance - stellaris exhibits the behaviour nicely. This even includes mouse focus, and if you Apple-tab, then focus goes to whatever you Apple-tab to. You can only restore focus to the Lock Screen by clicking in the password field.
Both times I reported this I got a pedantic “locking the screen does not terminate applications, which may continue to run in the background” response.