Apple refused to pay bounty to Kaspersky for uncovering vulnerability
9to5mac.com
9to5mac.com
> While Kaspersky is a multi-national company, it was founded and headquartered in Russia, a country the United States has heavily sanctioned due to the war in Ukraine. This could severely restrict financial transactions between U.S. companies and those in the region.
> Additionally, per Apple Security Bounty’s terms and conditions, “Apple Security Bounty awards may not be paid to you if you are in any U.S. embargoed countries or on the U.S. Treasury Department’s list of Specially Designated Nationals, the U.S. Department of Commerce Denied Person’s List or Entity List, or any other restricted party lists.”
I just don’t get why Apple wouldn’t cite the law if that’s the reason? Surely doesn’t look good on them if they’re just holding back bounties for undisclosed reasons.
Makes total sense to me.
Any potential downside far outweighs the upside. Apple does not want to get on the State Department’s shit list, period, and certainly not to do goodwill efforts for the Russians.
"Oh, you can't pay because we are in Russia, just pay to our Massachusetts subsidiary!"
I would still call this a "refuse to" vs "can do", but hey, Apple can keep that money - keeps the layoffs away.
It's not the first time we've seen Apple not playing nice with their bug bounty programme, so it's something of a pattern of behaviour. "A show of good will" is exactly what they need.
... and who knows where that could lead. Why, the rabble might get the idea that they're allowed to disapprove of decisions Apple makes!
It clearly has. There are lots of hackers and security researchers who will make very different decisions depending on if they expect Apple will honor their bounties. Traditionally, people who report security bugs have been treated poorly, and arbitrary rejections certainly helps move the incentives towards the exploit market instead.
Should be “Apple cannot legally pay bounty to Russian company due to sanctions.”
There’s a very real chance that headlines of the variety “Apple makes donation to charity to pay Russian hackers” float around. It’s not even wrong (though it lacks a lot of context).
I’m doubtful Kaspersky is even that mad about it; they knew they weren’t getting paid at the outset.
Well, as long as the charity is a legit thing and not some shady attempted workaround.
Do tell...
But the company constantly gets squeezed between trying to fight obnoxious demands from the Russian government (including, I suspect, by not expanding into businesses where those demands would be un-resistable), and trying to fight suspicion from everybody else.
> At the age of 16, Kaspersky entered a five-year program with The Technical Faculty of the KGB Higher School,[14][15] which prepared intelligence officers for the Russian military and KGB.[6][7] He graduated in 1987[14] with a degree in mathematical engineering and computer technology.[3][7] After graduating college, Kaspersky served the Soviet military intelligence service [5] as a software engineer.
https://en.wikipedia.org/wiki/Eugene_Kaspersky#:~:text=At%20....
I knew dozens of people in my computer security career who'd "openly" been in technical branches of the (mostly US) military, or done classified work for defense contractors, or in a few cases who had worked for outright spy agencies (on what I do not know). Maybe a handful of them might have still been not-openly working for those agencies; most almost certainly were not.
Many of them were still obviously sympathetic to those agencies' agendas. That did not necessarily extend to helping them out in any way (although sometimes it definitely did). A few sure seemed exactly the opposite, and if they were in deep cover, they probably could have served that goal better by just keeping their mouths shut. In a few cases they helped to build organizational or technical structures that clearly would have made it harder for anybody, including the agencies they'd previously worked for, to subvert their new employers' security guarantees.
So, 35+ years ago, at 16, Kaspersky took what was probably the only technical education opportunity available to him in Soviet Russia(TM). At maybe 20, he took what was probably the only job available to him. Going by that same Wikipedia article, apparently within a year or two, he moved to private industry (such as it was in that place and time). That included getting an early release from military service (not sure how that interacted with the dissolution of the USSR, which happened at more or less the same time).
That's par for the course.
It is very, very hard to find a person or company in that space that's squeaky clean, has no conflicts of interest, and/or has no ties at all with any government or government agency you might be afraid of.
If it's a large company (bigger than Kaspersky), and has been around a while, there's a real chance that it's released products with all kinds of weird back doors, with and/or without the knowledge of its executive management. Maybe even back doors for multiple competing actors. And at the same time it may release many more products that don't have them.
I don't think Kaspersky (the man) is some kind of revolutionary, nor do I think Kaspersky (the company) is going to openly defy the Russian government. I also don't think that their trustworthiness couldn't change at any given time. I do think that they're at least averagely "good". And I think that they get way more than their share of paranoia, with tons of people just assuming that they've "always" done things with their products that, frankly, they couldn't realistically have gotten away with doing.
If Kaspersky himself wouldn't do it, they would replace him with someone who would. But chances are, Kaspersky would see it himself as a patriotic act.
You run a bug bounty program. When you set it up you talked with a bunch of lawyers and they wrote the language saying that you can't run afoul of sanctions. But you'd like an exception so you shoot an email to the lawyer for your organization. "Hey Alice, I'd like some legal advice. I know the law says we can't pay companies in Russia but could we like, you know, set up a shell company that we can route some money through?"
https://www.zdnet.com/article/log4j-chinese-regulators-suspe...
“We found zero-day, zero-click vulnerabilities, transferred all the information to Apple, and did a useful job,” Dmitry Galov, head of the Russian research center at Kaspersky Lab, told Russian news outlet RTVI. “Essentially, we reported a vulnerability to them, for which they must pay a bug bounty.”
Galov even proposed that Kaspersky donate the bounty to charity, but Apple rejected this, citing internal policies without explanation. It’s not uncommon for research firms to donate bounty payments from large companies to charity. Some perceive it as an extension of their ethical obligation, but it undeniably contributes to a positive reputation within the security community.
“Considering how much information we provided them and how proactively we did it, it is unclear why they made such a decision.”
It is because you uncovered the backdoor, stupid. They worked hard to hide it. /s
Galov’s statement is plainly wrong. The very first line in Apple’s bug bounty program terms and conditions states that awards are granted solely at their exclusive discretion.
There is no “must.”
They should be sued, and also given that such sophisticated attacks are usually the domain of state sponsors, if they dont pay they can be assured that the next one wont be reported to them.
..or maybe thats the plan.
https://blog.jetbrains.com/blog/2022/12/06/update-on-jetbrai...
https://en.wikipedia.org/wiki/Collaboration_with_Nazi_German...
https://en.wikipedia.org/wiki/Business_collaboration_with_Na...
Those from the West who don't like the truth I'm saying - I am actually Russian, know my country better than you, and I DESPISE every American who supports our regime or just ready to deal with it like with some civilised entity. Fascist dictatorship you deal with has nothing but hatred towards your state and your nation. Every dollar you pay them will come back will to you in form of terror attacks and deaths of your people, directly of through proxy conflicts.
I'm sure during WWII there were anti-Nazi Germans who felt the same for example towards IBM, who had lucrative contracts with the system of concentration camps of Third Reich.
https://news.ycombinator.com/item?id=40381708
Perhaps I’m cynical or pragmatic or simply a realist, but part of me thinks that the US and its businesses by proxy are able and willing to do business with hostile regimes to gain exposure to markets, capital, and personnel for intelligence purposes.
Wartime makes for strange bedfellows, for example, the collaboration between the US government and the Italian mafia during WW2:
https://en.wikipedia.org/wiki/Collaborations_between_the_Uni...