77°F
weather icon Mostly Cloudy

Apple to start awarding cash for information related to major security gaps

Apple announced a security bounty program at the cybersecurity convention Black Hat in Las Vegas.

“We’ve had great help from researchers like you improving iOS security all along,” Apple’s head of security, Ivan Krstić, told a crowd of cybersecurity and information technology professionals on Thursday. “It’s getting increasingly more difficult to find some of the most critical gaps in security vulnerabilities, so the apple security bounty program is going to reward researchers who actually share critical vulnerabilities with Apple.”

Apple will pay between $25,000 and $200,000 for that information, depending on the type of security gap discovered. The company will also provide public recognition, unless asked otherwise.

The announcement of the bug bounty program was greeted by a roar of applause from attendees at Mandalay Bay.

The announcement came after Krstić gave a presentation on Apple’s data protection mechanisms, laying out in highly technical detail how the coming iOS 10 will be safer than previous iOS security.

“There were very few surprises,” said a Romanian information security professional, who did not want his name or the name of his company to be recorded — like most at Black Hat.

A question and answer session after the presentation was more of a charade, as Krstić was highly evasive.

In reponse to an audience question about the most persistent security challenges at Apple, Krstić responded tongue and cheek with, “Tough audience questions, thank you,” and moved on to the next question.

An attendee from California, who works for a mobile security company, said he was satisfied with the presenation.

“He’s given the most internal information that’s ever come out of Apple, so I’ll give it to him.”

Contact Nicole Raz at nraz@reviewjournal.com or 702-380-4512. Find @JournalistNikki on Twitter.

Don't miss the big stories. Like us on Facebook.
THE LATEST