/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Interviews reveal a slow start for Apple's bug bounty program as some feel financial rewards are too small or reporting bugs would prevent research

In August 2016, Apple's head of security Ivan Krstic stole the show at one of the biggest security conferences in the world with an unexpected announcement.

Motherboard Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

When Ivan Krstic announced the program at a major security conference in August 2016, analysts called it a good start — but noted it covered only high-quality exploits in a few key areas of iOS and iCloud, with Apple promising it would grow over time. A year later, Motherboard's interviews find that growth hasn't materialized: participation is slow, and researchers say the rewards are too small or that handing bugs to Apple would end their research value.

The friction documented here proved durable rather than transitional. Four years on, researchers were still describing a program undermined by Apple's insular culture, payment confusion, and long fix delays (Washington Post reporting) — and Apple itself later disclosed roughly $20M in total payouts since reopening the bounty in December 2019, including twenty $100K+ rewards (9to5Mac).

First-order effects

  • Researchers weighing whether to report an iOS or iCloud flaw to Apple face a direct trade-off between a payout they consider too small and the resale or research value of withholding it — which suppresses submissions to Apple right now.

Second-order effects

  • Low participation pushes high-value iOS exploits toward gray-market buyers instead of Apple's patch pipeline, raising effective exploit-availability risk for iPhone and iCloud users while rivals' more generous programs become the benchmark researchers compare against.

Third-order effects

  • If the pattern holds, platform vendors converge on invitation-style, tightly scoped bounty programs where the vendor controls who participates and which flaws qualify — trading open researcher goodwill for controlled disclosure, with regulators and security firms eventually scrutinizing whether such gating leaves users exposed.

The trend: Corporate bug bounties are evolving from open cash-for-bugs offers into gated, vendor-controlled pipelines whose scope and reward structure determine whether researchers sell to the company or around it.