Interviews reveal a slow start for Apple's bug bounty program as some feel financial rewards are too small or reporting bugs would prevent research
In August 2016, Apple's head of security Ivan Krstic stole the show at one of the biggest security conferences in the world with an unexpected announcement.
Context & Ripple Effects
When Ivan Krstic announced the program at a major security conference in August 2016, analysts called it a good start — but noted it covered only high-quality exploits in a few key areas of iOS and iCloud, with Apple promising it would grow over time. A year later, Motherboard's interviews find that growth hasn't materialized: participation is slow, and researchers say the rewards are too small or that handing bugs to Apple would end their research value.
The friction documented here proved durable rather than transitional. Four years on, researchers were still describing a program undermined by Apple's insular culture, payment confusion, and long fix delays (Washington Post reporting) — and Apple itself later disclosed roughly $20M in total payouts since reopening the bounty in December 2019, including twenty $100K+ rewards (9to5Mac).
First-order effects
- Researchers weighing whether to report an iOS or iCloud flaw to Apple face a direct trade-off between a payout they consider too small and the resale or research value of withholding it — which suppresses submissions to Apple right now.
Second-order effects
- Low participation pushes high-value iOS exploits toward gray-market buyers instead of Apple's patch pipeline, raising effective exploit-availability risk for iPhone and iCloud users while rivals' more generous programs become the benchmark researchers compare against.
Third-order effects
- If the pattern holds, platform vendors converge on invitation-style, tightly scoped bounty programs where the vendor controls who participates and which flaws qualify — trading open researcher goodwill for controlled disclosure, with regulators and security firms eventually scrutinizing whether such gating leaves users exposed.
The trend: Corporate bug bounties are evolving from open cash-for-bugs offers into gated, vendor-controlled pipelines whose scope and reward structure determine whether researchers sell to the company or around it.