• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechThe Mobile Executive

Apple Exposed – the Value of Bug Bounties

By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
July 24, 2016, 12:50 PM ET
Photograph by Bloomberg via Getty Images

A version of this post originally appeared in the Cyber Saturday edition of Data Sheet, Coins2Day ’sdaily tech newsletter.

You know how they say most crime victims know their attacker? Two incidents this week suggest this holds true in the case of cyber-crime too.

The culprit in both cases was none other than Apple — not some sketchy Android app created who-knows-where. It turns out the iPhone’s software contains a “very high severity issue” that could let hackers steal passwords with nothing more than a text message. Meanwhile, a second vulnerability allows snoops to exploit FaceTime and listen in on your calls.

Apple has issued patches for both problems but this won’t help unless you, and this is probably worth shouting: UPDATE YOUR SOFTWARE. After all, those update notifications on your phone aren’t there for nothing.

The Apple incidents are also a reminder of the value of bug bounty programs that companies use to pay people to expose their software flaws. It might cost firms a tad of money and embarrassment, but it’s infinitely better than letting bad guys find the flaws first. If you have doubts, take it from Google’s former head of spam, who brought up bug bounties in the context of a clever phone scam:

Bug bounties are a good idea, part 927: https://t.co/32VMIvrH9x

— Matt Cutts (@mattcutts) July 22, 2016

Ironically, Apple is alone among major tech companies in not offering a bug bounty program. While everyone from Uber to the Pentagon is offering bounties these days, Apple remains a hold-out. (The FaceTime and message vulnerabilities were reported instead by employees at Cisco and SalesForce – their respective warnings are here and here).

This week’s news may increase the pressure on Apple to finally create a bounty program of its own. But as the New York Timesreported in March, the company might have a hard time doing so:

Some security researchers said no bounty Apple could offer now would match the reward they could expect from the underground market.Apple has waited so long that the black market for its flaws has become extremely lucrative, perhaps making any bug bounty program the company would create seem late to the game.

Finally, a bit of personal news: I’m thrilled to say I’m formally teaming up with my colleague Robert Hackett to build up Coins2Day’s cyber-security coverage, including on our Cyber Saturday newsletter.

Enjoy the rest of your weekend — and download those updates!

About the Author
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Coins2Day, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.