Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Apple has a bug bounty program, yes? Are they paying Google for these?


Project Zero does not accept bounties. They generally ask for the money to be donated.


Makes sense. The bug bounty is meaningful money to an individual but it's just a pittance to Google.


I'd assume it also helps avoid the perception of a conflict of interest.


Apple's program has a few very specific classes of bugs that they pay out bounties for: these bugs probably don't qualify.


Probably not. I think that most of those bounties can only be redeemed when you sign an NDA.


Who requires an NDA? I don't believe Google does: https://www.google.com/about/appsecurity/reward-program/

(Disclosure: I work for Google)


I meant the NDA from the party where the bug is reported, Apple in this case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: