Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Late reply: They just paid for 28 more issues, running total is now $288,500.

https://twitter.com/samwcyo/status/1314310787243167744



$288k and Apple has only paid them for roughly half of the vulnerabilities. They expect the payout to exceed $500k.

Well worth it for Apple and a decent payday for 3 months of spelunking.


Gross pay (not including employee benefits and before payroll tax deduction), split among a team of 5 people, unclear if they were working on this one project full time, and amortized over other months with less renumeration. It may not be better amortized pay than a regular software job.


Especially considering that the authors are some of the best bug bounty hunters in the world. $500 an hour is a fairly normal rate for a top security consultant, as far as I'm aware.


Absolutely wonderful news! Congrats to everyone involved.

Kudos to Apple for following through.

I hope this sets the standard for companies going forward.


Apple are already behind the standard and times on this. Apple aren’t leading here, they are reluctantly catching up and doing the minimum they need.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: