Apple to hand out limited-edition iPhones among 1337 h4x0rs because it wants more bug-hunters
- Reference: 1595492825
- News link: https://www.theregister.co.uk/2020/07/23/apple_iphone_security_research_device/
- Source link:
The new "Security Research Device" (SRD) is a full iPhone that adds shell access so that security researchers can give it a thorough going-over.
As Apple [1]explains : "This program is designed to help improve security for all iOS users, bring more researchers to iPhone, and improve efficiency for those who already work on iOS security."
The company says the SRD offers "unique code execution and containment policies" to help researchers along.
To get your hands on the device, Apple says you'll need "a proven track record of success in finding security issues on Apple platforms, or other modern operating systems and platforms." Apple will also conduct its own application process and says that not all applicants will be offered a device.
Those that do will enjoy access for a year at a time, but must keep the SRD on-premises, use it only for research and ensure it is only used by named personnel that Apple has approved.
If working with the device yields a bug, users "must promptly report it to Apple and, if the bug is in third-party code, to the appropriate third party." Apple will then set a date for disclosure – usually the date on which it publishes a patch.
News of the SRD programme suggests Apple recognises it needs a bigger security testing ecosystem and that for a wider programme to be effective testers will need deeper access to iPhones' workings than is possible with third-party tools. ®
Get our [2]Tech Resources
[1] https://developer.apple.com/programs/security-research-device/
[2] https://whitepapers.theregister.com/
We know where you live
Given Apple's historical reticence when it comes to bug submissions, this is presumably just a ruse to find out where the people are before sending round the AET (Apple Enforcement Team)!
If they want people to work at testing and improving their product, why don't they employ people to work at testing and improving their product?
Cognitive Bias?
I’d bet that Apple already employ many people for product security purposes but any employee is open to the many cognitive biases just because they are an employee.
Handing low level access to “independents” is a way of reducing the role of cognitive bias in security assessments, basically getting input from another set of eyes.
An obvious weakness in this approach is that you have to trust the people (you give low level access to) that they will report any interesting findings and not keep it to themselves, eg would the FBI report they had found a useful backdoor?
Do it yourself
> The new "Security Research Device" (SRD) is a full iPhone that adds shell access so that security researchers can give it a thorough going-over.
Surely the sort of "security researcher" who was any good at finding _real_ exploits would be able to gain shell access, without any help.
That has to be a Good Thing (TM)
Good on Apple for this initiative that will undoubtedly improve the security of their products.
The FBI must be seething. On the other hand, the FBI can very well enroll in this program, either openly or covertly, and it probably will.
I wonder how Apple is going to manage that ?