large image

Trusted Reviews is supported by its audience. If you purchase through links on our site, we may earn a commission. Learn more.

Apple is making hacker-friendly iPhones for security researchers

Apple has taken a couple of giant strides in making itself more open to security researchers. Not only has it opened up a new set of new bug bounties, but it has gone as far as to create a more hacker-friendly iPhone.

Obviously, the latter isn’t available to everyone and is intended for a small selection of trusted security researchers who have proven their worth by spotting exploits in locked-down Apple handsets before. The custom handsets will give this handful of owners a “root” shell as the default and will also have debugging privileges, Wired reports. Together, this should make finding vulnerabilities far easier, hopefully ensuring that fewer exploits make it out into the wild.

Related: Best free antivirus software

We want to attract some of the exceptional researchers who have thus far been focusing their time on other platforms,” Ivan Krstic, head of security engineering and architecture at Apple, told an audience at the Black Hat Security Conference. “Today many of them tell us they look at our platform and they want to do research but the bar is just too high.”

As these hacker-friendly iPhones are only being provided to a limited number of security researchers, another change is potentially more significant. Apple’s bug bounty programme, itself only opened to select researchers three years ago, is to be expanded to macOS and other Apple operating systems. 

Related: Best iPhone

More importantly, it will now be open to all, and sounds pretty generous with its rewards. Apple will pay anywhere from $100,000 for a lock screen bypass, all the way up to $1 million for remote attacks that can give a hacker total control of a computer without the owner doing anything. This reward gets a 50% bonus for exploits found when code is in beta, as the company is keen to snuff out bugs before new software reaches the majority of users.

This is a bold, but welcome move by the company. And by opening up the rewards program to all, some exploits that may have previously been sold on the black market might just end up being reported to Apple instead.

Is this the right approach from Apple? Let us know what you think on Twitter: @TrustedReviews.

Why trust our journalism?

Founded in 2004, Trusted Reviews exists to give our readers thorough, unbiased and independent advice on what to buy.

Today, we have millions of users a month from around the world, and assess more than 1,000 products a year.

author icon

Editorial independence

Editorial independence means being able to give an unbiased verdict about a product or company, with the avoidance of conflicts of interest. To ensure this is possible, every member of the editorial staff follows a clear code of conduct.

author icon

Professional conduct

We also expect our journalists to follow clear ethical standards in their work. Our staff members must strive for honesty and accuracy in everything they do. We follow the IPSO Editors’ code of practice to underpin these standards.