Skip to main content

Google lead says he’s ‘disappointed’ with Apple’s new iPhone security program

Apple’s new hacker-friendly iPhones offer security researchers unrestricted access to devices so that they can easily hunt down vulnerabilities and bugs. But Ben Hawkes, technical lead at Project Zero, a team at Google tasked with discovering security flaws, says he’s “pretty disappointed” with Apple’s latest security program.

Hawkes, in a Twitter thread, said that its team won’t be able to take advantage of Apple’s “Security Research Device” (SRD) iPhones since it appears to exclude security groups that have a policy to publish their findings in three months.

Every time a security researcher discovers a vulnerability, they offer the company a period of time to patch it before it is publicly reported. Project Zero, like many security researchers, has a 90-day policy. However, Apple has kept the control of the timeline to itself and developers who sign up for this new iPhone security program have to agree that they can’t disclose the issues they find until Apple allows them to.

“If you report a vulnerability affecting Apple products, Apple will provide you with a publication date (usually the date on which Apple releases the update to resolve the issue). Apple will work in good faith to resolve each vulnerability as soon as practical. Until the publication date, you cannot discuss the vulnerability with others,” notes the SRD program’s sign-up page.

Project Zero is one of the most widely regarded research groups, and since early 2015, it has reported over 350 security vulnerabilities to Apple.

“We’ll continue to research Apple platforms and provide Apple with all of our findings because we think that’s the right thing to do for user security. But I’ll confess, I’m pretty disappointed,” Hawkes added in a tweet.

Apple’s Security Research Device program has been long overdue and was first mentioned last year at the Black Hat security conference by the company’s head of security, Ivan Krstic. Over the past year or two, iPhone’s security has been found lax and compromised on multiple occasions. The new program ensures eligible developers don’t have to go out of their way to hack into iPhones for research purposes and allows them to access the device’s core components to unearth any potential vulnerabilities.

Security researchers can now sign up to request an SRD on a 12-month renewable basis.

Editors' Recommendations

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
Apple may face ‘severe’ iPhone 15 shortage over production issue, report says
The Apple logo on the iPhone 14 Pro Max.

Hoping to get your hands on an iPhone 15 Pro or iPhone 15 Pro Max when the new phones come out in the fall? Well, you may be in for a wait.

Apple is experiencing production issues caused by a new manufacturing process designed to significantly reduce the size of the bezel around the display, according to a report from The Information on Thursday.

Read more
An iPhone just sold for a crazy amount at auction
An original, unsealed iPhone.

An original, still-boxed iPhone. LCG Auctions

Rare iPhones have been going under the hammer for some large sums in recent months, and the latest auction to feature one of the first Apple handsets has just smashed the record for such a device.

Read more
I’ll be furious if the iPhone 15 Pro doesn’t get this one feature
A black iPhone 14 Pro lying on a table.

It’s peak summer season, but that also means we’re getting closer to Apple’s fall event in September. This is typically when we expect the next generation of iPhones and Apple Watches.

This year, we’re expecting the iPhone 15 lineup, which should include the standard iPhone 15, iPhone 15 Plus, iPhone 15 Pro, and iPhone 15 Pro Max. On top of that, it’s safe to say that we should also see the Apple Watch Series 9, but whether we’re getting a second-generation Apple Watch Ultra is still up in the air. And new AirPods? Who knows! Regardless, it will be exciting and jam-packed with a ton of new products.

Read more