Comment by ngneer

2 years ago

How is this different than a bug bounty?

Well they are providing a dedicated environment from which to attack their infrastructure. But also they have a section called “ Apple Security Bounty for Private Cloud Compute” in the linked article so this is a bug bounty + additional goodies to help you test their security.

There is a bug bounty too, but the ability to run one the same infrastructure, OS, models locally is big.

Similar, but a lot of documentation is provided, source code for cross reference, and a VM based research environment instead of applying for a physical security research device.