Apple has started to impose new restrictions on its “bug bounty” program, in which it rewards researchers who identify security vulnerabilities. The company stated that the review processes have become difficult, especially due to the recent increase in notifications prepared with artificial intelligence tools, and set an upper limit on the number of applications that can be sent to the program. Participants who reach the limit set under the new rules will have to request special approval in order to send additional notifications.
The recent proliferation of productive artificial intelligence and automatic code analysis tools has made it possible to detect potential security vulnerabilities in software in a much shorter time. However, this development has created a different problem for companies managing bug bounty programs. While evaluating a large number of reports generated by artificial intelligence significantly increases the workload of security teams, it may cause more critical findings revealed by experienced security researchers to be left behind in the review processes.
Apple will apply quotas and waiting periods to applications
According to information confirmed by the Financial Times, Apple has implemented two new rules for notifications made through the company’s internal security portal in order to reduce this density. The first of these is the upper limit on the number of applications that can be sent within a certain period, while the second is a 30-day waiting period for participants who reach the limit. After this period, notification may be made again. Despite this, researchers who want to submit more applications will be able to apply for special permission from Apple.
Apple states that the main purpose of these changes is to make evaluation processes more efficient. The company does not directly oppose the use of artificial intelligence-supported tools in security research. Instead, it aims to reduce the density created by a large number of notifications of similar nature, which strain the capacity of the investigation teams. Thus, it is aimed to evaluate truly unique and high-impact security vulnerabilities more quickly.
Apple’s decision is not the only example in the technology industry. Google also made similar changes to its bug bounty program in the first months of the year. The company started to give higher rewards to vulnerabilities that are more complex to solve, especially compared to low-risk software bugs that artificial intelligence can easily detect. Thus, researchers are encouraged to focus on more qualified and high-impact security problems.
The increasingly widespread use of generative artificial intelligence tools in software development and security research is also reshaping the functioning of bug bounty programs. Although more errors can be detected thanks to automation, the majority of them are of low importance or consist of very similar reports, which can make the review process difficult. For this reason, technology companies are working on new balance models that will allow them to both benefit from the efficiency provided by artificial intelligence and allow security teams to devote their time to more critical findings.
Apple’s application quota and waiting period also stand out as current examples of this approach. Rather than completely limiting AI-supported security research, the regulation aims to maintain the sustainability of the program and use evaluation resources more efficiently. It seems likely that this approach will bring about similar changes in the bug bounty programs of other major technology companies in the coming period.
Join Channel