• Kaspersky uncovered iOS vulnerabilities in ‘Operation Triangulation’, reported to Apple, but was refused bounty payment
  • Apple’s Security Bounty Program offers rewards up to $1 million for discovering vulnerabilities to prevent them from being sold on the dark web
  • Apple’s refusal to pay Kaspersky could be due to restrictions on financial transactions with companies in sanctioned countries like Russia.
  • cbarrick@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    22 days ago

    Apple Security Bounty awards may not be paid to you if you are in any U.S. embargoed countries or on the U.S. Treasury Department’s list of Specially Designated Nationals, the U.S. Department of Commerce Denied Person’s List or Entity List, or any other restricted party lists.

    Kaspersky can whine all they want. Russia is embargoed. They’re not getting their money.

    Kaspersky is a good company doing good work in the cyber security space. Unfortunately, because of the embargo, they may have to turn to the black market to sell future exploits. Or maybe not; I’m not totally sure what kind of ethical standards they have.

      • alcoholicorn@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        22 days ago

        Apple could have tried to work with them and said something like “We’ll pay when the embargo ends”, since now Kapersky has every reason to sell their next apple exploit on the black market.

        They’ve just turned a department of people successfully working to make apple more secure into a department of people working to make it less secure.

        • mindlight@lemm.ee
          link
          fedilink
          English
          arrow-up
          1
          ·
          22 days ago

          Apple could have tried to work with them and said something like “We’ll pay when the embargo ends”

          …aaaaand that would most likely be trying to circumvent the sanctions by essentially receiving credit from Kaspersky on delivered services.

          Not saying the situation is optional, but the sanctions would be extremely toothless if it was that easy to circumvent.

          • ours@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            22 days ago

            How is holding the money until (and if) the sanctions are lifted, “circumventing”?

            However unlikely it would be, if the sanctions are lifted (maybe Russia gets a new, sane Government, calls off its invasion, stops its international shenanigans), wouldn’t it be OK to pay this company then?

  • RaoulDook@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    22 days ago

    “Apple refuses to send money to security company inside of embargoed country, to maintain compliance with USA law.”

  • Brownian Motion@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    22 days ago

    This is not really a story, is it.

    I worked for an Australian company, that was bought by an American company. Instantly we were required to do business as per American law, such as embargo’s. We lost many customers (businesses) that honestly had nothing to do with the actual reason for the embargos. For example Iran has an American embargo because of nuclear refinement, but we just wanted to sell “knives and forks” to them. Nope - they might use those forks in their refinement centrifuges… This is what happens (but also why embargos work).

    Kaspersky is Russian owned, so the hacks were discovered by Russian [whitehat] hackers. I’ll bet that Apple had no ability to do “business” with the company, even if it wanted to, since Russia is currently under embargo due to the Ukraine conflict.

    Now if Kaspersky spent time undermining it’s own failure of a government, and putting an end to its dictatorship, things would probably work out better for everyone in Russia.

    • Blackmist@feddit.uk
      link
      fedilink
      English
      arrow-up
      0
      ·
      22 days ago

      Is that the case though. You can buy a copy of Kaspersky anti virus right now if you live in the US. They have a US office. You can legally send them money.

      • exanime@lemmy.today
        link
        fedilink
        English
        arrow-up
        0
        ·
        22 days ago

        Or put the money in escrow pending resolution of the embargo … This is, I think, the easiest, most responsible solution to show good faith

        • Bakkoda@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          20 days ago

          Yeah thank you. There’s a ton of ways to “hold” the money legally so Apple can still be separated from some of its money.