Dan Underwood
banner
underwood.digital
Dan Underwood
@underwood.digital
Security Engineering @ Apple, Ex-UK Gov

The intersection of technology (device and national security), and liberal arts (public policy)
We're updating our bounty program with the top award now set at $2 million for zero-click remote exploit chains. In addition - there are increased awards for proximate wireless attacks, WebKit, and Gatekeeper

security.apple.com/blog/apple...
A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research - Apple Security Research
Today we’re announcing the next major chapter for Apple Security Bounty, featuring the industry’s highest rewards — up to $2 million and a maximum payout in excess of $5 million — expanded research categories, and a flag system for researchers to objectively demonstrate vulnerabilities and obtain accelerated awards.
security.apple.com
October 10, 2025 at 5:05 PM
Reposted by Dan Underwood
Did you know that more than half of all iPhones around the world are being used in languages other than English?

My team helps make that possible, and we're hiring! Our work is very dynamic and spans the entire localization pipeline, from internal tools to all our OSes.

jobs.apple.com/en-us/detail
Localization Software Engineer - Jobs - Careers at Apple
Apply for a Localization Software Engineer job at Apple. Read about the role and find out if it’s right for you.
jobs.apple.com
September 26, 2025 at 2:39 PM
"The iPhone 17 is probably now the most secure computing environment on the planet that is still connected to the internet,"
Apple's latest iPhone security feature just made life more difficult for spyware makers | TechCrunch
Apple launched a new security feature for iPhone 17 and iPhone Air designed to reduce the effect of memory corruption bugs, and in turn make spyware and zero-days more difficult to hack into iPhones.
techcrunch.com
September 12, 2025 at 1:08 AM
Reposted by Dan Underwood
@rmondello.com Neven got this email from Portland Public Schools that is relevant to your interests. I'll be thinking about it for a while…
September 10, 2025 at 6:33 PM
iPhone 17, iPhone Air, and iPhone 17 Pro all support
Memory Integrity Enforcement bringing a significant advancement in memory safety - including to developers as part of the Enhanced Security feature announced earlier this year at WWDC
Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
Memory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort spanning half a decade that combines the unique strengths of Apple silicon hardware with our advanced operating system security to provide industry-first, always-on memory safety protection across our devices — without compromising our best-in-class device performance. We believe Memory Integrity Enforcement represents the most significant upgrade to memory safety in the history of consumer operating systems.
security.apple.com
September 9, 2025 at 6:32 PM
With iOS 26.0, we're introducing support for Wi-Fi Aware via AccessorySetupKit - this makes it easy for users to connect to and set up your accessories securely, and build peer to peer connectivity experiences with DeviceDiscoveryUI!

https://developer.apple.com/videos/play/wwdc2025/228

#wwdc25
Supercharge device connectivity with Wi-Fi Aware - WWDC25 - Videos - Apple Developer
Learn how to create peer-to-peer network connections with Wi-Fi Aware. We'll also cover how to share videos in real time, transfer large...
developer.apple.com
June 10, 2025 at 5:59 PM
We've launched support for developers to build their own security hardened extensions, distribute apps using Pointer Authentication, and access a range of other security mitigations: https://developer.apple.com/documentation/xcode/enabling-enhanced-security-for-your-app

#wwdc25
Enabling enhanced security for your app | Apple Developer Documentation
Detect out-of-bounds memory access, use of freed memory, and other potential vulnerabilities.
developer.apple.com
June 10, 2025 at 1:41 AM
This is a hugely important update for CryptoKit - make sure you check out the session to learn more about what you do (and don’t) need to do as an App Developer to protect against quantum computers.
🆕⚛️🔐 Starting with iOS 26, CryptoKit gets support for quantum-secure cryptography with algorithms such as ML-KEM, ML-DSA and HPKE with X-Wing:
developer.apple.com/documentatio...
Apple CryptoKit | Apple Developer Documentation
Perform cryptographic operations securely and efficiently.
developer.apple.com
June 9, 2025 at 8:25 PM
Reposted by Dan Underwood
New post on the Swift blog: we re-wrote the Password Monitoring service for Apple Passwords in Swift and saw huge improvements in memory use and throughput. Some of the details here still blow my mind; it's a fun read. https://www.swift.org/blog/swift-at-apple-migrating-the-password-monitoring-servi
Swift at Apple: migrating the Password Monitoring service from Java
Swift is heavily used in production for building cloud services at Apple, with incredible results. Last year, the Password Monitoring service was rewritten in Swift, handling multiple billions of requests per day from devices all over the world. In comparison with the previous Java service, the updated backend delivers a 40% increase in performance, along with improved scalability, security, and availability.
www.swift.org
June 3, 2025 at 1:58 PM
Manta rays off the coast of Hawaii!
May 16, 2025 at 4:56 PM
Picked up my Close Your Rings Day pin! (Happy 10th birthday to Apple Watch)
April 24, 2025 at 5:32 PM
Reposted by Dan Underwood
👋 from the Swift team, now on Bluesky!
February 21, 2025 at 5:46 PM
Reposted by Dan Underwood
Decided to do the #promosky as I’m looking for more friends (MDNI), especially people to play games with 🙂

🎮 Zelda, Kirby, Skyrim, No Man’s Sky, Stellaris, Civilization

📺 Dragon Prince, Severance, Foundation

📖 Arc of a Scythe, Mistborn

🎨 Used to write so artists are also welcome (🚫 NFT, genAI)
January 28, 2025 at 10:37 PM
Maybe a catastrophic natural disaster isn't the best way to advertise your features in an app for managing your smart devices LG
January 8, 2025 at 10:49 PM
CISA has launched guidance on protecting mobile devices given recent threats against telecommunications infrastructure - including the benefit of Lockdown Mode, Private Relay, and the Passwords app
www.cisa.gov
December 18, 2024 at 6:18 PM
Do you want to work on designing the security of the latest Apple products and features that will be used by over a billion users? Our team is hiring for engineers to help provide security leadership!

https://jobs.apple.com/en-us/details/200582891/security-reviewer-secure-design
Security Reviewer, Secure Design - Careers at Apple
Apply for a Security Reviewer, Secure Design job at Apple. Read about the role and find out if it’s right for you.
jobs.apple.com
December 11, 2024 at 9:33 PM
My colleagues in the Cryptographic Engineering team within SEAR are hiring in Paris! They're an incredibly talented team working on challenging real world problems - if you're interested please do consider applying

https://jobs.apple.com/en-us/details/200578463/cryptography-engineer-expert
November 26, 2024 at 7:43 PM
Despite increasing legislation, and a low minimum bar for compliance, it’s incredible (albeit not surprising) how many device manufacturers and software vendors still struggle to provide that bare minimum to allow researchers to report security vulnerabilities
Here's our annual report into the state of vulnerability disclosure in the IoT space - a good window into how poor product security is overall:
We're pleased to publish our annual report into the State of Vulnerability Disclosure in Consumer IoT, on behalf of the IoT Security Foundation. The creation of the report was kindly supported by @hacker0x01.bsky.social . More details in our blog here: copperhorse.co.uk/vulnerabilit...
November 25, 2024 at 5:09 PM
Reposted by Dan Underwood
Just look at that Interop 2024 score…
wpt.fyi/interop-2024
November 22, 2024 at 6:28 PM
Need to improve memory safety in existing unsafe C code? My colleagues have published a patch for clang that introduces support for -f-bounds-safety!

https://github.com/swiftlang/llvm-project/pull/9665
November 22, 2024 at 5:17 AM
November 20, 2024 at 7:04 PM
As expected, the first episode of Silo season two was superb.
November 17, 2024 at 5:11 AM
Proud of my colleagues who have driven the work on this - we just launched a huge amount of security material for PCC (Private Cloud Compute), including a new security guide, Virtual Research Environment, and source code

https://security.apple.com/blog/pcc-security-research/
October 24, 2024 at 5:37 PM