Announcing the Windows Bounty Program
blogs.technet.microsoft.com
Announcing the Windows Bounty Program
1–10 of 121 posts
Re: Announcing the Windows Bounty Program
#2Wow. I guess this kind of functions as hush money? To make sure they don't reveal the issue before MS patches it. But still, this seems like a good move.
Re: Announcing the Windows Bounty Program
#3Re: Announcing the Windows Bounty Program
#4http://tvtropes.org/pmwiki/pmwiki.php/Main/CutLexLuthorAChec...
Re: Announcing the Windows Bounty Program
#5Re: Announcing the Windows Bounty Program
#6It's good to see the bounties increasing to the range you could get on the open market.
Re: Announcing the Windows Bounty Program
#7>Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty
Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?).
Please send me further instructions on how I can claim my 250k.
Also: Why is there nothing for Server 2016?
Re: Announcing the Windows Bounty Program
#8> If a researcher reports a qualifying vulnerability already found internally by Microsoft, a payment will be made to the first finder at a maximum of 10% of the highest amount they could’ve received (example: $1,500 for a RCE in Edge, $25,000 for RCE in Hyper-V) Wow. I guess this kind of functions as hush money? To make sure they don't reveal the issue before MS patches it. But still, this seems like a good move.
Re: Announcing the Windows Bounty Program
#9> If a researcher reports a qualifying vulnerability already found internally by Microsoft, a payment will be made to the first finder at a maximum of 10% of the highest amount they could’ve received (example: $1,500 for a RCE in Edge, $25,000 for RCE in Hyper-V) Wow. I guess this kind of functions as hush money? To make sure they don't reveal the issue before MS patches it. But still, this seems like a good move.
Re: Announcing the Windows Bounty Program
#10Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…