> If a researcher reports a qualifying vulnerability already found internally by Microsoft, a payment will be made to the first finder at a maximum of 10% of the highest amount they could’ve received (example: $1,500 for a RCE in Edge, $25,000 for RCE in Hyper-V) Wow. I guess this kind of functions as hush money? To make sure they don't reveal the issue before MS patches it. But still, this seems like a good move.
It also encourages researchers to do research, by making it less likely they'll do a pile of research only to be told "sorry, we already found this, you get nothing". Right now, pursuing a bounty is a risky proposition; this makes it less risky.
Announcing the Windows Bounty Program
11–20 of 121 posts
Re: Announcing the Windows Bounty Program
#12It's good to see the bounties increasing to the range you could get on the open market.
Re: Announcing the Windows Bounty Program
#13I don't think this was a big find but I remember I was still somewhat underwhelmed by the response.
Re: Announcing the Windows Bounty Program
#14Re: Announcing the Windows Bounty Program
#15Re: Announcing the Windows Bounty Program
#16Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…
Just like Apple, yet no one complains about them.
Re: Announcing the Windows Bounty Program
#17Re: Announcing the Windows Bounty Program
#18Re: Announcing the Windows Bounty Program
#19Re: Announcing the Windows Bounty Program
#20Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…
In this setting this is relevant even if funny.
I'll still downvote you for the same comment elsewhere.
And I mostly defend MS for enabling telemetry by default but I don't defend how absurdly hard they have made it to disable it.