Live data from Hacker News

Announcing the Windows Bounty Program

blogs.technet.microsoft.com

51–60 of 121 posts

Re: Announcing the Windows Bounty Program

#51
post #21

Earlier quoted context omitted.

Because you can disable it. No?

Yes, with some effort: https://github.com/drduh/macOS-Security-and-Privacy-Guide You probably could with the same amount of effort for Windows, but at least Windows makes it more clear that it is happening.

As far as telemetry goes, there is a simple on or off checkbox in the Security and Privacy control panel.

Re: Announcing the Windows Bounty Program

#52
post #22
post #14

With the increasing number and value of these bounty programs, how viable is a career in professional free lance security bug hunting?

It's doable, but if you're good enough to somewhat routinely find bounty-worthy bugs but not spooky good at it, it's not the most lucrative way to put bug-hunting skills to work.

And even if you're "spooky good", you only really need to be spooky good for six - 12 months before something like Google Project Zero will pick you up to (in all likelihood) pay you far more anyway.

Re: Announcing the Windows Bounty Program

#53
post #22
post #14

With the increasing number and value of these bounty programs, how viable is a career in professional free lance security bug hunting?

It's doable, but if you're good enough to somewhat routinely find bounty-worthy bugs but not spooky good at it, it's not the most lucrative way to put bug-hunting skills to work.

[deleted]

Re: Announcing the Windows Bounty Program

#54
post #40

Earlier quoted context omitted.

Similar behaviors likely exists in OSS they are just called different things. For example, ACME Co uses open source project XYZ. Acme Co uses resources to make sure that XYZ is secure and bug free. Acme Co is then incentivized to contribute any changes they have found, because they would like to stay in sync with the master branch of XYZ so they can get any updates the community pushes. In the case of OSS, the pool o…

That's how the theory goes, but how often does this really happen though? See: OpenSSL

Well, the kernel, right? Many many major corporate contributors. Kind of the opposite of OpenSSL, I guess, which everyone uses and no one seems to maintain.

Re: Announcing the Windows Bounty Program

#55
post #31

Earlier quoted context omitted.

My understanding is that the grey market for exploits is way more lucrative than the bug bounty programs.

It is in the very specific case that: (1) You are effective at finding the specific kinds of vulnerabilities that the grey market actually purchases . People have _very_ weird ideas about what the grey market wants. In reality, if your bug isn't a drive-by clientside in a popular client, it is unlikely that anyone wants to buy it. (2) You are willing to get your hands dirty with shady purchasers. If you're talented,…

> In reality, if your bug isn't a drive-by clientside in a popular client, it is unlikely that anyone wants to buy it.

That sounds like black market buyers (maybe we disagree on where the "gray" line is). Governments are very interested in bugs that allow pivoting and lateral movement.

Re: Announcing the Windows Bounty Program

#56

Earlier quoted context omitted.

A company would never lie. Especially Microsoft.

My sarcasm detector is acting a little wonky - there is no real reason for Microsoft to lie about this, it isn't exactly breaking the bank for them.

Microsoft is composed of people. The people we worry about here, are the ones who might be incentivised to discover exploits before an outsider. They would have an incentive to back-date their work, or their subordinate's work.

Re: Announcing the Windows Bounty Program

#57
post #55
post #31

Earlier quoted context omitted.

It is in the very specific case that: (1) You are effective at finding the specific kinds of vulnerabilities that the grey market actually purchases . People have _very_ weird ideas about what the grey market wants. In reality, if your bug isn't a drive-by clientside in a popular client, it is unlikely that anyone wants to buy it. (2) You are willing to get your hands dirty with shady purchasers. If you're talented,…

> In reality, if your bug isn't a drive-by clientside in a popular client, it is unlikely that anyone wants to buy it. That sounds like black market buyers (maybe we disagree on where the "gray" line is). Governments are very interested in bugs that allow pivoting and lateral movement.

How would one, hypothetically, go about selling exploits/bugs to governments as a freelancer?

Re: Announcing the Windows Bounty Program

#58
post #7

Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…

Don't know why you got downvoted for this on a hacker forum.

From the site guidelines (https://news.ycombinator.com/newsguidelines.html):

> Please avoid introducing classic flamewar topics unless you have something genuinely new to say about them.

For the record, I'm not the one who downvoted the parent for an honest question.

Re: Announcing the Windows Bounty Program

#59
Overall, I feel this is a good move by Microsoft. Admittedly from their side, they won't (or cannot) cover all security holes from their system. Asking help from external sources and rewarding them appropriately is also good, allowing them to patch their system. In turn, end users will (hopefully) get an OS that is secure. Win for everyone. Way to go MS!
Post reply on HN