Live data from Hacker News

Announcing the Windows Bounty Program

blogs.technet.microsoft.com

71–80 of 121 posts

Re: Announcing the Windows Bounty Program

#71

Earlier quoted context omitted.

My sarcasm detector is acting a little wonky - there is no real reason for Microsoft to lie about this, it isn't exactly breaking the bank for them.

Microsoft is composed of people. The people we worry about here, are the ones who might be incentivised to discover exploits before an outsider. They would have an incentive to back-date their work, or their subordinate's work.

They're not stupid. If they cared so much more about pinching every last dollar than about security, they wouldn't have launched the bug bounty program at all.

BTW, as others have mentioned, this is strictly better than the policy of other bug bounties until now, which is "We already found this, so you get nothing"

Re: Announcing the Windows Bounty Program

#72
post #33
post #5

Its about time. I hope the incentives stay strong enough, and dont require hoops to jump through. otherwise the gray/blackmarkets could out-bid the bounty and cut the red tape to incentivise their own acquisition of the exploits in question.

Microsoft has been doing this for a long time; they're one of the pioneers of bounty programs.

Much respect to Microsoft and their new found love of bounty programs, but pioneer is a bit of a stretch - they launched their first bounty program in 2013, well after third party bug bug buyers like ZDI, and even after BugCrowd and other bug bounty as a service companies launched.

Re: Announcing the Windows Bounty Program

#74

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

To begin with, some OSS doesn't even know how to treat people who report bugs.

Re: Announcing the Windows Bounty Program

#75
post #7

Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…

I am mostly surprised by the absence of server 2016 as well

Re: Announcing the Windows Bounty Program

#76

Earlier quoted context omitted.

I've noticed a spike recently in bug bounties going to people who using a combination of fuzzing and code analysis tools. It may be that we're moving to a point where bug-hunters' ability to use sophisticated tools will be what earns them the most money, rather than their ability to eyeball code and see the bugs. Speaking just for myself: A few years ago I was saying "I should really set aside a few months to learn t…

There was this thing called "Hostile Subdomain Takeover" where a company would point a subdomain to a particular SaaS product (Say Zendesk), sometime later, they would cancel their subscription but not change the A record. Someone could then go and register a new Zendesk account (If the service doesn't require proof of ownership of domain), and say that they want to use the same subdomain. Now they have a Zendesk acc…

This is definitely still a thing.

Re: Announcing the Windows Bounty Program

#77

> Bounty payouts will range from $500 USD to $250,000 USD I will need some $25K in cash upfront to be convinced to start using Windows 10.

Not complaining, but technical question: how did that get a downvote when it was 3 minutes old? I have a 5 minute delay configured!

I saw "0 points"; then refreshed browser; still said "3 minutes ago". Rubbed eyes, checked profile settings: "delay 5" still configured.

"delay" is a profile parameter which specifies the number of minutes which elapse from when you initially create a comment to when it becomes published. This gives you a chance to edit or retract your comment before it is subject to public criticism. I've never before seen a voting or reply event occur on a comment prior to the expiry of the delay.

(Maybe some clocks are way out of sync between some distributed servers, so 3 minutes old here means 5 minutes old there? Or maybe NTP suddenly stepped a lagging wall clock forward by a couple of minutes?)

To the topic: how much $ can I get out of this? ;)

Re: Announcing the Windows Bounty Program

#80
post #14

With the increasing number and value of these bounty programs, how viable is a career in professional free lance security bug hunting?

My understanding is that the grey market for exploits is way more lucrative than the bug bounty programs.

I've looked at dartknet markets. Quite often, there are vulnerabilities advertised for thousands or tens of thousands of dollars. And quite often, they claim to be an exclusive sale (ie, they'll take it down after one purchase).

And quite often, they will be relisted for months at a time. I'm not at all saying there's no market - we clearly know that a remote code exec on a common server will sell well.

Things like "Microsoft Word Exploit" seem a lot more like Duff beer - I'm often hearing how much they are "for sale" for a fortune but I'm not convinced people are getting the significant sums people refer to on a reliable basis.

Post reply on HN