Live data from Hacker News

Announcing the Windows Bounty Program

blogs.technet.microsoft.com

81–90 of 121 posts

Re: Announcing the Windows Bounty Program

#81

Bounties for Edge? Isn't it less than 5% in browser market share? I like the fact they're offering a bounty program, I'm just surprised Edge was included I guess.

Edge is Microsoft's primary browser. One of the selling points of a browser is security. From their perspective it makes total sense to make sure it's secure.

Re: Announcing the Windows Bounty Program

#83
post #72
post #33

Earlier quoted context omitted.

Microsoft has been doing this for a long time; they're one of the pioneers of bounty programs.

Much respect to Microsoft and their new found love of bounty programs, but pioneer is a bit of a stretch - they launched their first bounty program in 2013, well after third party bug bug buyers like ZDI, and even after BugCrowd and other bug bounty as a service companies launched.

I feel like Katie Moussouris switched from SDL to bug bounty stuff at MSFT in like 2011, but I may have the dates fuzzed up a little bit.

Really the only point I want to make is that this is not Microsoft announcing their first bounty program.

Re: Announcing the Windows Bounty Program

#84

Bounties for Edge? Isn't it less than 5% in browser market share? I like the fact they're offering a bounty program, I'm just surprised Edge was included I guess.

Edge is also behind webviews in UWP apps, also WWAHost [0] apps and Store-delivered PWAs [1] will run in Edge

[0]: https://blogs.windows.com/buildingapps/2015/07/06/project-we...

[1]: https://developer.microsoft.com/en-us/windows/projects/event...

Re: Announcing the Windows Bounty Program

#85

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

"OSS can't afford to pay people"

You don't really understand how open source works, do you? cough shill cough.

The source is free but you are also free to build consultancy etc on the back of it.

"I wonder if there will exist ... yield better (less buggy) software vs OSS." - RLY?

Re: Announcing the Windows Bounty Program

#86

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

To begin with, some OSS doesn't even know how to treat people who report bugs.

Citation needed

Re: Announcing the Windows Bounty Program

#87
post #40

Earlier quoted context omitted.

That's how the theory goes, but how often does this really happen though? See: OpenSSL

On the other side, e.g. Egor Homakov hacked GitHub a few times through vulnerabilities in Rails. GitHub paid him bounties anyway. I'm no expert, but it appears to me that at times it does work, just not always.

Is github itself open source tho?

Re: Announcing the Windows Bounty Program

#88
post #48
post #40

Earlier quoted context omitted.

That's how the theory goes, but how often does this really happen though? See: OpenSSL

The simple reality is that when it comes to vulnerability research, Microsoft : Windows :: Google : Open Source.

Google's Project Zero has found quite a number of Microsoft bugs. Unfortunately, Microsoft has not reciprocated the favor.

Re: Announcing the Windows Bounty Program

#89
post #87

Earlier quoted context omitted.

On the other side, e.g. Egor Homakov hacked GitHub a few times through vulnerabilities in Rails. GitHub paid him bounties anyway. I'm no expert, but it appears to me that at times it does work, just not always.

Is github itself open source tho?

Well I think the source code is included (since it's Ruby, but encrypted) with the Github Enterprise image. But that's "source code available", not "open source" (ie, under a copyleft license)

Re: Announcing the Windows Bounty Program

#90
post #35

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

Maybe we should start some sort of foundation dedicated to providing the same incentive to find bugs in OSS I'd imagine there are a lot of programmers who would be interested in supporting something like this

You mean something like The Internet Bug Bounty?
Post reply on HN