Live data from Hacker News

Announcing the Windows Bounty Program

blogs.technet.microsoft.com

91–100 of 121 posts

Re: Announcing the Windows Bounty Program

#91
post #48

Earlier quoted context omitted.

The simple reality is that when it comes to vulnerability research, Microsoft : Windows :: Google : Open Source.

Google's Project Zero has found quite a number of Microsoft bugs. Unfortunately, Microsoft has not reciprocated the favor.

Hehe, "favor"

Re: Announcing the Windows Bounty Program

#92
post #89
post #87

Earlier quoted context omitted.

Is github itself open source tho?

Well I think the source code is included (since it's Ruby, but encrypted) with the Github Enterprise image. But that's "source code available", not "open source" (ie, under a copyleft license)

Encrypted with a widely known (people have blogged it) key.

Re: Announcing the Windows Bounty Program

#93
post #89
post #87

Earlier quoted context omitted.

Is github itself open source tho?

Well I think the source code is included (since it's Ruby, but encrypted) with the Github Enterprise image. But that's "source code available", not "open source" (ie, under a copyleft license)

> But that's "source code available", not "open source" (ie, under a copyleft license)

It's proprietary. Also, there are many free software (or "open source" if you prefer) licenses that are not copyleft. MIT, Apache, Revised BSD, zlib, etc are all examples.

Re: Announcing the Windows Bounty Program

#94
post #75
post #7

Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…

I am mostly surprised by the absence of server 2016 as well

Windows servers are legacy - even SQL Server is on Linux now...ok jokes aside - might be PR move to not make nervous their old-school corporate customers

Re: Announcing the Windows Bounty Program

#95

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

To begin with, some OSS doesn't even know how to treat people who report bugs.

The average OSS project probably is better about that than the average software company though - at least with OSS projects you can be reasonably secure that they won't send lawyers or the police after you for finding bugs.

Re: Announcing the Windows Bounty Program

#96

That max hyper-v payout of $250,000 reminds me of the TV Trope Just Cut Lex Luthor a Check http://tvtropes.org/pmwiki/pmwiki.php/Main/CutLexLuthorAChec...

Usually you can get more money for exploits on the black market, than from bug-bounties. Governments from all around the world have a lot of money to spend to buy exploits.

People keep saying that but is it true? There are some problems;

1. The seller would like to keep their identity secret so that they aren't prosecuted or attacked.

2. The buyer would also like to keep their identity secret.

3. The seller wants money. How do they know that the buyer will send them the money if they hand over the exploit before getting paid? Normally you'd report theft to the police but you're not going to go to the police and admit to selling exploits. Also you don't know who the seller is.

4. The seller wants the exploit. If they pay first then how do they know they will get the exploit.

If you contact some agency directly then surely they will not want to pay you out of fear that you will inform either the public or another government or agency about the transaction?

If there was a darknet marketplace for exploits (maybe there already is, maybe there already are several ones?) then that might solve it. There you can have both some degree of anonymity, you can have reputations for sellers and buyers and the DNM can offer escrow of funds.

Re: Announcing the Windows Bounty Program

#97

Earlier quoted context omitted.

A company would never lie. Especially Microsoft.

My sarcasm detector is acting a little wonky - there is no real reason for Microsoft to lie about this, it isn't exactly breaking the bank for them.

I very much doubt they would lie about it; but if the amount in question was so little that they wouldn't care about it, they would just pay the full price.

Re: Announcing the Windows Bounty Program

#98
post #21

Earlier quoted context omitted.

Because you can disable it. No?

Yes, with some effort: https://github.com/drduh/macOS-Security-and-Privacy-Guide You probably could with the same amount of effort for Windows, but at least Windows makes it more clear that it is happening.

Yep, windows has documented it fairly well with the possible configuration options: https://docs.microsoft.com/en-us/windows/configuration/confi...

Re: Announcing the Windows Bounty Program

#100

Earlier quoted context omitted.

Yes, with some effort: https://github.com/drduh/macOS-Security-and-Privacy-Guide You probably could with the same amount of effort for Windows, but at least Windows makes it more clear that it is happening.

As far as telemetry goes, there is a simple on or off checkbox in the Security and Privacy control panel.

The real issue being that it is set to ON by default and that it tends to reset itself randomly after updates.
Post reply on HN