Earlier quoted context omitted.
The simple reality is that when it comes to vulnerability research, Microsoft : Windows :: Google : Open Source.
Google's Project Zero has found quite a number of Microsoft bugs. Unfortunately, Microsoft has not reciprocated the favor.
Announcing the Windows Bounty Program
91–100 of 121 posts
Re: Announcing the Windows Bounty Program
#92Earlier quoted context omitted.
Is github itself open source tho?
Well I think the source code is included (since it's Ruby, but encrypted) with the Github Enterprise image. But that's "source code available", not "open source" (ie, under a copyleft license)
Re: Announcing the Windows Bounty Program
#93Earlier quoted context omitted.
Is github itself open source tho?
Well I think the source code is included (since it's Ruby, but encrypted) with the Github Enterprise image. But that's "source code available", not "open source" (ie, under a copyleft license)
It's proprietary. Also, there are many free software (or "open source" if you prefer) licenses that are not copyleft. MIT, Apache, Revised BSD, zlib, etc are all examples.
Re: Announcing the Windows Bounty Program
#94Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…
I am mostly surprised by the absence of server 2016 as well
Re: Announcing the Windows Bounty Program
#95I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.
To begin with, some OSS doesn't even know how to treat people who report bugs.
Re: Announcing the Windows Bounty Program
#96That max hyper-v payout of $250,000 reminds me of the TV Trope Just Cut Lex Luthor a Check http://tvtropes.org/pmwiki/pmwiki.php/Main/CutLexLuthorAChec...
Usually you can get more money for exploits on the black market, than from bug-bounties. Governments from all around the world have a lot of money to spend to buy exploits.
1. The seller would like to keep their identity secret so that they aren't prosecuted or attacked.
2. The buyer would also like to keep their identity secret.
3. The seller wants money. How do they know that the buyer will send them the money if they hand over the exploit before getting paid? Normally you'd report theft to the police but you're not going to go to the police and admit to selling exploits. Also you don't know who the seller is.
4. The seller wants the exploit. If they pay first then how do they know they will get the exploit.
If you contact some agency directly then surely they will not want to pay you out of fear that you will inform either the public or another government or agency about the transaction?
If there was a darknet marketplace for exploits (maybe there already is, maybe there already are several ones?) then that might solve it. There you can have both some degree of anonymity, you can have reputations for sellers and buyers and the DNM can offer escrow of funds.
Re: Announcing the Windows Bounty Program
#97Earlier quoted context omitted.
A company would never lie. Especially Microsoft.
My sarcasm detector is acting a little wonky - there is no real reason for Microsoft to lie about this, it isn't exactly breaking the bank for them.
Re: Announcing the Windows Bounty Program
#98Earlier quoted context omitted.
Because you can disable it. No?
Yes, with some effort: https://github.com/drduh/macOS-Security-and-Privacy-Guide You probably could with the same amount of effort for Windows, but at least Windows makes it more clear that it is happening.
Re: Announcing the Windows Bounty Program
#99Re: Announcing the Windows Bounty Program
#100Earlier quoted context omitted.
Yes, with some effort: https://github.com/drduh/macOS-Security-and-Privacy-Guide You probably could with the same amount of effort for Windows, but at least Windows makes it more clear that it is happening.
As far as telemetry goes, there is a simple on or off checkbox in the Security and Privacy control panel.