Earlier quoted context omitted.
It's doable, but if you're good enough to somewhat routinely find bounty-worthy bugs but not spooky good at it, it's not the most lucrative way to put bug-hunting skills to work.
I've noticed a spike recently in bug bounties going to people who using a combination of fuzzing and code analysis tools. It may be that we're moving to a point where bug-hunters' ability to use sophisticated tools will be what earns them the most money, rather than their ability to eyeball code and see the bugs. Speaking just for myself: A few years ago I was saying "I should really set aside a few months to learn t…
Announcing the Windows Bounty Program
111–120 of 121 posts
Re: Announcing the Windows Bounty Program
#112I find the wording of this odd? they have had a bounty program for ages? the list of active bounties is here https://technet.microsoft.com/en-us/security/dn425036
Re: Announcing the Windows Bounty Program
#113I've come to feel that a Windows 10 machine is more secure than an OSX machine, all else being equal.
That's interesting. Care to elaborate?
[1] https://community.rapid7.com/community/infosec/blog/2016/04/...
[2] https://venturebeat.com/2015/12/31/software-with-the-most-vu...
Re: Announcing the Windows Bounty Program
#114Re: Announcing the Windows Bounty Program
#115Re: Announcing the Windows Bounty Program
#116Earlier quoted context omitted.
Which is actually sort of a worst-case scenario (not that I think this bounty is bad), because NSA's primary objective is in fact not to hack all your Windows machines, or even to hack anyone's Windows machine. NSA's primary objective is to secure more budget/headcount for NSA.
While that's true, the NSA's secondary objective is to be the only people who have an arsenal of exploits. Since they have the largest budget, having the price of exploits go up only helps this goal.
It would taken an extraordinary exploit to be worth that much, but imagine a flaw in some weapons platform used by an aggressor that's impractical or impossible to patch and allows for remote code execution. If the US was trying to fend off an attack, or was embroiled in a conflict where this would be an invaluable asset, could end the conflict overnight, they'd pony up.
Like if it could allow them to hack the enemy's radar system to render allied jets invisible, or could corrupt the firmware in anti-aircraft missiles to make them always miss their targets, that would be worth a billion. If it prevented the loss of a few high-value planes it'd pay for itself instantly.
Re: Announcing the Windows Bounty Program
#117Earlier quoted context omitted.
As far as telemetry goes, there is a simple on or off checkbox in the Security and Privacy control panel.
The real issue being that it is set to ON by default and that it tends to reset itself randomly after updates.
However, I would agree that if preferences are changing without user intervention, that would definitely be a problem.
I haven't heard about users having that problem and can't find examples of it happening on the web. Do you have a citation?
Re: Announcing the Windows Bounty Program
#118Earlier quoted context omitted.
As far as telemetry goes, there is a simple on or off checkbox in the Security and Privacy control panel.
This is somewhat misinformed. http://www.computerworld.com/article/3159424/microsoft-windo...
Re: Announcing the Windows Bounty Program
#119Earlier quoted context omitted.
Similar behaviors likely exists in OSS they are just called different things. For example, ACME Co uses open source project XYZ. Acme Co uses resources to make sure that XYZ is secure and bug free. Acme Co is then incentivized to contribute any changes they have found, because they would like to stay in sync with the master branch of XYZ so they can get any updates the community pushes. In the case of OSS, the pool o…
That's how the theory goes, but how often does this really happen though? See: OpenSSL
Re: Announcing the Windows Bounty Program
#120I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.
Software insurance companies can invest a part of the insurance premium on OSS in bug bounties. It’s a shame more people aren’t aware of software insurance, since OSS has several advantages in this area, for example that the source code is available to everyone, such that insurance companies can pay everyone in the world to find bugs in the software they’re insuring.
That’s a definite advantage. It’s not often that an insurance company has the opportunity to invite everyone in the world to help them assess the quality of what they’re insuring.