Live data from Hacker News

Announcing the Windows Bounty Program

blogs.technet.microsoft.com

111–120 of 121 posts

Re: Announcing the Windows Bounty Program

#111
post #22

Earlier quoted context omitted.

It's doable, but if you're good enough to somewhat routinely find bounty-worthy bugs but not spooky good at it, it's not the most lucrative way to put bug-hunting skills to work.

I've noticed a spike recently in bug bounties going to people who using a combination of fuzzing and code analysis tools. It may be that we're moving to a point where bug-hunters' ability to use sophisticated tools will be what earns them the most money, rather than their ability to eyeball code and see the bugs. Speaking just for myself: A few years ago I was saying "I should really set aside a few months to learn t…

[deleted]

Re: Announcing the Windows Bounty Program

#113

I've come to feel that a Windows 10 machine is more secure than an OSX machine, all else being equal.

That's interesting. Care to elaborate?

IIRC articles have been posted on HN about this but I don't recall what they were exactly. Also not sure how accurate this [1] is and if it reflects actual security/breaches/... per user, but it does give an indication the OP's feeling might be correct, seeing statements like In 2015, according to the NVD, OSX had the most vulnerabilities, followed by Windows 2012 and Ubuntu Linux. And here [2] it's also at the top and Windows 10 is mentioned as well, but it was quite young then. Similar in 2016 [3]

[1] https://community.rapid7.com/community/infosec/blog/2016/04/...

[2] https://venturebeat.com/2015/12/31/software-with-the-most-vu...

[3] https://www.cybrnow.com/10-most-vulnerable-os-of-2016/

Re: Announcing the Windows Bounty Program

#114
Nice. now can we please have a way of reporting phishing/malware hosted on Microsoft services (Onedrive, hosted Sharepoint, Azure, etc)? I have reported a few of these to Microsoft's CERT team and they just seem to get ignored.

Re: Announcing the Windows Bounty Program

#116
post #25

Earlier quoted context omitted.

Which is actually sort of a worst-case scenario (not that I think this bounty is bad), because NSA's primary objective is in fact not to hack all your Windows machines, or even to hack anyone's Windows machine. NSA's primary objective is to secure more budget/headcount for NSA.

While that's true, the NSA's secondary objective is to be the only people who have an arsenal of exploits. Since they have the largest budget, having the price of exploits go up only helps this goal.

I bet the NSA can and would pay a billion dollars for an exploit that was worth it, but other nation-states would be shut out from bidding simply because they couldn't even if they wanted to.

It would taken an extraordinary exploit to be worth that much, but imagine a flaw in some weapons platform used by an aggressor that's impractical or impossible to patch and allows for remote code execution. If the US was trying to fend off an attack, or was embroiled in a conflict where this would be an invaluable asset, could end the conflict overnight, they'd pony up.

Like if it could allow them to hack the enemy's radar system to render allied jets invisible, or could corrupt the firmware in anti-aircraft missiles to make them always miss their targets, that would be worth a billion. If it prevented the loss of a few high-value planes it'd pay for itself instantly.

Re: Announcing the Windows Bounty Program

#117
post #100

Earlier quoted context omitted.

As far as telemetry goes, there is a simple on or off checkbox in the Security and Privacy control panel.

The real issue being that it is set to ON by default and that it tends to reset itself randomly after updates.

I'd say the real issue is that Windows 10 not only defaults to having telemetry turned on, but that it also does not allow a system administrator to turn it completely off.

However, I would agree that if preferences are changing without user intervention, that would definitely be a problem.

I haven't heard about users having that problem and can't find examples of it happening on the web. Do you have a citation?

Re: Announcing the Windows Bounty Program

#118

Earlier quoted context omitted.

As far as telemetry goes, there is a simple on or off checkbox in the Security and Privacy control panel.

This is somewhat misinformed. http://www.computerworld.com/article/3159424/microsoft-windo...

I should have been clearer that I was referring to how one turns off telemetry on MacOS.

Re: Announcing the Windows Bounty Program

#119
post #40

Earlier quoted context omitted.

Similar behaviors likely exists in OSS they are just called different things. For example, ACME Co uses open source project XYZ. Acme Co uses resources to make sure that XYZ is secure and bug free. Acme Co is then incentivized to contribute any changes they have found, because they would like to stay in sync with the master branch of XYZ so they can get any updates the community pushes. In the case of OSS, the pool o…

That's how the theory goes, but how often does this really happen though? See: OpenSSL

You say that like Heartbleed was the end of the story. Since then, "the Linux Foundation launched the Core Infrastructure Initiative (CII) as a way of getting resources to those projects. That has helped OpenSSL, among others, to get back into a healthy state." which includes a ton of funding from many companies that depend on OpenSSL like AWS, Google, Intel, Microsoft.

https://lwn.net/Articles/702751/

Re: Announcing the Windows Bounty Program

#120

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

> OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can.

Software insurance companies can invest a part of the insurance premium on OSS in bug bounties. It’s a shame more people aren’t aware of software insurance, since OSS has several advantages in this area, for example that the source code is available to everyone, such that insurance companies can pay everyone in the world to find bugs in the software they’re insuring.

That’s a definite advantage. It’s not often that an insurance company has the opportunity to invite everyone in the world to help them assess the quality of what they’re insuring.

Post reply on HN