Live data from Hacker News

Announcing the Windows Bounty Program

blogs.technet.microsoft.com

11–20 of 121 posts

Re: Announcing the Windows Bounty Program

#11

> If a researcher reports a qualifying vulnerability already found internally by Microsoft, a payment will be made to the first finder at a maximum of 10% of the highest amount they could’ve received (example: $1,500 for a RCE in Edge, $25,000 for RCE in Hyper-V) Wow. I guess this kind of functions as hush money? To make sure they don't reveal the issue before MS patches it. But still, this seems like a good move.

It also encourages researchers to do research, by making it less likely they'll do a pile of research only to be told "sorry, we already found this, you get nothing". Right now, pursuing a bounty is a risky proposition; this makes it less risky.

Yeah, good point. "Hush money" may have been a little too harsh.

Re: Announcing the Windows Bounty Program

#13
I reported an information leakage from password fields in Windows some moons ago (ctrl arrow would stop between different character classes in modern Windows style password fields.)

I don't think this was a big find but I remember I was still somewhat underwhelmed by the response.

Re: Announcing the Windows Bounty Program

#16
post #7

Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…

Just like Apple, yet no one complains about them.

Where do you live where you're not hearing complaints about Apple?

Re: Announcing the Windows Bounty Program

#17
post #16

Earlier quoted context omitted.

Just like Apple, yet no one complains about them.

Where do you live where you're not hearing complaints about Apple?

Not Silicon Valley ;p.

I never hear anyone complain or hardly anyone even knowing about it.

Re: Announcing the Windows Bounty Program

#19

Earlier quoted context omitted.

Yes, I'm pretty glad this is around. Hopefully it will lead to less NSA exploits.

The NSA will just have to pay more.

Where the people pay increased taxes to help the NSA spy on them easier.

Re: Announcing the Windows Bounty Program

#20
post #7

Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…

Defending you here:

In this setting this is relevant even if funny.

I'll still downvote you for the same comment elsewhere.

And I mostly defend MS for enabling telemetry by default but I don't defend how absurdly hard they have made it to disable it.

Post reply on HN