Live data from Hacker News

Announcing the Windows Bounty Program

blogs.technet.microsoft.com

21–30 of 121 posts

Re: Announcing the Windows Bounty Program

#22
post #14

With the increasing number and value of these bounty programs, how viable is a career in professional free lance security bug hunting?

It's doable, but if you're good enough to somewhat routinely find bounty-worthy bugs but not spooky good at it, it's not the most lucrative way to put bug-hunting skills to work.

Re: Announcing the Windows Bounty Program

#23
I wonder what impact this will have on open source software (OSS).

OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can.

I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

Re: Announcing the Windows Bounty Program

#25

Earlier quoted context omitted.

Yes, I'm pretty glad this is around. Hopefully it will lead to less NSA exploits.

The NSA will just have to pay more.

Which is actually sort of a worst-case scenario (not that I think this bounty is bad), because NSA's primary objective is in fact not to hack all your Windows machines, or even to hack anyone's Windows machine. NSA's primary objective is to secure more budget/headcount for NSA.

Re: Announcing the Windows Bounty Program

#26
post #21

Earlier quoted context omitted.

Not Silicon Valley ;p. I never hear anyone complain or hardly anyone even knowing about it.

Because you can disable it. No?

Yes, with some effort: https://github.com/drduh/macOS-Security-and-Privacy-Guide

You probably could with the same amount of effort for Windows, but at least Windows makes it more clear that it is happening.

Re: Announcing the Windows Bounty Program

#28

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

Facebook, Github, and Microsoft already co-sponsor a well-funded open-source "Internet bug bounty".

Re: Announcing the Windows Bounty Program

#29

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

It seems like this might be in part balanced by the fact that it's much easier to find vulnerabilities in open source software, since it's open source.

Re: Announcing the Windows Bounty Program

#30

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

If you think about it, it was always that way. However, a lot of companies that depend upon open source software also invest on it, so it also gets a reasonably good number of eyes trying to fix bugs and add features.
Post reply on HN