Live data from Hacker News

Announcing the Windows Bounty Program

blogs.technet.microsoft.com

1–10 of 121 posts

Re: Announcing the Windows Bounty Program

#2
> If a researcher reports a qualifying vulnerability already found internally by Microsoft, a payment will be made to the first finder at a maximum of 10% of the highest amount they could’ve received (example: $1,500 for a RCE in Edge, $25,000 for RCE in Hyper-V)

Wow. I guess this kind of functions as hush money? To make sure they don't reveal the issue before MS patches it. But still, this seems like a good move.

Re: Announcing the Windows Bounty Program

#5
Its about time. I hope the incentives stay strong enough, and dont require hoops to jump through. otherwise the gray/blackmarkets could out-bid the bounty and cut the red tape to incentivise their own acquisition of the exploits in question.

Re: Announcing the Windows Bounty Program

#7
Dear Microsoft

>Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty

Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?).

Please send me further instructions on how I can claim my 250k.

Also: Why is there nothing for Server 2016?

Re: Announcing the Windows Bounty Program

#8

> If a researcher reports a qualifying vulnerability already found internally by Microsoft, a payment will be made to the first finder at a maximum of 10% of the highest amount they could’ve received (example: $1,500 for a RCE in Edge, $25,000 for RCE in Hyper-V) Wow. I guess this kind of functions as hush money? To make sure they don't reveal the issue before MS patches it. But still, this seems like a good move.

I wonder how often it happens that a company lies (or stretches the truth) about already knowing about a vulnerability to avoid paying a bounty. If it happens even sometimes, the 10% might provide additional incentive for researches to target Microsoft. Even if they don't get a full payout, at least they get something.

Re: Announcing the Windows Bounty Program

#9

> If a researcher reports a qualifying vulnerability already found internally by Microsoft, a payment will be made to the first finder at a maximum of 10% of the highest amount they could’ve received (example: $1,500 for a RCE in Edge, $25,000 for RCE in Hyper-V) Wow. I guess this kind of functions as hush money? To make sure they don't reveal the issue before MS patches it. But still, this seems like a good move.

It also encourages researchers to do research, by making it less likely they'll do a pile of research only to be told "sorry, we already found this, you get nothing". Right now, pursuing a bounty is a risky proposition; this makes it less risky.

Re: Announcing the Windows Bounty Program

#10
post #7

Dear Microsoft >Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?). Please send me f…

Just like Apple, yet no one complains about them.
Post reply on HN