Microsoft’s Bounty Program … Improves It’s Scope?

Source: Bleeping Computer Microsoft’s Bounty Program … Improves It’s Scope?

Careful Redmond, People Might Expect You To Improve Other Things As Well

Anyone who has dealt with Microsoft’s support services knows that there is nothing one of their reps likes more than finding a piece of third party software to blame a bug on.  If they can do so they can then close off your case immediately, leaving you to try to navigate a different support team.  Amazingly this tradition is being tossed to the wind as the Microsoft Bug Bounty program will now pay out “regardless of whether the code was written by Microsoft or a third party.

The reasoning is that attackers don’t care who created the vulnerability, only that they can infect a Windows device with it.  This was announced yesterday at Black Hat Europe and could mean we see a lot more effective patches coming out in the future.  Microsoft have paid out over $17 million in bounty awards in the last 12 months to 344 different security researchers.  They may see that bill climb, hopefully that doesn’t change Microsoft’s mind about third party app bug bounties.

Microsoft now pays security researchers for finding critical vulnerabilities in any of its online services, regardless of whether the code was written by Microsoft or a third party.

Video News

About The Author

Jeremy Hellstrom

Call it K7M.com, AMDMB.com, or PC Perspective, Jeremy has been hanging out and then working with the gang here for years. Apart from the front page you might find him on the BOINC Forums or possibly the Fraggin' Frogs if he has the time.

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Podcasts

Archive & Timeline

Previous 12 months
Explore: All The Years!