Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Its about time. I hope the incentives stay strong enough, and dont require hoops to jump through. otherwise the gray/blackmarkets could out-bid the bounty and cut the red tape to incentivise their own acquisition of the exploits in question.


Microsoft has been doing this for a long time; they're one of the pioneers of bounty programs.


Much respect to Microsoft and their new found love of bounty programs, but pioneer is a bit of a stretch - they launched their first bounty program in 2013, well after third party bug bug buyers like ZDI, and even after BugCrowd and other bug bounty as a service companies launched.


I feel like Katie Moussouris switched from SDL to bug bounty stuff at MSFT in like 2011, but I may have the dates fuzzed up a little bit.

Really the only point I want to make is that this is not Microsoft announcing their first bounty program.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: