Announcing the Windows Bounty Program
blogs.technet.microsoft.com
blogs.technet.microsoft.com
OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can.
I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.
For example, ACME Co uses open source project XYZ. Acme Co uses resources to make sure that XYZ is secure and bug free. Acme Co is then incentivized to contribute any changes they have found, because they would like to stay in sync with the master branch of XYZ so they can get any updates the community pushes.
In the case of OSS, the pool of resources is likely far bigger than with closed source software.
It's proprietary. Also, there are many free software (or "open source" if you prefer) licenses that are not copyleft. MIT, Apache, Revised BSD, zlib, etc are all examples.
I'd imagine there are a lot of programmers who would be interested in supporting something like this
I was personally involved in a case where a recognizable brand's pen testing effort lead to a fix a well-used piece of open source software.
There is a lot of open source is already being fixed thanks to commercial interests.
I had a bug using NLTK to display parse trees in Jupyter notebooks. NLTK uses tkinter to render the parse trees to PostScript and GhostScript to produce a png image. The chain broke when the PostScript output had a font size of 0.
If this had been a bug in a closed-source program, all I could have put in a bug report would have been "doesn't work, pls fix".
Instead, I could submit a workaround to NLTK and start looking for the reason tkinter generated malformed PostScript output. This turned out to be because Tcl/Tk's font handling used Xft, which used FontConfig, and used an integer for the font size where FontConfig expected a double. Everything worked fine until FontConfig started doing floating point math on the font size. The Tk maintainer who triaged my bug report couldn't even reproduce it on his system, because his version of FontConfig only ever copied the value.
Only because every component of the chain was open source, was it possible to track the bug down and fix it.
Software insurance companies can invest a part of the insurance premium on OSS in bug bounties. It’s a shame more people aren’t aware of software insurance, since OSS has several advantages in this area, for example that the source code is available to everyone, such that insurance companies can pay everyone in the world to find bugs in the software they’re insuring.
That’s a definite advantage. It’s not often that an insurance company has the opportunity to invite everyone in the world to help them assess the quality of what they’re insuring.
Speaking just for myself: A few years ago I was saying "I should really set aside a few months to learn to use fuzzing tools"; now I'm saying "it's easier to just offer bounties and let someone else do the fuzzing for me".
Fuzzing is where you are going to find most memory corruption bugs these days, bounties or not.
Someone could then go and register a new Zendesk account (If the service doesn't require proof of ownership of domain), and say that they want to use the same subdomain. Now they have a Zendesk account with the URL of http://help.somedomain.com as an example. And they can phish people quite easily.
Anyway, the reason I bring it up is because for a while, I saw people spamming the shit out of bug bounties with this stuff. Because it's super simple to do.
So I'm not sure what is more lucrative for an average joe, actually learning proper techniques or trying to piggy back on some low hanging fruit that may be easy to automate.
(1) You are effective at finding the specific kinds of vulnerabilities that the grey market actually purchases. People have _very_ weird ideas about what the grey market wants. In reality, if your bug isn't a drive-by clientside in a popular client, it is unlikely that anyone wants to buy it.
(2) You are willing to get your hands dirty with shady purchasers. If you're talented, you can make good money in the grey market, or you can retain plausible deniability about what your work is being used for, but you can't do both of those things.
That first case is really the limiting factor. And remember, if you can reliably sell bugs to the grey market, that strongly implies you have lucrative options in the legitimate market. Bug bounties are not the most competitive alternative to the grey market!
That sounds like black market buyers (maybe we disagree on where the "gray" line is). Governments are very interested in bugs that allow pivoting and lateral movement.
1. If you have to ask this question, you are quite far from being able to do it any time soon (and that's assuming you can find the vulnerabilities!),
2. You will predominantly sell your vulnerabilities, preferably weaponized as complete exploits, to firms that specialize in "vulnerability research" and "exploitation development" with close ties to government agencies.
It's much easier to find a firm that can act as a broker between you and the government agency than it is to knock on the right doors to sell it on your own, with no background or prior contact.
And quite often, they will be relisted for months at a time. I'm not at all saying there's no market - we clearly know that a remote code exec on a common server will sell well.
Things like "Microsoft Word Exploit" seem a lot more like Duff beer - I'm often hearing how much they are "for sale" for a fortune but I'm not convinced people are getting the significant sums people refer to on a reliable basis.
If you are legitimately good enough, there are certainly companies out there who will pay you well and consistently to hunt for bugs/vulns.
Wow. I guess this kind of functions as hush money? To make sure they don't reveal the issue before MS patches it. But still, this seems like a good move.
BTW, as others have mentioned, this is strictly better than the policy of other bug bounties until now, which is "We already found this, so you get nothing"
the list of active bounties is here https://technet.microsoft.com/en-us/security/dn425036
I think it's more important to remember the NSA's primary goal in other security conversations. What you really don't want to do is propose protocols that leave plausible-but-difficult attack vectors for NSA, because "plausible-but-difficult" is probably inscribed in Latin on some seal somewhere in Ft. Meade.
It would taken an extraordinary exploit to be worth that much, but imagine a flaw in some weapons platform used by an aggressor that's impractical or impossible to patch and allows for remote code execution. If the US was trying to fend off an attack, or was embroiled in a conflict where this would be an invaluable asset, could end the conflict overnight, they'd pony up.
Like if it could allow them to hack the enemy's radar system to render allied jets invisible, or could corrupt the firmware in anti-aircraft missiles to make them always miss their targets, that would be worth a billion. If it prevented the loss of a few high-value planes it'd pay for itself instantly.
http://tvtropes.org/pmwiki/pmwiki.php/Main/CutLexLuthorAChec...
1. The seller would like to keep their identity secret so that they aren't prosecuted or attacked.
2. The buyer would also like to keep their identity secret.
3. The seller wants money. How do they know that the buyer will send them the money if they hand over the exploit before getting paid? Normally you'd report theft to the police but you're not going to go to the police and admit to selling exploits. Also you don't know who the seller is.
4. The seller wants the exploit. If they pay first then how do they know they will get the exploit.
If you contact some agency directly then surely they will not want to pay you out of fear that you will inform either the public or another government or agency about the transaction?
If there was a darknet marketplace for exploits (maybe there already is, maybe there already are several ones?) then that might solve it. There you can have both some degree of anonymity, you can have reputations for sellers and buyers and the DNM can offer escrow of funds.
I like the fact they're offering a bounty program, I'm just surprised Edge was included I guess.
[0]: https://blogs.windows.com/buildingapps/2015/07/06/project-we...
[1]: https://developer.microsoft.com/en-us/windows/projects/event...
I don't think this was a big find but I remember I was still somewhat underwhelmed by the response.
[1] https://community.rapid7.com/community/infosec/blog/2016/04/...
[2] https://venturebeat.com/2015/12/31/software-with-the-most-vu...
Really the only point I want to make is that this is not Microsoft announcing their first bounty program.
I will need some $25K in cash upfront to be convinced to start using Windows 10.
I saw "0 points"; then refreshed browser; still said "3 minutes ago". Rubbed eyes, checked profile settings: "delay 5" still configured.
"delay" is a profile parameter which specifies the number of minutes which elapse from when you initially create a comment to when it becomes published. This gives you a chance to edit or retract your comment before it is subject to public criticism. I've never before seen a voting or reply event occur on a comment prior to the expiry of the delay.
(Maybe some clocks are way out of sync between some distributed servers, so 3 minutes old here means 5 minutes old there? Or maybe NTP suddenly stepped a lagging wall clock forward by a couple of minutes?)
To the topic: how much $ can I get out of this? ;)
>Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty
Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?).
Please send me further instructions on how I can claim my 250k.
Also: Why is there nothing for Server 2016?
I never hear anyone complain or hardly anyone even knowing about it.
You probably could with the same amount of effort for Windows, but at least Windows makes it more clear that it is happening.
However, I would agree that if preferences are changing without user intervention, that would definitely be a problem.
I haven't heard about users having that problem and can't find examples of it happening on the web. Do you have a citation?
In this setting this is relevant even if funny.
I'll still downvote you for the same comment elsewhere.
And I mostly defend MS for enabling telemetry by default but I don't defend how absurdly hard they have made it to disable it.
> Please avoid introducing classic flamewar topics unless you have something genuinely new to say about them.
For the record, I'm not the one who downvoted the parent for an honest question.
There are threads where it would be relevant, in this case they're just using this thread as a sounding board because the title contains the word Microsoft. Plus we have all read near identical posts and the corresponding discussion hundreds of times already, because they appear in every thread that brings up Microsoft.
It is kind of like Godwin's law, except instead of Hitler it is telemetry and Microsoft. If there is new information or new things to discuss, absolutely let's talk about it, but repeating the same complaint gets old after the nth time.