Microsoft Offers Bug Bounty to Prevent Another Spectre-Meltdown Fiasco
hothardware.com
hothardware.com
Imagine they know of a vulnerability but believe that it's not practical to exploit, or something. Then someone comes along and demonstrates that it actually is practical to exploit. They could say, well, we knew about this already and didn't believe it's practical, so we're not paying you for it.
It can sometimes be hard to convince a vendor that a vulnerability is "their fault" and this policy only increases the difficulty.
Because of the public?
If someone decides to try make a name for themselves by taking a shot at embarrassing MS/Intel/Linux/AMD/other which do you think will have more affect on public perception: intelligent, detailed discussion about practicalities and real world attack/defense profiles, or loud shouty "but what if" reporting carefully word to be as scary as possible?
When I worked at Mozilla on the MDN team, for example, there was a lot of inevitable spamming of "security" bugs which basically boiled down to "MDN is a publicly-editable wiki and hosts code samples" (MDN also goes to some trouble to do that safely). The current bug bounty exclusions are still pretty broad as far as I can tell, and thankfully will automatically throw out a bunch of the worst of the spam.
Same thing happens still with Django. I've considered writing up something with similar exclusions to Mozilla's policy just because it would save time dealing with meaningless reports (though Django would get a few categories the Mozilla policy doesn't, like "it's not a vulnerability if the only person you can CSRF is yourself").
It doesn't need to be a block-chain but I guess it would help create a tamper proof time ordered record.
Yes, that was obvious to people with some background in this class of attacks. Good on you for figuring that out independently (seriously!), but you're not going to get a bounty for something widely known.
The problem is how do you recognize a truly good CEO vs. a CEO that lowers costs and makes everybody happy.
Not necessary! Many CPU architectures and implementations were created by academic institutions, so nationalisation of this industry should be considered a possibility.
A lot of companies set a 4 year window for their CEOs. Funneling capital into research, displeases stock holders, as you show reduced earnings. Observe that markets care about steady earning growth; catching these things before they happen in general will not earn you points. That is a sad part of human psychology. Think as a metaphor that an average manager will ask how many bugs did this guy fix and not how many bugs and security issues did this guy caught or saved us from.
(See freaking Equifax -- https://www.marketwatch.com/investing/stock/efx -- they should have been out of business [my personal opinion]. Their stock price is fine. The only mistake of the CEO as far as SEC is concerned is he used inside information and sold.)
Infrastructure is normally patched and rebooted on a regular schedule, but when a bug like this hits and requires an off-cycle upgrade it's a big cost.
250k is a huge bug bounty. It's a step in the right direction.
At the same time it raises the stakes by begging the question for other cloud providers to fill in by asking "why isn't this higher?" So in that light, the number they've chosen may have served its purpose quite well, by encouraging others to think about what another massive 0-day CPU security flaw might cost them.
Also, I think the temptation to go black hat is a lot lower than if the choices were "nothing" vs "millions"
A check for helping out Microsoft is gonna be pretty clean.
Money you bring in from selling exploits might be something you don't want tracked back to its origin...
How likely is the less clean money going to get you in trouble I don't know, but the check from Microsoft surely will not.
> Yeah, clean money has some extra value.
So in the context of your original post, with your provided definition now of clean money, can you clarify how the alternatives (selling to law enforcement / government, which is the most common alternative) would be “unclean”?
As for selling to another gov or law enforcement, how clean that money is will be relative to what your government thinks of your role. If you sell to say an unfriendly neighbor government, they're going to look at those proceeds a bit differently than say if you sold to THEM.
Clean for me is your likely local legal issues with the money, and/or your actions.
In the end though provided Microsoft isn't considered a terrible enemy by your local government, that probabbly is the cleanest way to sell, and IMO probabbly the safest morally IMO (granted morally and clean money might not always go hand in hand).
Fixed price anything (job, bounty) means very different things to different people.
The world is a big place, and I think exploring security is fairly attractive to the weekend warrior programmer that might find other work hard to come by.
But it's really splitting hairs. I don't really get it either - just a guess.
Ten or twenty times more! But who are these people?! Where do I go to sell them??
https://tsyrklevich.net/2015/07/22/hacking-team-0day-market/
If you're ready to cross the bridge from "providing info to companies that will likely sell it to repressive governments and surveillance agencies" to "I don't care where this goes, I just want the money under any circumstance", my understanding is that you'll end up having to do a lot of finagling, networking, and negotiating to get the information to the people who want it. I couldn't tell you much about this myself, but having known people who did some small-time floating around in the field, opportunities of the under-the-table type are pretty transient.
The ultimate irony would be if your bank(s) got compromised by your but and some of your money was lost.
When I reward you for finding my wallet I don't give you the entire contents of it, even though I would have lost that much money.
I’m sure I missed something. Could you help me out ?
It was a "fiasco" because it affected over 90% of all servers and laptops out there. And there was just no way to prepare enough of a response, while keeping it secret. For a few months, too few engineers knew about it for good mitigation development. Towards the end, as more people who needed to know were looped in, everyone could see it coming. The vulnerabilities, and mitigations, were just too big.
I wonder what the rationale is for that narrow scope. Is it just that there aren't that many potential sources of side-channels?
If the last 10 years of VT-x implementations had a flaw that lets you extract data from other VMs that would be about as juicy as Meltdown.
https://eprint.iacr.org/2016/479.pdf
https://ts.data61.csiro.au/publications/csiro_full_text//Ge_...
They should broaden it to confidentiality or integrity breaches on CPU components that affect Windows-based products. That will cover more ground. Availability is important, too, but the other two are a nice start that won't break the bank with crashes or stalls. They might still pay for them but with less money.
- https://www.linkedin.com/pulse/bug-bounty-when-auctioning-of...
It includes an implementation of the exploit in a few lines of javascript.