250k is a huge bug bounty. It's a step in the right direction.
At the same time it raises the stakes by begging the question for other cloud providers to fill in by asking "why isn't this higher?" So in that light, the number they've chosen may have served its purpose quite well, by encouraging others to think about what another massive 0-day CPU security flaw might cost them.
Also, I think the temptation to go black hat is a lot lower than if the choices were "nothing" vs "millions"
A check for helping out Microsoft is gonna be pretty clean.
Money you bring in from selling exploits might be something you don't want tracked back to its origin...
How likely is the less clean money going to get you in trouble I don't know, but the check from Microsoft surely will not.
> Yeah, clean money has some extra value.
So in the context of your original post, with your provided definition now of clean money, can you clarify how the alternatives (selling to law enforcement / government, which is the most common alternative) would be “unclean”?
As for selling to another gov or law enforcement, how clean that money is will be relative to what your government thinks of your role. If you sell to say an unfriendly neighbor government, they're going to look at those proceeds a bit differently than say if you sold to THEM.
Clean for me is your likely local legal issues with the money, and/or your actions.
In the end though provided Microsoft isn't considered a terrible enemy by your local government, that probabbly is the cleanest way to sell, and IMO probabbly the safest morally IMO (granted morally and clean money might not always go hand in hand).
When I reward you for finding my wallet I don't give you the entire contents of it, even though I would have lost that much money.
The ultimate irony would be if your bank(s) got compromised by your but and some of your money was lost.
But it's really splitting hairs. I don't really get it either - just a guess.
Ten or twenty times more! But who are these people?! Where do I go to sell them??
https://tsyrklevich.net/2015/07/22/hacking-team-0day-market/
If you're ready to cross the bridge from "providing info to companies that will likely sell it to repressive governments and surveillance agencies" to "I don't care where this goes, I just want the money under any circumstance", my understanding is that you'll end up having to do a lot of finagling, networking, and negotiating to get the information to the people who want it. I couldn't tell you much about this myself, but having known people who did some small-time floating around in the field, opportunities of the under-the-table type are pretty transient.
The problem is how do you recognize a truly good CEO vs. a CEO that lowers costs and makes everybody happy.
Not necessary! Many CPU architectures and implementations were created by academic institutions, so nationalisation of this industry should be considered a possibility.
A lot of companies set a 4 year window for their CEOs. Funneling capital into research, displeases stock holders, as you show reduced earnings. Observe that markets care about steady earning growth; catching these things before they happen in general will not earn you points. That is a sad part of human psychology. Think as a metaphor that an average manager will ask how many bugs did this guy fix and not how many bugs and security issues did this guy caught or saved us from.
(See freaking Equifax -- https://www.marketwatch.com/investing/stock/efx -- they should have been out of business [my personal opinion]. Their stock price is fine. The only mistake of the CEO as far as SEC is concerned is he used inside information and sold.)
Infrastructure is normally patched and rebooted on a regular schedule, but when a bug like this hits and requires an off-cycle upgrade it's a big cost.
Fixed price anything (job, bounty) means very different things to different people.
The world is a big place, and I think exploring security is fairly attractive to the weekend warrior programmer that might find other work hard to come by.