A vulnerability on this scale.. and they pay out only 40K ? I don't understand, this is peanuts compared to the damages this could cause no? Why do they not pay out respectable amounts?
A vulnerability on this scale.. and they pay out only 40K ? I don't understand, this is peanuts compared to the damages this could cause no? Why do they not pay out respectable amounts?
Should a surgeon ask you for millions? After all he saved your life.
What about the mechanic that finds an issue with your breaks?
If you paid someone not for the work done, but for the resulting loss if criminals exploited something, a lot of professions would ask for crazy prices.
Anyway, seems like an NFT with the instructions would've sold for far more than 40k...
If there are 50 others who can fix my brakes, one of them will likely try to undercut your price so as to get my business.
In this case, M$ could have paid ten times that amount and it would still be pocket money both in terms of their ledger AND vs the damages the PR could cause alone.
M$ does have black market competitors that would have paid far more.
Doing the right thing morally is good. But when people see time and again that simply cashing out once could set you up for life.(Maybe not in this case but maybe in others.) That is an awfully tempting risk to take and I wouldn't blame them.
We're literally saying it doesn't pay to be moral.
At the same time, these discussions about then paying to little aren't good PR either
There was a story on HN a while some guy just got 100K for an Apple account takeover exploit. That is a huge exploit, paying 100K is peanuts for 2 Trillion dollar company.
How have you confirmed that this amount is accurate? Have there been bo zero-days on the black market, instead all hackers have gone to microsoft?
Would the number of hack on black market change is amount paid out increased 10x? It seems you have no basis for claiming that the amount paid is optimal
But if no one can succesfully sue for those damages, then what is it really worth.
The idea that Microsoft with its gargantuan resources cannot discover these mistakes and has to wait for "security researchers" to discover them and then pay them a paltry sum for their "valuable work" makes little sense; a more sensible interpretation is that the company has little incentive to find such mistakes because it has little exposure to potential liability arising from them. It needs to stage "security theater" to avoid reputational damage but does not need to achieve real results. Mistake after mistake, the stock price is not affected. Regarding an ongoing lapse in quality control that spans four decades, it has no skin in the game.
> Some of the best hackers within the NSA turned into independent contractors so they could work faster and make more money, but were on the outside? This is one of those things that someone like Microsoft is afraid of, too. If they pay too much for bugs, then some of their internal bug hunters might decide to quit but keep doing the same thing; just make more money on the outside.
He even used Microsoft as an example. I wonder if they paid less because the researcher was a turncoat in their mind.
Or they could release information publically, without informing M$
I'd be in favor of something like this. Why should the criminal justice system and every tax payer be on the hook for protecting these big companies from the consequences of their bug-ridden software?
There's many examples where the law doesn't stop companies from ripping off individuals, obfuscating terms and conditions to their advantage, hiding prices, etc. Recent example that bothers me is the paperwork at a doctors office, expecting the patient to be responsible for all bills insurance doesn't pay, without letting the patient know the costs involved, basically signing a blank check, even on a signature pad where the contract can't be seen, being told "this is just consent for the exam". The justification that these are standard forms is not a justification.
Too often big companies get subsidized at public expense. That money goes right from taxpayers to shareholders. Microsoft should deal with the fallout from it's less secure software, not taxpayers. Instead these big companies race ahead to make features and sales, playing games with juristictions to avoid paying taxes, etc.
Doesn't seem fair, and just saying "because rule of law" doesn't seem like a good explanation of why we should defend this kind of thing.
Maybe a bug exploit should be considered protected free speech. How about that law?