From the https://immunefi.com/leaderboard/
#1. 4 paid reports: $13,010,000 total earnings
#2. 2 paid reports: $10,020,000 total earnings
#3. 8 paid reports: $8,010,000 total earnings
If these trillion dollar companies messing around with your personal information was an existential threat to their business, they would pay comparably with crypto companies.
But taking an ancient bounty and multiplying it by an exchange rate from years later would definitely be silly.
Yes, but you have to go through a KYC process, and of course pay your taxes. (In the US)
It also depends on which country you're in. There are a lot of OTC desks if you know where to look.
And yet, it still seems out of line with the scope of the vulnerability.
"seems" implies a subjective measurement.
> If the researchers weren't ok with that bounty, they shouldn't (and wouldn't!)
Researchers are going to research. Please don't carry water for trillion dollar companies; the reward was paltry don't blame the researchers for Microsoft's cheapness.
It is only uninformed HN posters imagining that vulnerabilities are worth millions of dollars on some imaginary black market that are complaining about it. Just like they do with every vulnerability disclosure that mentions the size of the bounty.
And by repeating this low-value conversation for the hundredth tube, you (yes, the specific you) are just hijacking the conversation and taking attention from what is unique and interesting about this case into your fantasy grievances about the bounty being too small.
Well, good morning to you as well.
Anyway, the conversation had turned to the topic of remuneration. You didn't reply with THIS comment originally, you joined right in and defended Microsoft's payment terms. If you thought this thread of conversation was "taking attention away" why did you wallow into the mud with the rest of us?
It's neither imaginary nor black. They list their prices on their website: https://zerodium.com/program.html
Sure normally it is a joke but this one in particular does look like something that would actually be worth something to the right buyer
It's impossible to know if anybody else has been abusing this for some time or not, and it's a valid concern for people here to argue the bounty is low enough that this kind of valuable exploit may have ended up on an exploit marketplace in the interim.
These researchers would get more from re-selling the exploit from dark web criminals than this bug bounty program.
In either case only paying $40,000 for disclosing an exploit like this sends a clear message from Microsoft. They don't take their user's security seriously. And it also incentivizes certain outcomes -- They're cheap and less moral actors who are only motivated by the finanical reward won't bother to engage with Microsoft.
Use Microsoft products at your own peril.
Put another way: just because the researchers didn't (publicly) complain doesn't put MSFT in the right here. There are more than a few kernel developers who didn't raise hell about Linus' abusive behavior. Yet even Linus himself realized his behavior had to change.