Microsoft Announces Direct Cash Payments For Vulnerabilities
microsoft.com
microsoft.com
Also interesting because Microsoft was once publicly opposed to programs like these:
https://threatpost.com/microsoft-says-no-paying-bug-bounties...
Basically if you had a Microsoft vulnerability and you decided that you wanted to disclose it, you would just go through a broker (such as ZDI) who would deal with Microsoft, but also pay you. The other options were full disclosure, or selling it on the grey market.
There are major vendors who are far worse than Microsoft, such as Oracle and Adobe, but they are just so bad that nobody expects anything of them.
tl;dr Google has been making them look bad.
Money well spent by Microsoft, and something that will be of value to Microsoft's customers, who are usually treated as the least important people on the planet. Good for Microsoft.
I can confirm they had a (semi?) official program to do this as far back as 2006, as I was actually doing penetration testing as a hobby in high school a couple years before this article was written. They flew myself and a few other researchers out for retreats, put us up in nice hotels, took us out to fancy dinners, offered us internships, sent me an ipod video for my birthday at a time when they were really pushing the Zune, and at one point they even organized a huge paintball retreat for myself and some of the employees. The whole thing really put a very human face on the "corporate" persona we had always associated with Microsoft.
I think their strategy was more focused on grooming researchers to become permanent employees (which a few of them did, including Skylined, the guy that developed the Heapspray technique [1], who I shared an office with - super nice guy) or at the very least building loyalty to encourage responsible disclosure. They were also very interested in hearing how us researchers could be persuaded to continue disclosing responsibly, as a few of us were known to wear hats that weren't always white.
>I think Microsoft might be unique in offering a huge bonus for core platform exploitation
I'm happy to see them taking such a progressive approach considering a single critical security flaw can rake in tens of thousands of dollars on the black market.
Is there an age limit for participants?
Researchers 14 years of age or older may submit bypasses and defense ideas to the program. If you are at least 14 years old but are considered a minor in your place of residence, you must ask your parent’s or legal guardian’s permission prior to participating in this program. Please see the program guidelines for full information on eligibility.
Selling exploits to customers who don't intend on fixing the exploit (buying a hacker's silence) is exactly the nightmare that came to light regarding MS releasing exploit information to NSA prior to releasing publicly-available bugfixes, and these kinds of monetary incentives to the security community will only make things worse.
Read more: https://www.eff.org/deeplinks/2012/03/zero-day-exploit-sales...
These exploits are effectively high-tech weaponry and they should be treated similarly.
The work required to build reliable exploits against hardened Windows can take months. Why shouldn't researchers be compensated for that work? If you don't want to accept payment for it, that's fine; don't. But why is it bad for other people to do so?
By default a naturally occurring exploit probably upon inspection looks less intentional then one put there on purpose.
. . . except for the outsider who mailed them about it and got paid a chunk of money as a result.
At least an internal employee is on your payroll, and has been screened with a background check. You don't get to screen which people get to discover vulnerabilities.
They would not know about the program which takes that exploit and then gives it to the NSA.
Nevertheless, I don't see how this is a bad thing.
MS is in the unique position of being the only ones able to fix the exploit so they are a single-point-of-failure, which diminishes the security of everybody using Windows operating systems.
Microsoft does not have the in-house expertise to feed exploits to anyone.
I agree with you everywhere else in this thread, but you are clearly not up to speed on who works there if you believe that to be accurate. Some of the best exploit writers, who have pioneered new classes of techniques, work at Microsoft (because Microsoft went on a recruiting spree to target them).
Then again, the notion that Microsoft dedicates resources to serve as an outsourcing shop for NSA hackers to develop "cyber weapons" no longer has "reasonable person" anywhere on the horizon. That's not even worth entertaining, I just had to interject because I thought you were saying MS doesn't have good exploit writers ;)
I do think the MAPP equivalent for governments, probably as an unintended side effect, grants some advantage to parts of the .gov interested in attacking the products. How much, and whether or not they need it, is another story. But I agree that the NSA sure doesn't need their help - it's probably just a bit of free gravy if anything.
And in Microsoft's defense, it really wouldn't matter if they gave them to the NSA or not. The distribution list is very large, and the teams who ultimately receive that content are not vetted in any way.
(I made that number up.)
> The work required to build reliable exploits against hardened Windows can take months.
Under it all, the current model remains a by obscurity model, where anyone with orders of more magnitude of resources can certainly do enough reverse engineering to find the weak links and break in without planting backdoors.
Vendors reaching the point where they can offer bounties without contemplating bankruptcy implies considerably more resources are going into secure by design software and will continue to flow if they plan to remain solvent and unembarrassed (equally emabarassed?)
I've been playing with a chromebook and I am delighted to see frivolous and even fairly significant features were dropped to develop a secure boot model with a reasonable opt out. I'm sure it will still be broken, but 5-10 years ago it would have been trivially breakable to meet some last minute corporate request for tftp booting, marketing demo, or what have you..
Similar to the drug market, you can not drop the open market and expect everything to stop. Instead you must capture as many resources as you can and direct them to the right goal. I would hope that goal is secure kernels that expand out towards today's features, since the opposite clearly does not work with the resources at hand.
http://thedailywtf.com/Articles/The-Defect-Black-Market.aspx
It's not obvious that people not writing the software can contribute to the problem, but I suppose this program will test the hypothesis. What I mean is that, in this Dilbert strip, the programmers get paid to fix bugs that they create, incenting the creation of bugs. Paying the townspeople to let the company know about bugs would not obviously (to me) lead to more bugs being created (except in contrived scenarios that involve collusion).
Searching for Dilbert bug bounty brought it up in the top results.
This would make things fair.
If he is smart enough to hire cheapo programmers and suppress creativity and initiative, he has to pay for his technical debt to clean the mess up.
In all seriousness, any package as complex as Windows and Office is bound to have bugs, many, many bugs.
It's appears to be a lot better than their blue-hat prize, which was crowd-sourced spec work and they kept rights to all of the submissions, despite not paying for any beyond the top two or three.
Now that we know Microsoft passes vulns along to the NSA, this looks a lot different.
Another thing to note: when you claim a bounty for a vulnerability from Microsoft, you can be pretty confident that the vulnerability will at some point be fixed. When you sell it to a government yourself, the opposite is true.
[edit]Link for reference, if anyone missed that particular news: http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... [/edit]
NSA does not need Microsoft's help to break into Windows boxes.
What's wrong with speculating that the Microsoft Bug Bounty is an NSA-influenced plot to funnel zero-day to the government is that that's a stupid conspiracy theory. It's elaborate and complicated in ways that the NSA doesn't need to deal with. It also casts aspersions on the people at Microsoft --- who are actual people who you can actually talk to --- who worked very hard to make this program happen after Microsoft spent years being criticized for not doing this.
From this and other assertions made in the Bloomberg piece, it seems very fair not to read this as conventional patch management, but as a special arrangement with intelligence agencies. And to read this as, yes, from time to time Microsoft's help does get the NSA into Windows boxes.
Now, we all know that tech reporting often leaves something to be desired. If you're saying the officials were wrong or quoted out of context, then that's fine. But it's not reasonable to dismiss this out of hand as some outlandish Alex Jonesian conspiracy theory.
BTW, obviously I'm not saying that Microsoft's bug bounty program is an NSA plot. It's a good program that every major company should have. I'm also not saying that they don't share bugs with other partners ahead of time, they obviously do. Just that from what the sources in this article (which again, did not originally appear on infowars.com) say, Microsoft does have a special arrangement with intelligence agencies and from time to time has shared bugs knowing they might be exploited by said agencies. The bug bounty program could find the sort of bugs that would (incidentally) be shared as part of this arrangement.