2,474 karma · joined August 27, 2016
That said, there are numerous options that should be enabled and several protocols that should be disabled. It just isn't worth the spam you get if you allow submissions for these type of issues.
Testing against customers is also a common prohibition for obvious reasons.
It's stupid too, because the question I answered "wrong" wasn't clear. It basically sounded like they were asking me if I currently had a cold or covid.
All it takes is one wrong person to be assigned as a report comes in, a person who doesn't understand the real value of a bounty program, or one person having a bad day to completely ruin a company's reputation. It seems like that might have happened here (of course MS has done this before so who knows if it'll matter in the end).
Microsoft needs to be completely transparent and to do so immediately. They should, with the reporters permission, release all communications. They can exclude technical details if patches aren't available yet. Doing anything less is going to prevent a lot of people from using their bounty program in the future and we'll all be worse off for it. They almost certainly made a mistake and they need to own up to it.
I'm a bit surprised with Alexis' involvement they didn't anticipate the bot problem. Alexis left reddit several years ago but I'm sure he's still in touch with the folks who run the place. It would've been worth it to talk to them about the threats they currently face and how they deal with them.
ASCII windows may not have been everyone's cup of tea but I loved it.
It does have me thinking about what versions of SSH would run on such an old OS. I'm sure there were versions available at one time... and since it's vulnerable to remote exploit anyways the version wouldn't really matter.