I could've accessed 17T Microsoft records
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
I could've accessed 17T Microsoft records
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
ltbarcly3 · · focus · HN ↗
I am the last person to judge someone for using AI to help them write a blog post, but what I wonder is: Do people not read what the AI produces before putting their name on it, or is the AI writing style not obvious to some people, or do they just not care that it's obviously AI and bad style?
t-writescode · · focus · HN ↗
Did you give the article a once-over beyond that? It’s one of the decidedly not-AI lines.
ltbarcly3 · · focus · HN ↗
functionmouse · · focus · HN ↗
Forgeties79 · · focus · HN ↗
vonneumannstan · · focus · HN ↗
ltbarcly3 · · focus · HN ↗
0x_rs · · focus · HN ↗
encom · · focus · HN ↗
gosub100 · · focus · HN ↗
bix6 · · focus · HN ↗
icantevenhold · · focus · HN ↗
applfanboysbgon · · focus · HN ↗
ltbarcly3 · · focus · HN ↗
[dead]
ltbarcly3 · · focus · HN ↗
The comment explicitly says, “I am the last person to judge someone for using AI to help them write a blog post.” The criticism is about the quality of the published prose and whether anyone reviewed it before putting their name on it.
You can dispute whether that sentence is bad or whether it indicates AI authorship. But “why criticize unedited AI prose when HN talks about AI so much?” doesn’t identify a contradiction. Discussing a technology doesn’t imply endorsing every use of it, and criticizing its output isn’t the same as vilifying someone for using it.
— GPT-6.1 Sol
eviks · · focus · HN ↗
f311a · · focus · HN ↗
Alifatisk · · focus · HN ↗
hackernudes · · focus · HN ↗
Guess everything is just going to be named after stars for awhile.
DaiPlusPlus · · focus · HN ↗
sdfhbdf · · focus · HN ↗
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What does HN think? Why would it be only $5000?
muglug · · focus · HN ↗
Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.
buckle8017 · · focus · HN ↗
yieldcrv · · focus · HN ↗
the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability
Perz1val · · focus · HN ↗
bix6 · · focus · HN ↗
k2xl · · focus · HN ↗
3.85 billion is actually closer to a "penny" for Microsoft.
poly2it · · focus · HN ↗
<a href="https://www.microsoft.com/investor/reports/ar25/index.html" rel="nofollow">https://www.microsoft.com/investor/reports/ar25/index.html
TeMPOraL · · focus · HN ↗
You could view the bounty prices as market evidence that most of this is rightfully treated as nothingburgers. I.e. the alternative to paying $5000 to some random person for this class of vulnerability research is not risking a trillion dollar hack the next day - it's just risking shmaybe some kerfuffle down the line, followed by fixing it through normal triage process. The process is as much marketing as security, and $5000 is probably about the right price for marginal effort into sustaining the "we are treating security seriously" message.
In a way, the very existence of those bug bounty programs in large companies is evidence they don't see a reason to treat vulnerabilities seriously enough to proactively find and fix them in-house.
If security vulnerabilities would be anywhere serious as most commenters on-line seem to think, companies would pay hundreds of thousands for serious vulnerabilities, just to save a day before they get hit by them - on top of spending millions in-house to try and stay ahead of the attackers.
But they don't. Because most exploits are inconsequential and/or aren't being exploited much.
TedDoesntTalk · · focus · HN ↗
TeMPOraL · · focus · HN ↗
giancarlostoro · · focus · HN ↗
There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued.
elmer2 · · focus · HN ↗
He wasn't a security researcher. He broke into a room and used equipment to steal information. It wasn't just 'tax funded papers'. Companies invested millions of dollars into some of this research.
We shouldn't support theft and he should have gotten some jail time/punishment for it.
"There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued."
Too many 'security researchers' demand money or threaten to release the vulnerabilities.
I don't know anyone that got into trouble going through a legit bug bounty program.
thereader12 · · focus · HN ↗
[dead]
mosseater · · focus · HN ↗
You can call that "theft" as much as you want. There are lots of people like Aaron out there that think this sort of information should be freely available.
Just because there is a law doesn't mean that that law is just and correct. Saying we "shouldn't support theft" is an over-simplification of the situation.
latexr · · focus · HN ↗
He was intimidated to the point of suicide, and somehow you don’t think that’s punishment enough?
omoikane · · focus · HN ↗
<a href="https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=tptacek%20bounty%20market&sort=byDate&type=comment" rel="nofollow">https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
This one probably has the best summary:
<a href="https://news.ycombinator.com/item?id=43025038">https://news.ycombinator.com/item?id=43025038
elmer2 · · focus · HN ↗
$5,000 is actually pretty normal for a critical. I think the most I received for one bug was around $10,000, but this is the exception.
AI has also ruined the market. I'm a security consultant (where I make most of my money) and stopped bug bounty once AI slop reports made it impossible to actually get anything triaged in a timely manner.
Something else many don't know is that with all of the major platforms, customers can see the bugs before they are even triaged by the platform team. Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It's then marked as a duplicate and the researcher gets nothing.
physicallyIllfr · · focus · HN ↗
[dead]
msdz · · focus · HN ↗
Isn’t that just a speedrun-encouragement for selling the exploit not to the one offering the product, but an attacker offering more (in this case, >$0 is not difficult to exceed) instead?
dfxm12 · · focus · HN ↗
xnickb · · focus · HN ↗
rnxrx · · focus · HN ↗
Aurornis · · focus · HN ↗
Big companies who run these programs don’t use them as their only security. It’s a bonus program. They have internal employees and often third parties doing testing too.
> I'm surprised these programs aren't pushed harder, as the potential ROI seems fantastic.
I have some exposure to managing one of these programs, which was started by someone who left the company abruptly (right after it went on their resume as an achievement).
It’s a huge amount of work. We got an unbelievable number of bad reports before AI was available. Now it’s just a nightmare. The ratio of bad reports to actual payout-worthy reports was out of control.
Most submitters also tried to inflate the severity of their submission to get to the higher tiers. This created a problem where people were withholding small bugs while they’d try to find a way to chain it or elevate privileges. You could tell because as soon as you detected and closed their exploit, they would hurriedly submit a rushed report to try to claim it and then argue with you for not paying out because it was fixed before they submitted it.
We had payouts that went to larger numbers, but honestly I think it would have been better off if we didn’t. This makes bystanders irate, but honestly the incentives get bad when the payouts are large and everyone is spamming LLM bots at your service.
xyst · · focus · HN ↗
It’s almost like most of you people have already forgotten your teenage years. And it shows. Doesn’t matter the decade or generation. A teenager , likely living with parents or grandparents, will always prioritize intangibles.
A mere 5 bands for full editorial control is quite literally peanuts for M$. It’s yet another case of abusing free labor, unfortunately.
xnyan · · focus · HN ↗
If I have an income of $250k/yr and a pack of peanuts costs $2 or very roughly 0.001% of my annual income, the equivalent peanut money for ~$130 billion a year microsoft would be more like $2 million.
julianeon · · focus · HN ↗
keithnz · · focus · HN ↗
skeptic_ai · · focus · HN ↗
asaddhamani · · focus · HN ↗
Kuyawa · · focus · HN ↗
sdcfgy · · focus · HN ↗
arm32 · · focus · HN ↗
khalic · · focus · HN ↗
matroxmemories · · focus · HN ↗
Waterluvian · · focus · HN ↗
bix6 · · focus · HN ↗
er0k · · focus · HN ↗
<a href="https://www.howmanydayssinceajwtalgnonevuln.com/" rel="nofollow">https://www.howmanydayssinceajwtalgnonevuln.com/
fabian2k · · focus · HN ↗
buckle8017 · · focus · HN ↗
Complexity is a spec failure in security issues.
It's that simple.
meindnoch · · focus · HN ↗
alex_suzuki · · focus · HN ↗
fabian2k · · focus · HN ↗
teamolHuang · · focus · HN ↗
JWT is a great tool, Microsoft just failed to use it correctly.
Perz1val · · focus · HN ↗
skhameneh · · focus · HN ↗
I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.
The fact that mistakes are so easy to make is indicative of poor design in the spec itself.
talon8635 · · focus · HN ↗
sdcfgy · · focus · HN ↗
ocdtrekkie · · focus · HN ↗
john_strinlai · · focus · HN ↗
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
igleria · · focus · HN ↗
the__alchemist · · focus · HN ↗
ceroxylon · · focus · HN ↗
A few weeks later, I was talking to an old colleague and they revealed that the story that came from stakeholders was that the accounting team found the error, and I left in disgrace (despite that not being my department?).
So if you find an embarrassing mistake and you do not control the narrative, you have to proceed very carefully.
sdcfgy · · focus · HN ↗
Write everything down and make sure everyone knows you’re writing it down. Saves a lot of hassle like that.
itslennysfault · · focus · HN ↗
That sounds like defamation to me.
igleria · · focus · HN ↗
so they made me not tell anyone I was leaving, and the letter was edited to make it less obvious how much of a better opportunity the new job was.
rkagerer · · focus · HN ↗
e.g. The $5000? Amnesty from being sued?
srdjanr · · focus · HN ↗
p-e-w · · focus · HN ↗
There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.
saghm · · focus · HN ↗
snapplebobapple · · focus · HN ↗
stronglikedan · · focus · HN ↗
not not either. where do I sign up?
eecc · · focus · HN ↗
dfxm12 · · focus · HN ↗
patmorgan23 · · focus · HN ↗
0x1ch · · focus · HN ↗
xeromal · · focus · HN ↗
0x1ch · · focus · HN ↗
drfloyd51 · · focus · HN ↗
mulmen · · focus · HN ↗
icantevenhold · · focus · HN ↗
whatsdowndog · · focus · HN ↗
[dead]
john_strinlai · · focus · HN ↗
menomatter · · focus · HN ↗
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
john_strinlai · · focus · HN ↗
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.
Computer0 · · focus · HN ↗
menomatter · · focus · HN ↗
SahAssar · · focus · HN ↗
mikeryan · · focus · HN ↗
Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.
And he’s 16. Parents might have had a say.
xyst · · focus · HN ↗
This is a company that has engaged in heavy monopolistic behavior and violating US anti-trust laws with reckless abandon. They have even pioneered the infamous "embrace, extend, extinguish" strategy.
M$ will never change. The modus operandi is always the same, regardless of which ever lame MBA douchebag is running the shit show.
If we want to actually care , rather than spew off platitudes, break up big tech.
iwontberude · · focus · HN ↗
[dead]
aw4rzs · · focus · HN ↗
saidnooneever · · focus · HN ↗
verst · · focus · HN ↗
jhfdbkofdchk · · focus · HN ↗
verst · · focus · HN ↗
That being said, just last night I observed that the identity team is now opening up agent-assisted PRs against individual service team repos to force MISE adoption and upgrade to the latest version and best practices. I think that's a great thing because many individual service teams simply lack the bandwidth or knowledge. Prior to GenAI availability I wasted many cycles on this kind of work. While GenAI made it easier - internal source documentation still does not unambiguously address every use case. So having the identity team drive this now with the help of agent sessions initiated by them is great.
throwaway2037 · · focus · HN ↗
bsoqk · · focus · HN ↗
lurk2 · · focus · HN ↗
bsoqk · · focus · HN ↗
ToucanLoucan · · focus · HN ↗
And to be clear, this is not an issue with them using contractors, overseas or otherwise, or with their senior dev staff, or even with AI really. It's an issue with them organizationally being so incredibly penny-pinching, and so dedicated to shipping new shit versus fixing anything long term, constantly chasing new revenue and letting their existing offerings rot.
If a Microsoft product is good nowadays, it is literally a miracle.
TeMPOraL · · focus · HN ↗
ocdtrekkie · · focus · HN ↗
sophietaylor · · focus · HN ↗
[dead]
rdtsc · · focus · HN ↗
I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.
flowerlad · · focus · HN ↗
pixl97 · · focus · HN ↗
huflungdung · · focus · HN ↗
[dead]
nenadg · · focus · HN ↗
gnarlouse · · focus · HN ↗
advael · · focus · HN ↗
moat · · focus · HN ↗
Can’t wait to see what he’s up to in 10 years.
Ylpertnodi · · focus · HN ↗
starkeeper · · focus · HN ↗
huflungdung · · focus · HN ↗
[dead]
froggertoaster · · focus · HN ↗
charcircuit · · focus · HN ↗
RajT88 · · focus · HN ↗
<.<
>.>
waws!
zk · · focus · HN ↗
09/17/26 - Awarded $5,000
darepublic · · focus · HN ↗
Holy! Child prodigy
jdw64 · · focus · HN ↗
hmokiguess · · focus · HN ↗
Sytten · · focus · HN ↗
FlameWolf · · focus · HN ↗
Great, give them one more reason to attack WBM.
kmoser · · focus · HN ↗
breakingcups · · focus · HN ↗
aghuang · · focus · HN ↗
Amekedl · · focus · HN ↗
Corporations, like Microsoft, offering 5 grand to that in comparison seems just lackluster.
Relationship and whatnot, pay that teenager 100k is what I'd say, really.
Offering him a job, that would be cool too.
In any case, I'm hoping stuff like this really remains a "once in a lifetime" opportunity for pen-testers and whatnot.
Having the planet hacked twice a day makes for a stressful future for everyone.
jakedata · · focus · HN ↗