‹ BackHN Continuity

Thread

I could've accessed 17T Microsoft records

322 points · 128 comments · luispa

  1. sdfhbdf · · focus · HN ↗
    > awarded $5000

    It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.

    On <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty it seems the top is $100,000 or $250,000 depending which program this counts under.

    What does HN think? Why would it be only $5000?

    1. muglug · · focus · HN ↗
      As I understand it, bug bounty awards are a rough proxy for &quot;would nation-state actors be able to exploit this for operational purposes without getting caught&quot;.

      Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.

      1. buckle8017 · · focus · HN ↗
        Try 10-20 million USD for a zero click iPhone exploit.
      2. yieldcrv · · focus · HN ↗
        thats the true market value of bug bounty awards

        the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability

    2. Perz1val · · focus · HN ↗
      Microsoft&#x27;s bounty program and payouts are known to be pathetic, see that nightmare eclipse situation
    3. bix6 · · focus · HN ↗
      $5k is a literal penny for Microsoft. Give the kid $100k.
      1. k2xl · · focus · HN ↗
        Per their market cap...

        3.85 billion is actually closer to a &quot;penny&quot; for Microsoft.

        1. poly2it · · focus · HN ↗
          Operating income for Microsoft was $128.5 billion in 2025.

          <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;investor&#x2F;reports&#x2F;ar25&#x2F;index.html" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;investor&#x2F;reports&#x2F;ar25&#x2F;index.html

    4. TeMPOraL · · focus · HN ↗
      I think HN, like a lot of people in this industry, have strongly skewed perception of the actual importance of these bugs.

      You could view the bounty prices as market evidence that most of this is rightfully treated as nothingburgers. I.e. the alternative to paying $5000 to some random person for this class of vulnerability research is not risking a trillion dollar hack the next day - it&#x27;s just risking shmaybe some kerfuffle down the line, followed by fixing it through normal triage process. The bounty program is as much marketing as security, and $5000 is probably about the right price for marginal effort into sustaining the &quot;we are treating security seriously&quot; message.

      In a way, the very existence of those bug bounty programs in large companies is evidence they don&#x27;t see a reason to treat vulnerabilities seriously enough to proactively find and fix them in-house.

      If security vulnerabilities would be anywhere serious as most commenters on-line seem to think, companies would pay hundreds of thousands for serious vulnerabilities, just to save a day before they get hit by them - on top of spending millions in-house to try and stay ahead of the attackers.

      But they don&#x27;t. Because most exploits are inconsequential and&#x2F;or aren&#x27;t being exploited much.

      1. TedDoesntTalk · · focus · HN ↗
        Some do pay that kind of money. You just don’t hear about those, and there’s certainly no blog posts about them.
        1. TeMPOraL · · focus · HN ↗
          Right. That&#x27;s how it goes when vulnerabilities are seen as really serious.
    5. giancarlostoro · · focus · HN ↗
      What&#x27;s worse is the alternative is winding up like Aaron Swartz... (all he did was scrape PDFs for mostly public funded &#x2F; tax funded papers) Which is even worse, I think I&#x27;d be glad to receive $20 for Starbucks instead of being legally chased for showing them they messed up.

      There should really be laws for protecting security researchers who produce 0 harm and divulge &#x2F; share a vulnerability with a service provider. I&#x27;d rather the floor be getting no money AND not going to jail or being sued.

      1. elmer2 · · focus · HN ↗
        &quot;all he did was scrape PDFs for mostly public funded &#x2F; tax funded papers&quot;

        He wasn&#x27;t a security researcher. He broke into a room and used equipment to steal information. It wasn&#x27;t just &#x27;tax funded papers&#x27;. Companies invested millions of dollars into some of this research.

        We shouldn&#x27;t support theft and he should have gotten some jail time&#x2F;punishment for it.

        &quot;There should really be laws for protecting security researchers who produce 0 harm and divulge &#x2F; share a vulnerability with a service provider. I&#x27;d rather the floor be getting no money AND not going to jail or being sued.&quot;

        Too many &#x27;security researchers&#x27; demand money or threaten to release the vulnerabilities.

        I don&#x27;t know anyone that got into trouble going through a legit bug bounty program.

        1. thereader12 · · focus · HN ↗
          I have not done a deep dive so I could be wrong, weren&#x27;t these papers published (or soon to be)? Wasn&#x27;t the one and only group with negative effects the Journals that could extract a fee? Especially with researchers usually happy to send a copy? This wasn&#x27;t someone stealing trade secrets they weren&#x27;t even secret.
        2. mosseater · · focus · HN ↗
          It was a protest against the monetization of academic knowledge.

          You can call that &quot;theft&quot; as much as you want. There are lots of people like Aaron out there that think this sort of information should be freely available.

          Just because there is a law doesn&#x27;t mean that that law is just and correct. Saying we &quot;shouldn&#x27;t support theft&quot; is an over-simplification of the situation.

        3. latexr · · focus · HN ↗
          &gt; he should have gotten some jail time&#x2F;punishment for it.

          He was intimidated to the point of suicide, and somehow you don’t think that’s punishment enough?

    6. omoikane · · focus · HN ↗
      Every HN post regarding security exploits inevitably results in some comment saying the bounty is too low. I find it helpful to read previous comments by tptacek regarding bug bounties and market values:

      <a href="https:&#x2F;&#x2F;hn.algolia.com&#x2F;?dateRange=all&amp;page=0&amp;prefix=true&amp;query=tptacek%20bounty%20market&amp;sort=byDate&amp;type=comment" rel="nofollow">https:&#x2F;&#x2F;hn.algolia.com&#x2F;?dateRange=all&amp;page=0&amp;prefix=true&amp;que...

      This one probably has the best summary:

      <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=43025038">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=43025038

      1. elmer2 · · focus · HN ↗
        This is correct. I&#x27;ve made well over six figures over the last couple of years through bug bounty programs. I wouldn&#x27;t spend months finding one bug. It&#x27;s usually days or a week or two max.

        $5,000 is actually pretty normal for a critical. I think the most I received for one bug was around $10,000, but this is the exception.

        AI has also ruined the market. I&#x27;m a security consultant (where I make most of my money) and stopped bug bounty once AI slop reports made it impossible to actually get anything triaged in a timely manner.

        Something else many don&#x27;t know is that with all of the major platforms, customers can see the bugs before they are even triaged by the platform team. Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It&#x27;s then marked as a duplicate and the researcher gets nothing.

        1. physicallyIllfr · · focus · HN ↗

          [dead]

        2. msdz · · focus · HN ↗
          &gt; Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It&#x27;s then marked as a duplicate and the researcher gets nothing.

          Isn’t that just a speedrun-encouragement for selling the exploit not to the one offering the product, but an attacker offering more (in this case, &gt;$0 is not difficult to exceed) instead?

          1. dfxm12 · · focus · HN ↗
            If money is your motivation, you probably wouldn&#x27;t consider disclosing the bugs in the first place.
            1. xnickb · · focus · HN ↗
              If there was an easy way to extract value out of any particular kind of a vulnerability, it&#x27;d cost much more and thus the bounty would&#x27;ve been higher.
        3. rnxrx · · focus · HN ↗
          $5K seems like an absolute steal compared to paying contracted security experts to find such bugs. I&#x27;m surprised these programs aren&#x27;t pushed harder, as the potential ROI seems fantastic.
          1. Aurornis · · focus · HN ↗
            &gt; $5K seems like an absolute steal compared to paying contracted security experts to find such bugs.

            Big companies who run these programs don’t use them as their only security. It’s a bonus program. They have internal employees and often third parties doing testing too.

            &gt; I&#x27;m surprised these programs aren&#x27;t pushed harder, as the potential ROI seems fantastic.

            I have some exposure to managing one of these programs, which was started by someone who left the company abruptly (right after it went on their resume as an achievement).

            It’s a huge amount of work. We got an unbelievable number of bad reports before AI was available. Now it’s just a nightmare. The ratio of bad reports to actual payout-worthy reports was out of control.

            Most submitters also tried to inflate the severity of their submission to get to the higher tiers. This created a problem where people were withholding small bugs while they’d try to find a way to chain it or elevate privileges. You could tell because as soon as you detected and closed their exploit, they would hurriedly submit a rushed report to try to claim it and then argue with you for not paying out because it was fixed before they submitted it.

            We had payouts that went to larger numbers, but honestly I think it would have been better off if we didn’t. This makes bystanders irate, but honestly the incentives get bad when the payouts are large and everyone is spamming LLM bots at your service.

    7. xyst · · focus · HN ↗
      The young researcher is a teenager. Getting your name out there, clout&#x2F;influence&#x2F;fame, is worth $1M to them.

      It’s almost like most of you people have already forgotten your teenage years. And it shows. Doesn’t matter the decade or generation. A teenager , likely living with parents or grandparents, will always prioritize intangibles.

      A mere 5 bands for full editorial control is quite literally peanuts for M$. It’s yet another case of abusing free labor, unfortunately.

      1. xnyan · · focus · HN ↗
        &gt; quite literally peanuts

        If I have an income of $250k&#x2F;yr and a pack of peanuts costs $2 or very roughly 0.001% of my annual income, the equivalent peanut money for ~$130 billion a year microsoft would be more like $2 million.

    8. julianeon · · focus · HN ↗
      I personally think it sets a bad precedent: you want to broadcast that valuable info will be treated as such. A hacker in the future will see this, compare the &quot;precedent&quot; price to the black market, and not even ask Microsoft the next time.
      1. keithnz · · focus · HN ↗
        many of these people want to work in security, selling to the black market will legally and professionally screw you.
        1. skeptic_ai · · focus · HN ↗
          If you sell for crypto how will ruin your reputation? I doubt anyone using real names and bank accounts
    9. asaddhamani · · focus · HN ↗
      I find it perplexing and stingy. Such a bug would likely fetch tens, hundreds of times more on the grey market. Why would anyone not just sell it there? $5000 for trillions of exposed records with PII from Microsoft is a joke.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.