‹ BackHN Continuity

Thread

I could've accessed 17T Microsoft records

322 points · 128 comments · luispa

  1. sdfhbdf · · focus · HN ↗
    > awarded $5000

    It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.

    On <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty it seems the top is $100,000 or $250,000 depending which program this counts under.

    What does HN think? Why would it be only $5000?

    1. muglug · · focus · HN ↗
      As I understand it, bug bounty awards are a rough proxy for &quot;would nation-state actors be able to exploit this for operational purposes without getting caught&quot;.

      Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.

      1. buckle8017 · · focus · HN ↗
        Try 10-20 million USD for a zero click iPhone exploit.
      2. yieldcrv · · focus · HN ↗
        thats the true market value of bug bounty awards

        the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.