>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
I will tell my story: I found a huge accounting error that allowed for several employees to embezzle funds. I disclosed it to the main stakeholders and some people went to jail. The accounting team still refused to acknowledge that the mistake was theirs, so I left on principle.
A few weeks later, I was talking to an old colleague and they revealed that the story that came from stakeholders was that the accounting team found the error, and I left in disgrace (despite that not being my department?).
So if you find an embarrassing mistake and you do not control the narrative, you have to proceed very carefully.
Had one like that. I quit and they blamed me for a project failure after the fact. That pissed off a couple of colleagues who thought it might happen to them. They also quit leaving them entirely without a software team. Set them back ten years because they didn’t make the market in time.
Write everything down and make sure everyone knows you’re writing it down. Saves a lot of hassle like that.
> the story that came from stakeholders was that the accounting team found the error, and I left in disgrace (despite that not being my department?).
I don't have the full letter at hand, but basically:
- new job paid almost 3x than this one
- I was the sole maintainer of an important project and they had no one else
so they made me not tell anyone I was leaving, and the letter was edited to make it less obvious how much of a better opportunity the new job was.
Of course not. You don’t push back on something like that. You hire a lawyer and let them do the pushing for you. If you contact the right NGO, they might even give you one for free.
There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.
I've seen hackers. Even if you do it right you're still going to get banned from the internet till you are 18 and dating Angelina Jolie is not the draw it was 20 years ago....
There are so many great one liners in that move. An underrated one is when Dade's mom opens the door, sees Acid Burn and says "now I see what all the fuss is about".
I mean when you're sixteen, you can sign a legally binding contract (might depend on the jurisdiction). Usually you have to be above the age of majority (18) or be emancipated before you can enter into a binding contract.
At that age in the mid 2000s, I would be foaming at the mouth to tell a FANG company to eat dirt over something like a disclosure + unpaid bounty. But if he got the money and didn't negotiate... You live and you learn.
A good move is to negotiate in good faith. You show you can’t be pushed around and you are able to be civil. And most importantly, you know your worth.
Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed.
I wonder what’s the consensus on this? Do people normally report it or not?
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.
My issue was knowing that reporting would allow them to possibly discover my identity. Discovering the vul in itself may instead be considered unauthorized access.
I think my take would be to report it anonymously (via support/marketing/etc.) and in the report strongly encourage them to create a path for security reports (either via a bounty or just a security email). When fixed or actually dismissed post publicly on anonymous channels, with a section saying how they could have created a channel for these reports.
Sounds like he’s gotten bug bounties from MS in the past. Might be forward thinking to keep the relationship amicable going forward.
Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.
This is a company that has engaged in heavy monopolistic behavior and violating US anti-trust laws with reckless abandon. They have even pioneered the infamous "embrace, extend, extinguish" strategy.
M$ will never change. The modus operandi is always the same, regardless of which ever lame MBA douchebag is running the shit show.
If we want to actually care , rather than spew off platitudes, break up big tech.
this is normal for responsible disclosure. its how u can keep to post about such things. if they paid out a bounty i see no issue. its a collaboration between 2 parties.
john_strinlai · · focus · HN ↗
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
igleria · · focus · HN ↗
the__alchemist · · focus · HN ↗
ceroxylon · · focus · HN ↗
A few weeks later, I was talking to an old colleague and they revealed that the story that came from stakeholders was that the accounting team found the error, and I left in disgrace (despite that not being my department?).
So if you find an embarrassing mistake and you do not control the narrative, you have to proceed very carefully.
sdcfgy · · focus · HN ↗
Write everything down and make sure everyone knows you’re writing it down. Saves a lot of hassle like that.
itslennysfault · · focus · HN ↗
That sounds like defamation to me.
igleria · · focus · HN ↗
so they made me not tell anyone I was leaving, and the letter was edited to make it less obvious how much of a better opportunity the new job was.
rkagerer · · focus · HN ↗
e.g. The $5000? Amnesty from being sued?
srdjanr · · focus · HN ↗
p-e-w · · focus · HN ↗
There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.
saghm · · focus · HN ↗
snapplebobapple · · focus · HN ↗
stronglikedan · · focus · HN ↗
not not either. where do I sign up?
eecc · · focus · HN ↗
dfxm12 · · focus · HN ↗
patmorgan23 · · focus · HN ↗
0x1ch · · focus · HN ↗
xeromal · · focus · HN ↗
0x1ch · · focus · HN ↗
drfloyd51 · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
icantevenhold · · focus · HN ↗
whatsdowndog · · focus · HN ↗
[dead]
john_strinlai · · focus · HN ↗
menomatter · · focus · HN ↗
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
john_strinlai · · focus · HN ↗
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.
Computer0 · · focus · HN ↗
menomatter · · focus · HN ↗
SahAssar · · focus · HN ↗
mikeryan · · focus · HN ↗
Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.
And he’s 16. Parents might have had a say.
xyst · · focus · HN ↗
This is a company that has engaged in heavy monopolistic behavior and violating US anti-trust laws with reckless abandon. They have even pioneered the infamous "embrace, extend, extinguish" strategy.
M$ will never change. The modus operandi is always the same, regardless of which ever lame MBA douchebag is running the shit show.
If we want to actually care , rather than spew off platitudes, break up big tech.
iwontberude · · focus · HN ↗
[dead]
aw4rzs · · focus · HN ↗
saidnooneever · · focus · HN ↗