‹ BackHN Continuity

Thread

I could've accessed 17T Microsoft records

322 points · 128 comments · luispa

  1. john_strinlai · · focus · HN ↗
    >Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.

    that is... not great. shame on microsoft.

    its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.

    1. rkagerer · · focus · HN ↗
      Love to hear more on the motivation for agreeing to this.

      e.g. The $5000? Amnesty from being sued?

      1. srdjanr · · focus · HN ↗
        Also he's 16. I'd definitely be less willing to push back (especially on something like this) at his age
        1. p-e-w · · focus · HN ↗
          Of course not. You don’t push back on something like that. You hire a lawyer and let them do the pushing for you. If you contact the right NGO, they might even give you one for free.

          There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.

          1. saghm · · focus · HN ↗
            I don't know about you, but when I was 16, I never hired a lawyer, and none of the other 16 year olds I knew had either
            1. snapplebobapple · · focus · HN ↗
              I've seen hackers. Even if you do it right you're still going to get banned from the internet till you are 18 and dating Angelina Jolie is not the draw it was 20 years ago....
              1. stronglikedan · · focus · HN ↗
                > dating Angelina Jolie is not the draw it was 20 years ago....

                not not either. where do I sign up?

              2. eecc · · focus · HN ↗
                She’s glorious in the movie, though she does play the part of an extremely high maintenance woman uncannily well…
              3. dfxm12 · · focus · HN ↗
                There are so many great one liners in that move. An underrated one is when Dade's mom opens the door, sees Acid Burn and says "now I see what all the fuss is about".
          2. patmorgan23 · · focus · HN ↗
            I mean when you're sixteen, you can sign a legally binding contract (might depend on the jurisdiction). Usually you have to be above the age of majority (18) or be emancipated before you can enter into a binding contract.
        2. 0x1ch · · focus · HN ↗
          At that age in the mid 2000s, I would be foaming at the mouth to tell a FANG company to eat dirt over something like a disclosure + unpaid bounty. But if he got the money and didn't negotiate... You live and you learn.
          1. xeromal · · focus · HN ↗
            iamverybadass
            1. 0x1ch · · focus · HN ↗
              Well yeah. Why else would you tell off a massive company in the FANG circle as a budding security researcher in their teens.
              1. drfloyd51 · · focus · HN ↗
                A good move is to negotiate in good faith. You show you can’t be pushed around and you are able to be civil. And most importantly, you know your worth.
              2. [deleted] · · focus · HN ↗

                [deleted]

      2. icantevenhold · · focus · HN ↗
        Not getting your life ruined by getting sued by a trillion dollar company sounds like a pretty good motivation
        1. whatsdowndog · · focus · HN ↗

          [dead]

      3. john_strinlai · · focus · HN ↗
        i think the answer is simple: they're a kid, and microsoft bullied them.
      4. menomatter · · focus · HN ↗
        Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed. I wonder what’s the consensus on this? Do people normally report it or not?

        On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.

        1. john_strinlai · · focus · HN ↗
          >Do people normally report it or not?

          if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.

          but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.

          otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.

          1. Computer0 · · focus · HN ↗
            don't worry you are popular with me
          2. menomatter · · focus · HN ↗
            My issue was knowing that reporting would allow them to possibly discover my identity. Discovering the vul in itself may instead be considered unauthorized access.
        2. SahAssar · · focus · HN ↗
          I think my take would be to report it anonymously (via support/marketing/etc.) and in the report strongly encourage them to create a path for security reports (either via a bounty or just a security email). When fixed or actually dismissed post publicly on anonymous channels, with a section saying how they could have created a channel for these reports.
      5. mikeryan · · focus · HN ↗
        Sounds like he’s gotten bug bounties from MS in the past. Might be forward thinking to keep the relationship amicable going forward.

        Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.

        And he’s 16. Parents might have had a say.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.