>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
Of course not. You don’t push back on something like that. You hire a lawyer and let them do the pushing for you. If you contact the right NGO, they might even give you one for free.
There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.
I've seen hackers. Even if you do it right you're still going to get banned from the internet till you are 18 and dating Angelina Jolie is not the draw it was 20 years ago....
There are so many great one liners in that move. An underrated one is when Dade's mom opens the door, sees Acid Burn and says "now I see what all the fuss is about".
I mean when you're sixteen, you can sign a legally binding contract (might depend on the jurisdiction). Usually you have to be above the age of majority (18) or be emancipated before you can enter into a binding contract.
At that age in the mid 2000s, I would be foaming at the mouth to tell a FANG company to eat dirt over something like a disclosure + unpaid bounty. But if he got the money and didn't negotiate... You live and you learn.
A good move is to negotiate in good faith. You show you can’t be pushed around and you are able to be civil. And most importantly, you know your worth.
Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed.
I wonder what’s the consensus on this? Do people normally report it or not?
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.
My issue was knowing that reporting would allow them to possibly discover my identity. Discovering the vul in itself may instead be considered unauthorized access.
I think my take would be to report it anonymously (via support/marketing/etc.) and in the report strongly encourage them to create a path for security reports (either via a bounty or just a security email). When fixed or actually dismissed post publicly on anonymous channels, with a section saying how they could have created a channel for these reports.
Sounds like he’s gotten bug bounties from MS in the past. Might be forward thinking to keep the relationship amicable going forward.
Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.
john_strinlai · · focus · HN ↗
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
rkagerer · · focus · HN ↗
e.g. The $5000? Amnesty from being sued?
srdjanr · · focus · HN ↗
p-e-w · · focus · HN ↗
There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.
saghm · · focus · HN ↗
snapplebobapple · · focus · HN ↗
stronglikedan · · focus · HN ↗
not not either. where do I sign up?
eecc · · focus · HN ↗
dfxm12 · · focus · HN ↗
patmorgan23 · · focus · HN ↗
0x1ch · · focus · HN ↗
xeromal · · focus · HN ↗
0x1ch · · focus · HN ↗
drfloyd51 · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
icantevenhold · · focus · HN ↗
whatsdowndog · · focus · HN ↗
[dead]
john_strinlai · · focus · HN ↗
menomatter · · focus · HN ↗
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
john_strinlai · · focus · HN ↗
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.
Computer0 · · focus · HN ↗
menomatter · · focus · HN ↗
SahAssar · · focus · HN ↗
mikeryan · · focus · HN ↗
Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.
And he’s 16. Parents might have had a say.