It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
As I understand it, bug bounty awards are a rough proxy for "would nation-state actors be able to exploit this for operational purposes without getting caught".
Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.
sdfhbdf · · focus · HN ↗
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What does HN think? Why would it be only $5000?
muglug · · focus · HN ↗
Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.
yieldcrv · · focus · HN ↗
the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability