‹ BackHN Continuity

Thread

I could've accessed 17T Microsoft records

322 points · 128 comments · luispa

  1. sdfhbdf · · focus · HN ↗
    > awarded $5000

    It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.

    On <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty it seems the top is $100,000 or $250,000 depending which program this counts under.

    What does HN think? Why would it be only $5000?

    1. giancarlostoro · · focus · HN ↗
      What&#x27;s worse is the alternative is winding up like Aaron Swartz... (all he did was scrape PDFs for mostly public funded &#x2F; tax funded papers) Which is even worse, I think I&#x27;d be glad to receive $20 for Starbucks instead of being legally chased for showing them they messed up.

      There should really be laws for protecting security researchers who produce 0 harm and divulge &#x2F; share a vulnerability with a service provider. I&#x27;d rather the floor be getting no money AND not going to jail or being sued.

      1. elmer2 · · focus · HN ↗
        &quot;all he did was scrape PDFs for mostly public funded &#x2F; tax funded papers&quot;

        He wasn&#x27;t a security researcher. He broke into a room and used equipment to steal information. It wasn&#x27;t just &#x27;tax funded papers&#x27;. Companies invested millions of dollars into some of this research.

        We shouldn&#x27;t support theft and he should have gotten some jail time&#x2F;punishment for it.

        &quot;There should really be laws for protecting security researchers who produce 0 harm and divulge &#x2F; share a vulnerability with a service provider. I&#x27;d rather the floor be getting no money AND not going to jail or being sued.&quot;

        Too many &#x27;security researchers&#x27; demand money or threaten to release the vulnerabilities.

        I don&#x27;t know anyone that got into trouble going through a legit bug bounty program.

        1. thereader12 · · focus · HN ↗
          I have not done a deep dive so I could be wrong, weren&#x27;t these papers published (or soon to be)? Wasn&#x27;t the one and only group with negative effects the Journals that could extract a fee? Especially with researchers usually happy to send a copy? This wasn&#x27;t someone stealing trade secrets they weren&#x27;t even secret.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.