‹ BackHN Continuity

Thread

I could've accessed 17T Microsoft records

322 points · 128 comments · luispa

  1. sdfhbdf · · focus · HN ↗
    > awarded $5000

    It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.

    On <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty it seems the top is $100,000 or $250,000 depending which program this counts under.

    What does HN think? Why would it be only $5000?

    1. TeMPOraL · · focus · HN ↗
      I think HN, like a lot of people in this industry, have strongly skewed perception of the actual importance of these bugs.

      You could view the bounty prices as market evidence that most of this is rightfully treated as nothingburgers. I.e. the alternative to paying $5000 to some random person for this class of vulnerability research is not risking a trillion dollar hack the next day - it&#x27;s just risking shmaybe some kerfuffle down the line, followed by fixing it through normal triage process. The bounty program is as much marketing as security, and $5000 is probably about the right price for marginal effort into sustaining the &quot;we are treating security seriously&quot; message.

      In a way, the very existence of those bug bounty programs in large companies is evidence they don&#x27;t see a reason to treat vulnerabilities seriously enough to proactively find and fix them in-house.

      If security vulnerabilities would be anywhere serious as most commenters on-line seem to think, companies would pay hundreds of thousands for serious vulnerabilities, just to save a day before they get hit by them - on top of spending millions in-house to try and stay ahead of the attackers.

      But they don&#x27;t. Because most exploits are inconsequential and&#x2F;or aren&#x27;t being exploited much.

      1. TedDoesntTalk · · focus · HN ↗
        Some do pay that kind of money. You just don’t hear about those, and there’s certainly no blog posts about them.
        1. TeMPOraL · · focus · HN ↗
          Right. That&#x27;s how it goes when vulnerabilities are seen as really serious.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.