4 ms·
Its about time. I hope the incentives stay strong enough, and dont require hoops to jump through. otherwise the gray/blackmarkets could out-bid the bounty and c
by oxide 9y ago
Its about time. I hope the incentives stay strong enough, and dont require hoops to jump through. otherwise the gray/blackmarkets could out-bid the bounty and cut the red tape to incentivise their own acquisition of the exploits in question.
- tptacek 9y agoMicrosoft has been doing this for a long time; they're one of the pioneers of bounty programs.
- ygjb 9y agoMuch respect to Microsoft and their new found love of bounty programs, but pioneer is a bit of a stretch - they launched their first bounty program in 2013, well after third party bug bug buyers like ZDI, and even after BugCrowd and other bug bounty as a service companies launched.
- tptacek 9y agoI feel like Katie Moussouris switched from SDL to bug bounty stuff at MSFT in like 2011, but I may have the dates fuzzed up a little bit. Really the only point I want to make is that this is not Microsoft announcing their first bounty program.