2 ms·
> We reported the issue to Microsoft. They did not consider it a vulnerability, but fixed it Seems like Microsoft doesn't like to pay for a bug bounty
by serjd 6y ago
> We reported the issue to Microsoft. They did not consider it a vulnerability, but fixed it
Seems like Microsoft doesn't like to pay for a bug bounty
- sufficient 6y agoI agree that it's weird that they fixed it and didn't consider it a security issue. For the user it looked like it would provide two-factor authentication since the PIN is requested, while in reality it's not verified. Thus, they only provided one-factor security.