8 ms·
The reason is probably to safe money. The bug bounty for a critical RCE would be between 10k$ and 20k$ depending on the quality of the report. Important Spoofi
by lhoff 6y ago
The reason is probably to safe money. The bug bounty for a critical RCE would be between 10k$ and 20k$ depending on the quality of the report.
Important Spoofing is rated for 3k$ and 500$.
So that is basically a giant middle finger to the security researchers.
Source: https://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud https://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud
- tester34 6y agoIt would be ridiculous, I don't think that's the case here
- lhoff 6y agoWhats your interpretation. The even acknowledged that the bug is an critical RCE on the desktop app. Coincidentally the desktop app is not part of the bug bounty programm. To be fair the impact on the desktop app is higher since it also has access to the OS and the attacker is not stuck inside the browser sandbox. But from my understanding it still is possible to steal the SSO token. When i think about O365 setups with OneDrive for Business and Sharepoint that means the attacker would have access to all files stored there. That usually means all company related files that person has. Additionally the attacker would have access to all emails and messages of the user. How is that not critical? And according to the Bug Bounty side, Spoofing bugs "do not qualify for this severity category".
- jtbayly 6y ago"from my understanding it still is possible to steal the SSO token" Isn't that precisely what spoofing is?
- lhoff 6y agoI wasn't arguing the spoofing part but the important vs. critical part. The same bug for ankther platform is ranked as critical. The thing is that according to Microsoft critical spoofing is not possible.
- donmcronald 6y ago> Isn't that precisely what spoofing is? Not in my opinion. I’ve always thought of spoofing as a write only type thing where you can impersonate someone, but not have access to any of their existing data. Email spoofing is a good example of this. Token theft is WAY more severe because it gives you complete access to everything. It’s total control. You can exfiltrate data and that’s what I’d consider the biggest difference, at least in my opinion.
- dane-pgp 6y agoCompanies offering bug bounties should allow appeals of the amounts/severities they determine by an independent body that is qualified to make these assessments. (Perhaps a respected team of security researchers would be happy to take on this responsibility). To prevent the appeals process being abused, the appellant should have to pay for the time spent by the independent researchers verifying their complaint. For a successful appeal, the company offering the bounty should have to pay that extra cost, encouraging them not to be stingy with the awards they give out in the first place.
- Enginerrrd 6y agoWon't the market just correct them here? If others are willing to pay more for the RCE 0-day, and are more reliable, they'll stop getting the reports and end up scrambling a few times trying to catch up to the curve until they get the message.
- p410n3 6y agoThe only company you can get bug bounty money from is the company that makes the software. If you sell your findings elsewhere you're selling an exploit. Which is probably more lucrative in most cases but also far less ethical. So there isn't much choice here
- ocdtrekkie 6y agoThe market still kind of works: Who is going to bother looking for vulnerabilities in your software if the pay is so much better elsewhere? There may be only one place you can sell a bug, but the security researchers have better places to spend their time.
- deleted 6y ago[deleted]
- gruez 6y agoI think most bug bounty programs are so pitiful in terms of time/effort vs reward that almost nobody is dedicating research on the basis of it. a $10k bounty works out to less than a week's of work for a cybersecurity consultant (at consulting rates), and it's not even guaranteed (both in terms of not finding a bug, and the company offering the bounty marking it as invalid/duplicate). Not to mention, that the black market will pay far more for a 0day than the companies offering the bounties.
- throwaway201103 6y agoSave money? $20K to Microsoft is like $0.02 (if even that) to you and me. Even $200K would be a drop in the bucket compared to the damage from a widely exploited Teams vulnerability.
- deleted 6y ago[deleted]
- deathanatos 6y agoI was curious how accurate that was… MSFT has a market cap of $1.62T. A quick Google says "The median net worth of the average U.S. household is $97,300." That works out to 0.1¢.
- pradn 6y agoThese payouts don't come from the grand central corporate treasury, but from the budget of a director or a VP. They might have a small amount of discretionary funds after their headcount and other expenses are accounted for.
- varispeed 6y agoIt's probably why they have so much money. It only goes one way. They are greedy and unethical just as any other big co, what's worse about them however is that they are trying to wear that deceptive image of them being changed now and embracing open source blah blah, but it is the same greedy Micro$oft it has always been.
- netsec_burn 6y agoIt wouldn't be the first time Microsoft has screwed over independent security researchers. There's a Twitter thread of a researcher who was accepted into the Azure bounty program, found a lot of important zeroday vulnerabilities, and was paid nothing. In fact he expected to be paid for his findings, and then had trouble with his basic living expenses. Anyone who has worked with bug bounties should know to stay far away from them since you can't get assurance you'll be paid (and companies are not incentivized to pay security researchers).
- toyg 6y agoOne thing I don’t understand is why security folks still bother with public bounty programs, when I hear that the market for software reviews is massive and very profitable. Is there a gap in the market for something that can matchmake skilled people with companies at reasonable rates...?
- netsec_burn 6y agoMost of us don't bother with bounties anymore. There are a lot of types of software review so I'm not quite sure which one you're referring to. If you're talking about matchmaking for pentests then you're essentially describing a bounty program, the only difference is that bounty programs don't pay researchers for their time. If you're referring to blog/publications on security then this is the first time I've heard of that market.
- toyg 6y agoI’m thinking of security-oriented code-reviews of various enterprise software. One of my old clients commissioned some last year over a piece of work I made, and apparently they had to go “to hell and back” to source a reputable (and very expensive) reviewer somewhere in California, while I’m sure there must be plenty of UK talent available. They then had someone else pentest it as a blackbox, which is definitely easier to source locally, although the quality can be very variable. I understand it is a very sensitive area, maybe it needs some sort of professional body to provide accreditation and self-regulate and promote reputable members, I don’t know. I think bounties are an unbalanced system; as you say, pentesters don’t get paid for their time and often don’t get paid at all, like in this case. There must be a better way, where an independent third-party can judge actual severity of the hole and sanction payments.
- randomfool 6y ago$20k to reward the amount of security analysis that went into finding this bug is an absolute deal for Microsoft. Seriously- a single FTE security researcher is going to be costing MS >$400k a year (salary, bonus, health care, office space, etc). I work at a BigCo as a recipient of some of these XSSs and I'm awed by the amount of work that goes into them. I always try to overstate the impact to boost the reward- it's not just the bug that they found, but how much of the system they had to look at before they found this. The security folks at BigCo that I interact with are badasses, but it's just so hard to get this level of attention.
- Xenoamorphous 6y agoMy first thought is that this has nothing to do with money and the truth is probably that some team wants nice metrics to show their bosses (see? zero critical vulnerabilities!).
- cutemonster 6y agoI was wondering if there's any weird KPI over at MS that can be gamed by reclassifying an RCE as something less severe.