Investors Hangout Stock Message Boards Logo
  • Mailbox
  • Favorites
  • Boards
    • The Hangout
    • NASDAQ
    • NYSE
    • OTC Markets
    • All Boards
  • Whats Hot!
    • Recent Activity
    • Most Viewed Boards
    • Most Viewed Posts
    • Most Posted
    • Most Followed
    • Top Boards
    • Newest Boards
    • Newest Members
  • Blog
    • Recent Blog Posts
    • Recently Updated
    • News
    • Stocks
    • Crypto
    • Investing
    • Business
    • Markets
    • Economy
    • Real Estate
    • Personal Finance
  • Market Movers
  • Interactive Charts
  • Login - Join Now FREE!
  1. Home ›
  2. Stock Message Boards ›
  3. User Boards ›
  4. Coffee Shoppe Message Board

Microsoft Finally Offers To Pay Hackers For Securi

Message Board Public Reply | Private Reply | Keep | Replies (0)                   Post New Msg
Edit Msg () | Previous | Next


Post# of 63843
Posted On: 06/24/2013 5:33:52 PM
Avatar
Posted By: PoemStone
Re: wowhappens28 #11071

Microsoft Finally Offers To Pay Hackers For Security Bugs With $100,000 Bounty





6 comments, 6 called-out

Comment Now


Follow Comments









396

959












90


























388


























5































Vasilis Pappas claiming his $200,000 reward for developing a new hacking defense at Microsoft's Blue Hat Prize event last year. Now Microsoft is adding ongoing bounties for offensive hacking techniques, too.



For years, Microsoft has refused to offer financial rewards to researchers who tell the company about security flaws in its software, even as Google GOOG -1.26% and Facebook FB -2.43% have ratcheted up their so-called “bug bounty” programs. Now the software giant has suddenly changed its mind–and it’s even offering even bigger bounties in some cases than those competitors.


On Tuesday Microsoft announced that it’s now willing to pay up to $100,000 for information about security bugs that can be used to bypass the defenses of Windows, starting with the upcoming preview version of Windows 8.1 to be released later this month. For researchers who also detail new defensive techniques for preventing similar bugs from being exploited in the future, Microsoft will pitch in an extra $50,000 “Defense Bonus” per submission.



Google Offers $3.14159 Million In Total Rewards For Chrome OS Hacking Contest Andy Greenberg Andy Greenberg Forbes Staff

Shopping For Zero-Days: A Price List For Hackers' Secret Software Exploits Andy Greenberg Andy Greenberg Forbes Staff

Meet The Hackers Who Sell Spies The Tools To Crack Your PC (And Get Paid Six-Figure Fees) Andy Greenberg Andy Greenberg Forbes Staff


“These are super challenging to discover and they require a new technique,” says Mike Reavey, director of Microsoft’s Security Response Center. “So to get people thinking in this area really does require a top-dollar reward.”


Aside from those $100,000 and $50,000 bounties, Microsoft will also pay up to $11,000 for exploits affecting the preview version of Internet Explorer 11, a strategy designed to fix the software’s bugs before it’s widely released to users. “[Most organization] don’t offer bounties for software in beta, so some researchers would hold onto vulnerabilities until the code is released to manufacturing,” reads a blog post about the bug bounty program from Microsoft’s senior security strategist Katie Moussouris. “Learning about these vulnerabilities earlier is always better for us and for our customers.


Microsoft’s payouts compare to just $20,000 offered by Google for bugs in its Web applications, though the search firm did briefly offer $150,000 for a bug in its Chrome operating system in a competition in January and $60,000 for bugs in its Chrome browser the year before. Mozilla offers up to $3,000 for bugs in its software. Facebook pays a minimum of $500 but doesn’t specify its maximum reward.


Since Bill Gates ‘ Trustworthy Computing memo in 2002 , Microsoft has created a reputation for working closely with the security research community, hiring hackers and hosting the Blue Hat security conferences in Redmond.  At the Black Hat conference last year it awarded the first Blue Hat prize for researchers who develop defensive techniques against exploits, totally $260,000 in rewards.


So why only start paying bounties for bugs in its software now? Microsoft’s Reavey says that the company has been receiving a growing stream of reports through third-party bug buying programs like the HP-owned Zero Day Initiative and Verisign’s iDefense, which pay up to $10,000 for bugs and report them the software’s vendor. It also saw the impact of events like the annual Pwn2Own competition, where hackers are sometimes paid six-figure rewards for developing advanced exploits against Microsoft products and then revealing their techniques. “We find out about [these advanced exploits] once a year through these events, or unfortunately,  in the wild,” says Reavey. “We want o get them year round as early and often as possible.”


Part of the incentive for Microsoft’s program may also be the growing bounty for exploit techniques among a different community: Government and black market buyers who plan to use them for espionage or for crime. According to interviews I conducted in March of last year , a working exploit affecting Windows could earn a hacker between $60,000 and $120,000 dollars from an intelligence or law enforcement agency, and one that achieves full compromise of a Windows computer through Internet Explorer could earn as much as $200,000.


In her blog post, Moussouris alluded to those less-friendly bug-sellers, arguing that Microsoft’s program aims to give them an equally lucrative alternative, and that its “Defense Bonus” may also make their offensive hacking more difficult. “With the strategic bounty programs announced today and the industry collaboration program enhancements to come, Microsoft will simultaneously encourage those who want to work with us while increasing costs for those whose actions cannot be affected by bounties or other incentive programs.”



(0)
(0)




Featured stocks: Coffee Shoppe
For conservative debate: "Keeping it Real"
Game Changing stock $SHMP





Investors Hangout

Home

Mailbox

Message Boards

Favorites

Whats Hot

Blog

Settings

Privacy Policy

Terms and Conditions

Disclaimer

Contact Us

Whats Hot

Recent Activity

Most Viewed Boards

Most Viewed Posts

Most Posted Boards

Most Followed

Top Boards

Newest Boards

Newest Members

Investors Hangout Message Boards

Welcome To Investors Hangout

Stock Message Boards

American Stock Exchange (AMEX)

NASDAQ Stock Exchange (NASDAQ)

New York Stock Exchange (NYSE)

Penny Stocks - (OTC)

User Boards

The Hangout

Private

Global Markets

Australian Securities Exchange (ASX)

Euronext Amsterdam (AMS)

Euronext Brussels (BRU)

Euronext Lisbon (LIS)

Euronext Paris (PAR)

Foreign Exchange (FOREX)

Hong Kong Stock Exchange (HKEX)

London Stock Exchange (LSE)

Milan Stock Exchange (MLSE)

New Zealand Exchange (NZX)

Singapore Stock Exchange (SGX)

Toronto Stock Exchange (TSX)

Contact Investors Hangout

Email Us

Follow Investors Hangout

Twitter

YouTube

Facebook

Market Data powered by QuoteMedia. Copyright © 2025. Data delayed 15 minutes unless otherwise indicated (view delay times for all exchanges).
Analyst Ratings & Earnings by Zacks. RT=Real-Time, EOD=End of Day, PD=Previous Day. Terms of Use.

© 2025 Copyright Investors Hangout, LLC All Rights Reserved.

Privacy Policy |Do Not Sell My Information | Terms & Conditions | Disclaimer | Help | Contact Us