Thursday, March 15th 2018

Microsoft Rolling Out New "Speculative Execution" Bug Bounty Program

In a blog post, Microsoft has announced that it has decided to take the matter of finding critical bugs of similar nature to the Spectre/Meltdown flaws into its own hands - at least partially. Adding to its bug bounty programs, the company has now announced that a new pot of up to $250,000 is up for grabs until at least December 31st of this year.

The new bug bounty program is divided into four different severity/compensation tiers, with tier 1 flaws (New categories of speculative execution attacks) granting up to $250,000 in rewards for the "coordinated disclosure" of such vulnerabilities. The idea here is Microsoft is employing the knowledge and will of the capable masses that might find ways of exploiting vulnerabilities, and would choose to disclose them to Microsoft - getting the prize money, helping the tech industry in providing a timely, coordinated defense against these exploits, and saving vast amounts of funding (and time), by not having to do the bug bounty themselves.
Source: Microsoft Technet Blogs
Add your own comment

9 Comments on Microsoft Rolling Out New "Speculative Execution" Bug Bounty Program

#1
eidairaman1
The Exiled Airman
Croud sourcing...

Now bribing people, how about they start listening to us on interface changes/customizations, how to turn off auto updates etc, put control back in our hands...
Posted on Reply
#2
R-T-B
Going back to the subject, I'm for this. Bounties to discover bugs are good things, people.
Posted on Reply
#3
Easo
eidairaman1Croud sourcing...

Now bribing people, how about they start listening to us on interface changes/customizations, how to turn off auto updates etc, put control back in our hands...
The news topic is about something else entirely.
Can we have news about MS without someone trying to derail it about what they dislike in W10?
Posted on Reply
#4
EzioAs
eidairaman1Croud sourcing...

Now bribing people, how about they start listening to us on interface changes/customizations, how to turn off auto updates etc, put control back in our hands...
The bug bounty program isn't new
Posted on Reply
#5
eidairaman1
The Exiled Airman
EzioAsThe bug bounty program isn't new
Ok so when did it start then?
Posted on Reply
#7
Prima.Vera
Aye. Apple does this for some time. That's why the Jailbreak it became so rare nowadays.
Posted on Reply
#8
eidairaman1
The Exiled Airman
EzioAsYears ago
Ok any proof?
Posted on Reply
Nov 27th, 2024 18:43 EST change timezone

New Forum Posts

Popular Reviews

Controversial News Posts