Microsoft still bucks bug bounty trend

Powered by SC Magazine
 

Redmond says BlueHat is better.

The richest and biggest software company in the world still won’t pay researchers for disclosing vulnerabilities despite a growing number of its peers opting to do so.

Microsoft thinks bug bounties are superfluous: its Microsoft Security Response Centre (MSRC) team were constantly inundated with free vulnerability reports from researchers looking for fame, not fortune. Up to 80 per cent of Microsoft vulnerabilities were privately and freely reported.

Researchers had a variety of motivations behind reporting bugs and money was not necessarily chief among them, Microsoft security boss Mike Reavey said.

“I don’t think that filing and rewarding point issues is a long-term strategy to protect customers."

Redmond’s new BlueHat competition -- which pays handsomely for defensive security solutions -- was more effective, he said, and more appealing to those who consider security research an “intellectual pursuit”.

Reavey said BlueHat participants had respect because they were builders and breakers.

“Rewarding $200,000 for finding techniques that blocks an entire class of exploits scales better, and better protects customers.”

Companies including Google, Mozilla, Facebook and Samsung were some of an expanding list of companies prepared to shell out for privately-disclosed vulnerabilities.

PayPal was the latest to join that list this week after the company’s chief security officer Michael Barrett changed his tune on paying for vulnerabilities.

“I originally had reservations about the idea of paying researchers for bug reports, but I am happy to admit that the data has shown me to be wrong – it’s clearly an effective way to increase researchers’ attention on internet-based services and therefore find more potential issues,” Barrett said.

He said the experience from companies that pay for bugs was “very positive”.

Researchers could earn a dollar from Microsoft vulnerabilities through HP's Zero Day Initiative, which pays for reported bugs and supplies them to affected vendors for free.

Microsoft’s MSRC receives between 100,000 to 200,000 emails each year that range from critical vulnerability disclosures down to user requests to help deal with malware infections.

Of those, about 1000 were triaged and around 150 were considered vulnerabilities.

Only 16 have been released as more costly out-of-band security releases, and the remainder pushed through Microsoft’s monthly patch Tuesday updates.

Details on PayPal's bug bounty is available online.

Copyright © SC Magazine, Australia


Microsoft still bucks bug bounty trend
 
 
 
Top Stories
First look: Microsoft Outlook for iOS
[Update] Office productivity suite for iOS completed with Outlook.
 
NewSat defaults on $26m in overdue Lockheed payments
Jabiru-1 satellite build hits further hurdles.
 
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Microsoft Outlook is now on iPhone and iPad: why could this be useful?
Jan 30, 2015
Microsoft today released Office for Android and Outlook for iOS - complementing the other Office ...
Franchisees, here's something you should know about
Jan 23, 2015
You need to know the Code if you are a franchisee or franchisor as the penalties are significant.
Xero users rejoice! Quoting has finally arrived
Jan 23, 2015
It has taken years, but Xero has at last added integrated quoting to its online accounting software.
You can now get a no-contract wi-fi tablet from Telstra
Jan 17, 2015
Telstra has began selling wi-fi tablets out of contract without paying extra for cellular ...
Get your business ready for 2015: mobile payments
Jan 2, 2015
These handy apps from MYOB, Xero and others can reduce your administrative load and improve ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3098

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 987

Vote