b33f Profile picture
13 Aug, 5 tweets, 3 min read
Let's have a #RealTalk moment. In recent years there has been a degeneration of the software bounty industry. Focussing on MSFT here (but it's not exclusive to their program). We had a lot of, "not a boundary", "that thing is not in scope", nerfing the payouts into the ground 1/n
, one of my favourites, "this app has live updates so we don't assign CVE's" and finally on-prem critical infra like Exchange and Sharepoint aren't eligible at all (lol wut, come again?)
I'm honestly baffled by this, for example look at this RCE for teams => github.com/oskarsve/ms-te… marked as "Important/Spoofing" (maybe like 3k bounty?) but at the same time p2o paying out 200k there was a similar story for Slack RCE
I'm not sure what the strategy is here but nerfing payouts into non-existence (5k EOP lol wut, come again?) and/or obscuring bugs doesn't decrease their impact or their real value. I think it only makes private sales much more attractive and is a detriment to everyone ¯\_(ツ)_/¯
Have we really forgotten about this collectively?

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with b33f

b33f Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!

:(