b33f | πŸ‡ΊπŸ‡¦βœŠ Profile picture
意志 / Antiquarian @ IBM Adversary Services / Ex-TORE βš”οΈπŸ¦… / I rewrite pointers and read memory / AI Psychoanalyst / Teaching @CalypsoLabs
Aug 13, 2021 β€’ 5 tweets β€’ 3 min read
Let's have a #RealTalk moment. In recent years there has been a degeneration of the software bounty industry. Focussing on MSFT here (but it's not exclusive to their program). We had a lot of, "not a boundary", "that thing is not in scope", nerfing the payouts into the ground 1/n , one of my favourites, "this app has live updates so we don't assign CVE's" and finally on-prem critical infra like Exchange and Sharepoint aren't eligible at all (lol wut, come again?)