b33f Profile picture
意志 / Team RedBlue ¯\_(ツ)_/¯ / Ex-TORE ⚔️🦅 / Undocumented / I rewrite pointers and read memory / Tempora mutantur, nos et mutamur in illis
Aug 13, 2021 5 tweets 3 min read
Let's have a #RealTalk moment. In recent years there has been a degeneration of the software bounty industry. Focussing on MSFT here (but it's not exclusive to their program). We had a lot of, "not a boundary", "that thing is not in scope", nerfing the payouts into the ground 1/n , one of my favourites, "this app has live updates so we don't assign CVE's" and finally on-prem critical infra like Exchange and Sharepoint aren't eligible at all (lol wut, come again?)