• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Microsoft Rolling Out New "Speculative Execution" Bug Bounty Program

Raevenlord

News Editor
Joined
Aug 12, 2016
Messages
3,755 (1.15/day)
Location
Portugal
System Name The Ryzening
Processor AMD Ryzen 9 5900X
Motherboard MSI X570 MAG TOMAHAWK
Cooling Lian Li Galahad 360mm AIO
Memory 32 GB G.Skill Trident Z F4-3733 (4x 8 GB)
Video Card(s) Gigabyte RTX 3070 Ti
Storage Boot: Transcend MTE220S 2TB, Kintson A2000 1TB, Seagate Firewolf Pro 14 TB
Display(s) Acer Nitro VG270UP (1440p 144 Hz IPS)
Case Lian Li O11DX Dynamic White
Audio Device(s) iFi Audio Zen DAC
Power Supply Seasonic Focus+ 750 W
Mouse Cooler Master Masterkeys Lite L
Keyboard Cooler Master Masterkeys Lite L
Software Windows 10 x64
In a blog post, Microsoft has announced that it has decided to take the matter of finding critical bugs of similar nature to the Spectre/Meltdown flaws into its own hands - at least partially. Adding to its bug bounty programs, the company has now announced that a new pot of up to $250,000 is up for grabs until at least December 31st of this year.

The new bug bounty program is divided into four different severity/compensation tiers, with tier 1 flaws (New categories of speculative execution attacks) granting up to $250,000 in rewards for the "coordinated disclosure" of such vulnerabilities. The idea here is Microsoft is employing the knowledge and will of the capable masses that might find ways of exploiting vulnerabilities, and would choose to disclose them to Microsoft - getting the prize money, helping the tech industry in providing a timely, coordinated defense against these exploits, and saving vast amounts of funding (and time), by not having to do the bug bounty themselves.



View at TechPowerUp Main Site
 
Croud sourcing...

Now bribing people, how about they start listening to us on interface changes/customizations, how to turn off auto updates etc, put control back in our hands...
 
Going back to the subject, I'm for this. Bounties to discover bugs are good things, people.
 
Croud sourcing...

Now bribing people, how about they start listening to us on interface changes/customizations, how to turn off auto updates etc, put control back in our hands...

The news topic is about something else entirely.
Can we have news about MS without someone trying to derail it about what they dislike in W10?
 
Croud sourcing...

Now bribing people, how about they start listening to us on interface changes/customizations, how to turn off auto updates etc, put control back in our hands...

The bug bounty program isn't new
 
Aye. Apple does this for some time. That's why the Jailbreak it became so rare nowadays.
 
Back
Top