Microsoft Awards First $100,000 Bug Bounty to Security Researcher
October 9, 2013 10:29 AM
comment(s) - last by
The same security researcher has earned the vast majority of all Microsoft payouts for bugs
Microsoft has announced that it awarded its first $100,000 bounty to a security researcher named James Forshaw. Forshaw is a security vulnerability researcher with Context Information Security and had previously found design level bugs during the IE11 Preview Bug Bounty.
Microsoft declined to go into any details about the new mitigation bypass technique Forshaw uncovered until it has addressed the attack. Microsoft says that it will be able to better protect customers by creating new defenses for future versions of its products.
Microsoft did note that one of its engineers named Thomas Garnier had also discovered a variant of this attack technique.
Despite this revelation, Microsoft says that it decided to get the full $100,000 to Forshaw. Microsoft says that it pays so much more for new attack techniques versus discovery of individual bugs because new mitigation bypass techniques allow Microsoft to develop defenses against an entire class of attack.
Microsoft said, "The reason we pay so much more for a new attack technique versus for an individual bug is that learning about new mitigation bypass techniques helps us develop defenses against entire classes of attack. This knowledge helps us make individual vulnerabilities less useful when attackers try to use them against customers. When we strengthen the platform-wide mitigations, we make it harder to exploit bugs in all software that runs on our platform, not just Microsoft applications."
Microsoft has paid out over $128,000 in its bug bounty programs so far. Interestingly, Forshaw has earned $109,400 of that total payout.
This article is over a month old, voting and posting comments is disabled
10/9/2013 4:14:22 PM
I love how he's received "the vast majority" of their bug bounty payouts, 109,000 out of 125,000. But according to the source article those numbers include the 100,000 he just earned. So yeah... of course he has received the majority, he just received 4x more than the program had paid out to date.
So, saying they should just hire him... well, look at it this way. If he hadn't found the vulnerability they wouldn't have had to pay him. If he's on the payroll they're out at least 6 figures each and every year regardless of if he finds something or not.
"Google fired a shot heard 'round the world, and now a second American company has answered the call to defend the rights of the Chinese people." -- Rep. Christopher H. Smith (R-N.J.)
Windows 10 on Raspberry Pi, IoT Devices Sees Developer Debut
August 12, 2015, 2:41 PM
Sony Issues Bizzare "Do Not Update" Edict to VAIO PC Owners
August 11, 2015, 9:42 PM
Report: Over 25 Million Devices Upgraded to Windows 10... or Was It 67 Million?
August 7, 2015, 3:24 PM
EA Set to Milk the Star Wars Cash Cow w/ Video Games
July 31, 2015, 12:36 PM
Windows 10 to Get New Features in October Service Release 2 (SR2)
July 30, 2015, 5:50 PM
Nintendo CEO Satoru Iwata's Passing Gives the Internet the Feels
July 14, 2015, 4:48 PM
Most Popular Articles
Worth the Wait? Microsoft Teases at Windows 10 Flagship Phones to Air Oct. 6
September 15, 2015, 5:13 PM
Apple's First Fixes to iOS 9 Land w/ iOS 9.0.1 Release
September 23, 2015, 6:11 PM
Breaking Bad: How to Crash Google's Chrome Browser With Just 8 Characters
September 23, 2015, 11:08 AM
Apple Watch Commands 2 in 3 Smart Watch Sales, WatchOS 2 Sweetens the Pitch
September 20, 2015, 6:07 PM
Fakebook Pt. I: From "The Chive" to "AskMen"; How Facebook's Phonies are Born and Used
September 15, 2015, 4:00 AM
Latest Blog Posts
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
More Blog Posts
Copyright 2015 DailyTech LLC. -
Terms, Conditions & Privacy Information