Microsoft Awards First $100,000 Bug Bounty to Security Researcher
October 9, 2013 10:29 AM
comment(s) - last by
The same security researcher has earned the vast majority of all Microsoft payouts for bugs
Microsoft has announced that it awarded its first $100,000 bounty to a security researcher named James Forshaw. Forshaw is a security vulnerability researcher with Context Information Security and had previously found design level bugs during the IE11 Preview Bug Bounty.
Microsoft declined to go into any details about the new mitigation bypass technique Forshaw uncovered until it has addressed the attack. Microsoft says that it will be able to better protect customers by creating new defenses for future versions of its products.
Microsoft did note that one of its engineers named Thomas Garnier had also discovered a variant of this attack technique.
Despite this revelation, Microsoft says that it decided to get the full $100,000 to Forshaw. Microsoft says that it pays so much more for new attack techniques versus discovery of individual bugs because new mitigation bypass techniques allow Microsoft to develop defenses against an entire class of attack.
Microsoft said, "The reason we pay so much more for a new attack technique versus for an individual bug is that learning about new mitigation bypass techniques helps us develop defenses against entire classes of attack. This knowledge helps us make individual vulnerabilities less useful when attackers try to use them against customers. When we strengthen the platform-wide mitigations, we make it harder to exploit bugs in all software that runs on our platform, not just Microsoft applications."
Microsoft has paid out over $128,000 in its bug bounty programs so far. Interestingly, Forshaw has earned $109,400 of that total payout.
This article is over a month old, voting and posting comments is disabled
10/11/2013 11:21:11 PM
His middle name is Bob.
"It seems as though my state-funded math degree has failed me. Let the lashings commence." -- DailyTech Editor-in-Chief Kristopher Kubicki
Apple Releases iOS 8.1; Adds Apple Pay Support, SMS Relay, Instant Hotspot
October 20, 2014, 1:00 PM
Quick Note: Android Gmail App to Gain Yahoo, Outlook Account Support
October 20, 2014, 9:15 AM
Sony Gets With the Program, Pledges to Update Entire Xperia Z Lineup to “Lollipop”
October 17, 2014, 9:28 AM
HP webOS Support, Cloud Services to Go Offline on January 15, 2015
October 16, 2014, 12:29 PM
Windows 10 Technical Preview: Over One Million Testers and Counting
October 13, 2014, 4:41 PM
Update: Apple Confirms October 16 Event for New Hardware, Software
October 8, 2014, 2:29 PM
Most Popular Articles
Cool Science Video of the Day: Carnivorous Leech Eats Giant Jungle Worm
October 16, 2014, 6:44 PM
Chinese Government Declares Digital War Against America's Top Tech Firms
October 20, 2014, 12:07 PM
PS4 "Masamune" Update 2.0 Will Bring New Music and Customization Features
October 17, 2014, 1:05 PM
HBO, CBS Lead Charge to Ditch Cable
October 16, 2014, 4:40 PM
Update: Motorola Droid Turbo Coming Oct 28, 48-hour Battery Life Confirmed
October 19, 2014, 9:19 PM
Latest Blog Posts
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information