Microsoft's Bug Bounty Betrayal Puts Everyone in Danger
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Microsoft's handling of security researcher Nightmare Eclipse has sparked controversy over its bug bounty program and coordinated vulnerability disclosure (CVD) practices. After Microsoft allegedly ignored submitted vulnerabilities in Defender and BitLocker, banned the researcher's reporting account, and failed to pay out, the researcher published proof-of-concept exploits publicly on GitHub. Microsoft then had both the GitHub and GitLab accounts removed. The post argues that Microsoft's implied legal threats against uncoordinated disclosure are eroding trust with the security research community, which could push talented researchers to sell exploits on dark web markets instead of reporting them responsibly. The broader concern is that undermining the bug bounty ecosystem makes widely-used software less secure for everyone.
•10m watch time
206 Impressions1 Comment