All the latest UK technology news, reviews and analysis

Microsoft will not pay bounties to bug hunters

by Dave Neal

More from this author

23 Jul 2010

Be the first to comment

  • Tweet this
Microsoft
Microsoft chooses to reward security researchers with kindness, not cash

Unlike its peers, Microsoft will not pay security researchers a reward for bringing bugs to its attention.

Google and Mozilla have both increased their bounties this month, each offering approximately £2,000 for alerts about the most critical flaws.

In a blog post released this week, Microsoft said that it regularly tackles questions about whether it should pay rewards when people point them out to it, but explained that it chooses to reward them in non-monetary ways.

"At Microsoft we recognise, and appreciate, the unique value that security researchers play in identifying issues and helping the entire computing ecosystem improve from a security perspective," the firm said, before skirting the cash question with the suggestion that it compensates these researchers in other ways.

"Throughout the years we've seen researchers saying that, if vendors really valued their work, we'd compensate them directly for the vulnerabilities they discover. That's a trend that's continued in recent weeks. We absolutely value the researcher ecosystem, and show that in a variety of ways."

There is an argument that the firm could not afford to pay out on all the bugs that people report to it. And indeed, the team posted about the sheer weight of emails it gets on the subject.

The Microsoft Security Response Center (MSRC) receives more than 100,000 email messages per year, according to the post. That is roughly 275 a day or 11 an hour. Although some of these will be found to be unproved, the team explained that it filters these reports down to 1,000 investigations a year.

One of the ways that Microsoft rewards the security community is through events, and indeed it is a sponsor of the Black Hat security conference.

In the run up to the event, which takes place next week in Las Vegas, the MSRC team reflected on the way it manages bug alerts and deals with them.

Reacting, in advance, to criticisms that the firm is slow to react to problems, whether self-discovered or alerted to them, the team noted: "Some will say that we take too long to fix our vulnerabilities. But it isn't all about time-to-fix.

"Our chief priority with respect to security updates is to minimise disruption to our customers and to help protect them from online criminal attackers."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Workflow Development Team Lead

A Workflow Development Team Leader with a good knowledge...

Senior SQL Developer SSIS SSRS £500pd

Senior SQL Developer Investment Banking SSIS SSRS T-SQL...

Business Analyst Financial Services

Business Analyst Financial Services, SQL (Business analysis...

Junior/Graduate IT Support, Financial Services

Junior/Graduate IT Support, Financial Services (Networks...

To send to more than one email address, simply separate each address with a comma.