>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
aw4rzs 10 hours ago [-]
They should have paid him at least a $1 million bounty if they're going to ask for editorial control of the disclosure.
rkagerer 14 hours ago [-]
Love to hear more on the motivation for agreeing to this.
e.g. The $5000? Amnesty from being sued?
mikeryan 10 hours ago [-]
Sounds like he’s gotten bug bounties from MS in the past. Might be forward thinking to keep the relationship amicable going forward.
Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.
And he’s 16. Parents might have had a say.
srdjanr 14 hours ago [-]
Also he's 16. I'd definitely be less willing to push back (especially on something like this) at his age
0x1ch 11 hours ago [-]
At that age in the mid 2000s, I would be foaming at the mouth to tell a FANG company to eat dirt over something like a disclosure + unpaid bounty. But if he got the money and didn't negotiate... You live and you learn.
xeromal 8 hours ago [-]
iamverybadass
0x1ch 7 hours ago [-]
Well yeah. Why else would you tell off a massive company in the FANG circle as a budding security researcher in their teens.
drfloyd51 7 hours ago [-]
A good move is to negotiate in good faith. You show you can’t be pushed around and you are able to be civil. And most importantly, you know your worth.
1 hours ago [-]
p-e-w 13 hours ago [-]
Of course not. You don’t push back on something like that. You hire a lawyer and let them do the pushing for you. If you contact the right NGO, they might even give you one for free.
There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.
saghm 12 hours ago [-]
I don't know about you, but when I was 16, I never hired a lawyer, and none of the other 16 year olds I knew had either
snapplebobapple 12 hours ago [-]
I've seen hackers. Even if you do it right you're still going to get banned from the internet till you are 18 and dating Angelina Jolie is not the draw it was 20 years ago....
stronglikedan 11 hours ago [-]
> dating Angelina Jolie is not the draw it was 20 years ago....
not not either. where do I sign up?
eecc 10 hours ago [-]
She’s glorious in the movie, though she does play the part of an extremely high maintenance woman uncannily well…
dfxm12 10 hours ago [-]
There are so many great one liners in that move. An underrated one is when Dade's mom opens the door, sees Acid Burn and says "now I see what all the fuss is about".
patmorgan23 9 hours ago [-]
I mean when you're sixteen, you can sign a legally binding contract (might depend on the jurisdiction). Usually you have to be above the age of majority (18) or be emancipated before you can enter into a binding contract.
icantevenhold 14 hours ago [-]
Not getting your life ruined by getting sued by a trillion dollar company sounds like a pretty good motivation
whatsdowndog 6 hours ago [-]
[dead]
menomatter 11 hours ago [-]
Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed.
I wonder what’s the consensus on this? Do people normally report it or not?
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
SahAssar 11 hours ago [-]
I think my take would be to report it anonymously (via support/marketing/etc.) and in the report strongly encourage them to create a path for security reports (either via a bounty or just a security email). When fixed or actually dismissed post publicly on anonymous channels, with a section saying how they could have created a channel for these reports.
john_strinlai 11 hours ago [-]
>Do people normally report it or not?
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.
menomatter 11 hours ago [-]
My issue was knowing that reporting would allow them to possibly discover my identity. Discovering the vul in itself may instead be considered unauthorized access.
Computer0 11 hours ago [-]
don't worry you are popular with me
john_strinlai 12 hours ago [-]
i think the answer is simple: they're a kid, and microsoft bullied them.
igleria 14 hours ago [-]
reminds me of a former job in which my goodbye letter was heavily editorialized...
the__alchemist 13 hours ago [-]
Would love to hear more.
ceroxylon 12 hours ago [-]
I will tell my story: I found a huge accounting error that allowed for several employees to embezzle funds. I disclosed it to the main stakeholders and some people went to jail. The accounting team still refused to acknowledge that the mistake was theirs, so I left on principle.
A few weeks later, I was talking to an old colleague and they revealed that the story that came from stakeholders was that the accounting team found the error, and I left in disgrace (despite that not being my department?).
So if you find an embarrassing mistake and you do not control the narrative, you have to proceed very carefully.
sdcfgy 11 hours ago [-]
Had one like that. I quit and they blamed me for a project failure after the fact. That pissed off a couple of colleagues who thought it might happen to them. They also quit leaving them entirely without a software team. Set them back ten years because they didn’t make the market in time.
Write everything down and make sure everyone knows you’re writing it down. Saves a lot of hassle like that.
itslennysfault 11 hours ago [-]
> the story that came from stakeholders was that the accounting team found the error, and I left in disgrace (despite that not being my department?).
That sounds like defamation to me.
xyst 10 hours ago [-]
_I am jack's complete lack of surprise_
This is a company that has engaged in heavy monopolistic behavior and violating US anti-trust laws with reckless abandon. They have even pioneered the infamous "embrace, extend, extinguish" strategy.
M$ will never change. The modus operandi is always the same, regardless of which ever lame MBA douchebag is running the shit show.
If we want to actually care , rather than spew off platitudes, break up big tech.
iwontberude 8 hours ago [-]
[dead]
sdfhbdf 15 hours ago [-]
> awarded $5000
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
Every HN post regarding security exploits inevitably results in some comment saying the bounty is too low. I find it helpful to read previous comments by tptacek regarding bug bounties and market values:
This is correct. I've made well over six figures over the last couple of years through bug bounty programs. I wouldn't spend months finding one bug. It's usually days or a week or two max.
$5,000 is actually pretty normal for a critical. I think the most I received for one bug was around $10,000, but this is the exception.
AI has also ruined the market. I'm a security consultant (where I make most of my money) and stopped bug bounty once AI slop reports made it impossible to actually get anything triaged in a timely manner.
Something else many don't know is that with all of the major platforms, customers can see the bugs before they are even triaged by the platform team. Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It's then marked as a duplicate and the researcher gets nothing.
rnxrx 4 hours ago [-]
$5K seems like an absolute steal compared to paying contracted security experts to find such bugs. I'm surprised these programs aren't pushed harder, as the potential ROI seems fantastic.
msdz 10 hours ago [-]
> Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It's then marked as a duplicate and the researcher gets nothing.
Isn’t that just a speedrun-encouragement for selling the exploit not to the one offering the product, but an attacker offering more (in this case, >$0 is not difficult to exceed) instead?
dfxm12 10 hours ago [-]
If money is your motivation, you probably wouldn't consider disclosing the bugs in the first place.
xnickb 8 hours ago [-]
If there was an easy way to extract value out of any particular kind of a vulnerability, it'd cost much more and thus the bounty would've been higher.
physicallyIllfr 11 hours ago [-]
[dead]
asaddhamani 35 minutes ago [-]
I find it perplexing and stingy. Such a bug would likely fetch tens, hundreds of times more on the grey market. Why would anyone not just sell it there? $5000 for trillions of exposed records with PII from Microsoft is a joke.
muglug 15 hours ago [-]
As I understand it, bug bounty awards are a rough proxy for "would nation-state actors be able to exploit this for operational purposes without getting caught".
Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.
yieldcrv 13 hours ago [-]
thats the true market value of bug bounty awards
the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability
buckle8017 14 hours ago [-]
Try 10-20 million USD for a zero click iPhone exploit.
bix6 14 hours ago [-]
$5k is a literal penny for Microsoft. Give the kid $100k.
k2xl 14 hours ago [-]
Per their market cap...
3.85 billion is actually closer to a "penny" for Microsoft.
poly2it 14 hours ago [-]
Operating income for Microsoft was $128.5 billion in 2025.
I think HN, like a lot of people in this industry, have strongly skewed perception of the actual importance of these bugs.
You could view the bounty prices as market evidence that most of this is rightfully treated as nothingburgers. I.e. the alternative to paying $5000 to some random person for this class of vulnerability research is not risking a trillion dollar hack the next day - it's just risking shmaybe some kerfuffle down the line, followed by fixing it through normal triage process. The bounty program is as much marketing as security, and $5000 is probably about the right price for marginal effort into sustaining the "we are treating security seriously" message.
In a way, the very existence of those bug bounty programs in large companies is evidence they don't see a reason to treat vulnerabilities seriously enough to proactively find and fix them in-house.
If security vulnerabilities would be anywhere serious as most commenters on-line seem to think, companies would pay hundreds of thousands for serious vulnerabilities, just to save a day before they get hit by them - on top of spending millions in-house to try and stay ahead of the attackers.
But they don't. Because most exploits are inconsequential and/or aren't being exploited much.
TedDoesntTalk 5 hours ago [-]
Some do pay that kind of money. You just don’t hear about those, and there’s certainly no blog posts about them.
julianeon 9 hours ago [-]
I personally think it sets a bad precedent: you want to broadcast that valuable info will be treated as such. A hacker in the future will see this, compare the "precedent" price to the black market, and not even ask Microsoft the next time.
keithnz 5 hours ago [-]
many of these people want to work in security, selling to the black market will legally and professionally screw you.
skeptic_ai 38 minutes ago [-]
If you sell for crypto how will ruin your reputation? I doubt anyone using real names and bank accounts
Perz1val 14 hours ago [-]
Microsoft's bounty program and payouts are known to be pathetic, see that nightmare eclipse situation
xyst 10 hours ago [-]
The young researcher is a teenager. Getting your name out there, clout/influence/fame, is worth $1M to them.
It’s almost like most of you people have already forgotten your teenage years. And it shows. Doesn’t matter the decade or generation. A teenager , likely living with parents or grandparents, will always prioritize intangibles.
A mere 5 bands for full editorial control is quite literally peanuts for M$. It’s yet another case of abusing free labor, unfortunately.
xnyan 8 hours ago [-]
> quite literally peanuts
If I have an income of $250k/yr and a pack of peanuts costs $2 or very roughly 0.001% of my annual income, the equivalent peanut money for ~$130 billion a year microsoft would be more like $2 million.
giancarlostoro 12 hours ago [-]
What's worse is the alternative is winding up like Aaron Swartz... (all he did was scrape PDFs for mostly public funded / tax funded papers) Which is even worse, I think I'd be glad to receive $20 for Starbucks instead of being legally chased for showing them they messed up.
There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued.
elmer2 12 hours ago [-]
"all he did was scrape PDFs for mostly public funded / tax funded papers"
He wasn't a security researcher. He broke into a room and used equipment to steal information. It wasn't just 'tax funded papers'. Companies invested millions of dollars into some of this research.
We shouldn't support theft and he should have gotten some jail time/punishment for it.
"There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued."
Too many 'security researchers' demand money or threaten to release the vulnerabilities.
I don't know anyone that got into trouble going through a legit bug bounty program.
latexr 57 minutes ago [-]
> he should have gotten some jail time/punishment for it.
He was intimidated to the point of suicide, and somehow you don’t think that’s punishment enough?
thereader12 12 hours ago [-]
I have not done a deep dive so I could be wrong, weren't these papers published (or soon to be)? Wasn't the one and only group with negative effects the Journals that could extract a fee? Especially with researchers usually happy to send a copy? This wasn't someone stealing trade secrets they weren't even secret.
mosseater 6 hours ago [-]
It was a protest against the monetization of academic knowledge.
You can call that "theft" as much as you want. There are lots of people like Aaron out there that think this sort of information should be freely available.
Just because there is a law doesn't mean that that law is just and correct. Saying we "shouldn't support theft" is an over-simplification of the situation.
throwaway2037 14 hours ago [-]
> Hey! I’m Faav. A little over a year ago, when I was 15, I published Break into any Microsoft building: Leaking PII in Microsoft Guest Check-In, my first Microsoft write-up. I’m 16 now, and this one is a little bigger.
Damn, these guys got schooled by a 15 year old! Say less...
bsoqk 14 hours ago [-]
You assume that whoever was responsible for the implementation of this feature cares in the slightest beyond “it seems to work”.
lurk2 13 hours ago [-]
His comment didn’t assume that at all.
bsoqk 7 hours ago [-]
It’s the way I interpreted the “got schooled” part. If you don’t try your best, or in fact do the bare minimum, if someone beats you they can’t say they “schooled” you.
ocdtrekkie 12 hours ago [-]
Physical security vendors usually stop exactly there. I can't count how many vendors responsible for badge systems shut off the Windows Firewall just because it’s easier than adding a rule.
ToucanLoucan 13 hours ago [-]
Honestly that series of blog posts that came across here semi-recently about what an utter disaster the Azure team is (through little fault of their own, mind you), combined with a lot of things I've read about the development behind Halo Infinite, have convinced me Microsoft is to avoided whenever possible. It's not even that they're too big to care, though that is an issue. It's that organizationally they are SO reliant on short-term contractors and junior devs plugging away with copilot, along with an ever more exhausted group of seniors who actually work for them but are continually disempowered, that I think it's safe to say anything they manage to ship is a minor miracle if it works at all, and it's certainly not going to have any guarantee at all of solid software engineering fundamentals.
And to be clear, this is not an issue with them using contractors, overseas or otherwise, or with their senior dev staff, or even with AI really. It's an issue with them organizationally being so incredibly penny-pinching, and so dedicated to shipping new shit versus fixing anything long term, constantly chasing new revenue and letting their existing offerings rot.
If a Microsoft product is good nowadays, it is literally a miracle.
TeMPOraL 12 hours ago [-]
You assume there is any actual reason to care more than that in this case.
verst 14 hours ago [-]
There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.
jhfdbkofdchk 14 hours ago [-]
There is so much work to do for SFI that is still being ignored. The only way that some of these services will update is by being the target of the red team, security researcher, or threat actor.
verst 14 hours ago [-]
And all of that is definitely happening.
That being said, just last night I observed that the identity team is now opening up agent-assisted PRs against individual service team repos to force MISE adoption and upgrade to the latest version and best practices.
I think that's a great thing because many individual service teams simply lack the bandwidth or knowledge. Prior to GenAI availability I wasted many cycles on this kind of work. While GenAI made it easier - internal source documentation still does not unambiguously address every use case. So having the identity team drive this now with the help of agent sessions initiated by them is great.
rdtsc 14 hours ago [-]
> {"alg":"none","typ":"JWT"}
I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.
flowerlad 13 hours ago [-]
It should be retroactively removed the spec, and all implementations should remove the "none" algorithm. It is a huge security hole.
pixl97 13 hours ago [-]
Yea, and it was a big issue years ago. I can't believe there is any modern implementation that has it.... or another way to put this is, how old is this damned implementation they are using?
huflungdung 11 hours ago [-]
[dead]
er0k 15 hours ago [-]
wow I am so surprised to hear once again how JWTs are terrible
Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.
meindnoch 14 hours ago [-]
They did verify the signature, and it was correct according to the "none" algorithm.
fabian2k 13 hours ago [-]
Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it.
alex_suzuki 14 hours ago [-]
“Works as designed.”
buckle8017 14 hours ago [-]
JWT is complicated.
Complexity is a spec failure in security issues.
It's that simple.
talon8635 14 hours ago [-]
Does this extend to OIDC? I’m not knowledgeable on the topic but it uses JWT right? Is it also prone to poor implementation? If you just error on alg=none does that solve it?
skhameneh 14 hours ago [-]
Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem.
I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.
The fact that mistakes are so easy to make is indicative of poor design in the spec itself.
Perz1val 14 hours ago [-]
Idk if that's not too much of an oversimplification, maybe more like JWTs are an indicator/enabler of architecture level bugs?
kmoser 2 hours ago [-]
Even more impressive to me than finding the bug is the clear way the article was written. Even if they used AI to write it (which I don't think they did), it reveals an incredible maturity and ability to communicate a complex topic.
f311a 15 hours ago [-]
What is Antares? Can't find anything related to it except for the 1B model, which does not seem to be capable of autoresearch.
UPD: It's his personal bot.
Alifatisk 14 hours ago [-]
> I also started building AI into how I hunt, which led me to develop Antares, my personal AI hackbot.
Guess everything is just going to be named after stars for awhile.
DaiPlusPlus 2 hours ago [-]
Antares is also the internal name of Azure App Services platform/infra.
aghuang 39 minutes ago [-]
What was the process in this?
FlameWolf 3 hours ago [-]
> I pulled 2023 snapshots of Titan’s login and privacy pages from the Wayback Machine
Great, give them one more reason to attack WBM.
Sytten 3 hours ago [-]
Always happy when I see software I built being used to hack cool targets. Very nice finding!
khalic 15 hours ago [-]
You’re going places kid :) keep up the good work
matroxmemories 15 hours ago [-]
Possibly jail if the wrong people get upset.
bix6 14 hours ago [-]
Well college isn’t worth it according to the Thiel crowd so maybe this will be better.
Waterluvian 14 hours ago [-]
Great way to use up that 6-10 years of vacation and sabbatical time.
zk 9 hours ago [-]
The kicker... only 5k reward for this is insane. That said probably the attacker didn't need to run as many queries as they did...
09/17/26 - Awarded $5,000
hmokiguess 4 hours ago [-]
How many times has Microsoft gone through this? I feel like I remember a similar one with Active Directory a few years back.
moat 13 hours ago [-]
This kid is 16?
Can’t wait to see what he’s up to in 10 years.
Ylpertnodi 5 hours ago [-]
Ai.
Saving us from.
charcircuit 10 hours ago [-]
Seriously, who is responsible for "none" JWT tokens. It has caused so many critical security bugs over the years.
froggertoaster 11 hours ago [-]
Geohot vibes
sdcfgy 15 hours ago [-]
Wait until someone does that to your favourite cloud provider's customer data.
ocdtrekkie 10 hours ago [-]
Entra has already had vulnerabilities where a user in one tenant could access global admin of every other tenant. Somehow everyone didn't immediately move off Microsoft's cloud platforms.
jdw64 8 hours ago [-]
I wish I had that kind of talent when I was 16 too... I'm jealous.
And it's really amazing. I wish I could think like that, and it's impressive how deeply you immerse yourself in it.
gnarlouse 13 hours ago [-]
If a 15yo can find it
darepublic 8 hours ago [-]
> I’m 16 now, and this one is a little bigger.
Holy! Child prodigy
9 hours ago [-]
nenadg 13 hours ago [-]
You should have.
advael 13 hours ago [-]
This is a pretty typical example of the security posture of microsoft, and yet people continually buy their arguments that open-source and therefore auditable alternatives are inherently less secure than their "trust me bro"
starkeeper 12 hours ago [-]
Only $5K when you saved them millions. Pretty cheap!
sophietaylor 14 hours ago [-]
[flagged]
huflungdung 11 hours ago [-]
[dead]
ltbarcly3 15 hours ago [-]
[flagged]
t-writescode 15 hours ago [-]
That.. looks like a normal sentence to me, and very probably one of the ones Microsoft required they add.
Did you give the article a once-over beyond that? It’s one of the decidedly not-AI lines.
ltbarcly3 15 hours ago [-]
Prefixing saying something with "Two quick notes first" is extremely common AI meta commentary. You may be right that it is something Microsoft insisted he put at the top, which would also explain the weird style.
functionmouse 15 hours ago [-]
From where do you think AI learned that?
ltbarcly3 12 hours ago [-]
Learning a phrase from humans doesn’t prevent a model from overusing it or making it a recognizable stylistic habit.
vonneumannstan 15 hours ago [-]
Weird user preferences during RLHF. Also how we got bulleted lists and emojis everywhere.
Forgeties79 15 hours ago [-]
All AI semantic tendencies were “learned” from us. That doesn’t change anything.
0x_rs 15 hours ago [-]
It's not a "normal" sentence and is quite clearly produced by an LLM, it's a typical Claudeism so probably that. The entire post is also flagged by Pangram, so OP is correct.
encom 9 hours ago [-]
> microsoft authored post
> clickbait headline
> slop writing
> some kid
Yea it's another bullshit post on the front page.
eviks 14 hours ago [-]
All of the above, though mostly the last one.
gosub100 14 hours ago [-]
Explain why easily 40% of HN posts are about AI, and when people actually _use_ AI for this task, they are vilified for (allegedly) using it.
bix6 14 hours ago [-]
He’s fine to use the AI for bug hunting but nobody wants to read AI’s bullshit slop and tone
icantevenhold 14 hours ago [-]
I’m as tired of slopped up text as the next person but the example OP gave really isn’t that bad
13 hours ago [-]
ltbarcly3 12 hours ago [-]
[flagged]
ltbarcly3 12 hours ago [-]
I pasted the thread into ChatGPT and here is what it would like to tell you:
The comment explicitly says, “I am the last person to judge someone for using AI to help them write a blog post.” The criticism is about the quality of the published prose and whether anyone reviewed it before putting their name on it.
You can dispute whether that sentence is bad or whether it indicates AI authorship. But “why criticize unedited AI prose when HN talks about AI so much?” doesn’t identify a contradiction. Discussing a technology doesn’t imply endorsing every use of it, and criticizing its output isn’t the same as vilifying someone for using it.
— GPT-6.1 Sol
Kuyawa 15 hours ago [-]
Next time you find a bug like that, offer it to the black market, you could make millions instead of measly salty peanuts
sdcfgy 15 hours ago [-]
I bet someone already did that and didn't disclose it.
arm32 14 hours ago [-]
Now some blackhat somewhere can't afford their monthly Lamborghini payment.
Rendered at 06:27:52 GMT+0000 (UTC) with Wasmer Edge.
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
e.g. The $5000? Amnesty from being sued?
Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.
And he’s 16. Parents might have had a say.
There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.
not not either. where do I sign up?
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.
A few weeks later, I was talking to an old colleague and they revealed that the story that came from stakeholders was that the accounting team found the error, and I left in disgrace (despite that not being my department?).
So if you find an embarrassing mistake and you do not control the narrative, you have to proceed very carefully.
Write everything down and make sure everyone knows you’re writing it down. Saves a lot of hassle like that.
That sounds like defamation to me.
This is a company that has engaged in heavy monopolistic behavior and violating US anti-trust laws with reckless abandon. They have even pioneered the infamous "embrace, extend, extinguish" strategy.
M$ will never change. The modus operandi is always the same, regardless of which ever lame MBA douchebag is running the shit show.
If we want to actually care , rather than spew off platitudes, break up big tech.
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What does HN think? Why would it be only $5000?
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
This one probably has the best summary:
https://news.ycombinator.com/item?id=43025038
$5,000 is actually pretty normal for a critical. I think the most I received for one bug was around $10,000, but this is the exception.
AI has also ruined the market. I'm a security consultant (where I make most of my money) and stopped bug bounty once AI slop reports made it impossible to actually get anything triaged in a timely manner.
Something else many don't know is that with all of the major platforms, customers can see the bugs before they are even triaged by the platform team. Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It's then marked as a duplicate and the researcher gets nothing.
Isn’t that just a speedrun-encouragement for selling the exploit not to the one offering the product, but an attacker offering more (in this case, >$0 is not difficult to exceed) instead?
Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.
the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability
3.85 billion is actually closer to a "penny" for Microsoft.
https://www.microsoft.com/investor/reports/ar25/index.html
You could view the bounty prices as market evidence that most of this is rightfully treated as nothingburgers. I.e. the alternative to paying $5000 to some random person for this class of vulnerability research is not risking a trillion dollar hack the next day - it's just risking shmaybe some kerfuffle down the line, followed by fixing it through normal triage process. The bounty program is as much marketing as security, and $5000 is probably about the right price for marginal effort into sustaining the "we are treating security seriously" message.
In a way, the very existence of those bug bounty programs in large companies is evidence they don't see a reason to treat vulnerabilities seriously enough to proactively find and fix them in-house.
If security vulnerabilities would be anywhere serious as most commenters on-line seem to think, companies would pay hundreds of thousands for serious vulnerabilities, just to save a day before they get hit by them - on top of spending millions in-house to try and stay ahead of the attackers.
But they don't. Because most exploits are inconsequential and/or aren't being exploited much.
It’s almost like most of you people have already forgotten your teenage years. And it shows. Doesn’t matter the decade or generation. A teenager , likely living with parents or grandparents, will always prioritize intangibles.
A mere 5 bands for full editorial control is quite literally peanuts for M$. It’s yet another case of abusing free labor, unfortunately.
If I have an income of $250k/yr and a pack of peanuts costs $2 or very roughly 0.001% of my annual income, the equivalent peanut money for ~$130 billion a year microsoft would be more like $2 million.
There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued.
He wasn't a security researcher. He broke into a room and used equipment to steal information. It wasn't just 'tax funded papers'. Companies invested millions of dollars into some of this research.
We shouldn't support theft and he should have gotten some jail time/punishment for it.
"There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued."
Too many 'security researchers' demand money or threaten to release the vulnerabilities.
I don't know anyone that got into trouble going through a legit bug bounty program.
He was intimidated to the point of suicide, and somehow you don’t think that’s punishment enough?
You can call that "theft" as much as you want. There are lots of people like Aaron out there that think this sort of information should be freely available.
Just because there is a law doesn't mean that that law is just and correct. Saying we "shouldn't support theft" is an over-simplification of the situation.
And to be clear, this is not an issue with them using contractors, overseas or otherwise, or with their senior dev staff, or even with AI really. It's an issue with them organizationally being so incredibly penny-pinching, and so dedicated to shipping new shit versus fixing anything long term, constantly chasing new revenue and letting their existing offerings rot.
If a Microsoft product is good nowadays, it is literally a miracle.
That being said, just last night I observed that the identity team is now opening up agent-assisted PRs against individual service team repos to force MISE adoption and upgrade to the latest version and best practices. I think that's a great thing because many individual service teams simply lack the bandwidth or knowledge. Prior to GenAI availability I wasted many cycles on this kind of work. While GenAI made it easier - internal source documentation still does not unambiguously address every use case. So having the identity team drive this now with the help of agent sessions initiated by them is great.
I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.
https://www.howmanydayssinceajwtalgnonevuln.com/
Complexity is a spec failure in security issues.
It's that simple.
I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.
The fact that mistakes are so easy to make is indicative of poor design in the spec itself.
UPD: It's his personal bot.
Guess everything is just going to be named after stars for awhile.
Great, give them one more reason to attack WBM.
09/17/26 - Awarded $5,000
Can’t wait to see what he’s up to in 10 years.
And it's really amazing. I wish I could think like that, and it's impressive how deeply you immerse yourself in it.
Holy! Child prodigy
Did you give the article a once-over beyond that? It’s one of the decidedly not-AI lines.
The comment explicitly says, “I am the last person to judge someone for using AI to help them write a blog post.” The criticism is about the quality of the published prose and whether anyone reviewed it before putting their name on it.
You can dispute whether that sentence is bad or whether it indicates AI authorship. But “why criticize unedited AI prose when HN talks about AI so much?” doesn’t identify a contradiction. Discussing a technology doesn’t imply endorsing every use of it, and criticizing its output isn’t the same as vilifying someone for using it.
— GPT-6.1 Sol