Skip to main content

Microsoft still bucks bug bounty trend

posted onJuly 2, 2012
by l33tdawg

The richest and biggest software company in the world still won’t pay researchers for disclosing vulnerabilities despite a growing number of its peers opting to do so.

Microsoft thinks bug bounties are superfluous: its Microsoft Security Response Centre (MSRC) team were constantly inundated with free vulnerability reports from researchers looking for fame, not fortune.

Up to 80 percent of Microsoft vulnerabilities were privately and freely reported. Researchers had a variety of motivations behind reporting bugs and money was not necessarily chief among them, Microsoft security boss Mike Reavey said. “I don’t think that filing and rewarding point issues is a long-term strategy to protect customers," he said.

Source

Tags

Microsoft Security Industry News

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th