Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Microsoft: Reckon our code is crap? Prove it and $30k could be yours (Edge Bug Bounty Program)
The Register ^ | Aug 21, 2019 | Richard Speed

Posted on 08/21/2019 9:03:52 PM PDT by dayglored

Doors on the Edge Insider Bounty Program flung open

Having finally pushed out the first Beta preview of its Chromium-based browser, Microsoft has launched a bounty programme aimed at getting researchers to kick the tyres on its latest and greatest.

Up to $30k is available to researchers who find what Microsoft deems "critical and important" vulnerabilities in the Beta and Dev channels of Chromium Edge. The Canary channel is excluded because, well, it seems hardly fair to poke holes in daily builds that are, by definition, not fit for public consumption.

Interestingly, up to $15k is available to anyone who discovers critical remote code execution and "design issues" in the original EdgeHTML version still lurking in the Slow Ring of the Windows 10 Insider Preview.

Just think, if a few dozen researchers are lured by that $15k, it could double the not-just-downloading-Chrome usage of old Edge overnight.

Snark aside, Microsoft really wants researchers to start thumping Chromium Edge, and has stated that a 2X multiplier is available via the Researcher Recognition Program and the company will pay out as soon the reproduction and assessment has been completed of each submission.

Of course, with Edge being Chromium-based, Chrome's own reward programme is a consideration, so Microsoft is keen on reports that reproduce on Edge rather than Chrome. Severity, impact and "report quality" are also factors, so "Yo browser sucks, Micro$oft" is unlikely to go down well.

Microsoft is also looking for reports from macOS Edge users in addition to those running the browser on fully patched versions of Windows 7 SP1 and 8.1.

It isn't clear what that means after January 2020, when poor old Windows 7 is due a visit from an engineer in a high-viz jacket, carrying an axe. ®


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: bugbounty; chrome; chromium; chromiumedge; edge; microsloth; microsoft; onetokeovertheline; windowspinglist
Navigation: use the links below to view more comments.
first 1-2021-23 next last
C'mon, Windows FReepers, let's go get them nasty bugs!
1 posted on 08/21/2019 9:03:52 PM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; bajabaja; ...
Edge Bug Chasers ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 08/21/2019 9:04:22 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
"Up to" $30,000.

"Up to."

"For the 300 hours you devoted to finding this exploit, and considering your 25 years of coding experience, Microsoft is prepared to pay you... Well, let's see, how about $1,000? That seems fair to us."

3 posted on 08/21/2019 9:20:00 PM PDT by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Their code is crap.


4 posted on 08/21/2019 9:25:14 PM PDT by mylife (The Roar Of The Masses Could Be Farts)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Microsoft Coders: “I’m gonna write me a new mini-van!”


5 posted on 08/21/2019 9:32:48 PM PDT by dfwgator (Endut! Hoch Hech!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I’d have to load Edge in order to find the bugs in it, which is kinda like having to get the clap in order to prove a woman is a hooker.


6 posted on 08/21/2019 9:36:42 PM PDT by bigbob (Trust Trump. Trust the Plan.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

That’s a crazy low amount, even if they expect 10-year-olds to find the bugs.


7 posted on 08/21/2019 9:53:41 PM PDT by Veto! (Veto! (Political Correctness Offends Me))
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

What are the bad guys paying for zero-day exploits these days?


8 posted on 08/21/2019 10:28:50 PM PDT by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

‘UP TO’ SOUNDS LIKE MICROSOFT IS TRYING TO GET THEIR BUGS WORKED OUT/FIXED ON THE CHEAP BY OFFERING A BOUNTY SO THEY DON’T HAVE TO PAY THEIR CODERS THE BIG $$


9 posted on 08/21/2019 10:32:43 PM PDT by Bob434
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

30k!?

They are crazy cheapskates.

Back in the day I was really pretty good on a bughunt....


10 posted on 08/21/2019 10:39:47 PM PDT by Bobalu (The Nobel Peace Prize doesn't deserve Trump.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Only $30k to fix code written by their sh!tty H-1B and outsourced programmers? This tells you they know the code is a disaster.


11 posted on 08/21/2019 10:44:48 PM PDT by Mozzafiato
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Just hang out and wait for the first update download and it should be easy. They always sabotage themselves with their own updates. lol


12 posted on 08/22/2019 5:35:26 AM PDT by Openurmind
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

What the hell is “Chromium Edge”???

Does it have anything to do with Gooogle Chrome?


13 posted on 08/22/2019 6:38:40 AM PDT by Mr. K (No consequence of repealing obamacare is worse than obamacare itself.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Had some serious side-effects from Windows 10 update 1903 that am still flushing out. But Microsoft Windows isn’t a serious operating system any more, and am skeptical of anything called “Chromium Edge”.


14 posted on 08/22/2019 6:44:38 AM PDT by Montana_Sam (Truth lives.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

How are you supposed to forensically examine closed source code when the owner won’t give you access to the code?


15 posted on 08/22/2019 9:49:57 AM PDT by Paal Gulli
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mr. K; Montana_Sam
"Chromium" is a free and open-source web browser developed by Google. It is a fully functional browser on its own and supplies the vast majority of source code for the Google Chrome browser.

https://en.wikipedia.org/wiki/Chromium_(web_browser)

Microsoft originally developed their Win10 "Edge" browser as proprietary in-house code. When it failed to attract serious use, they realized they'd be better off building Edge from open-source that was already the user standard. So "Chromium Edge" is an all-new "Edge" browser, built with the same code that Google developed for use in their Chrome browser.

It's a big deal that Microsoft decided that open-source was better than proprietary, in this situation. They also are making it available to non-Win10 platforms: Win7, Win8x, and even MacOS. This is another big deal.

16 posted on 08/22/2019 12:25:44 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 13 | View Replies]

To: dayglored
I already found a bug. I installed it on my Windows 7 pc and opened it. It says to close it as it is in administrative mode then open in non administrator mode. It never does. Just the same screen over and over again. Where do I collect the money?

Blnk
17 posted on 08/22/2019 6:55:02 PM PDT by minnesota_bound
[ Post Reply | Private Reply | To 1 | View Replies]

To: minnesota_bound
It might be detecting that your user identity is a member of the Administrators group on your computer. That is the default for Windows if you’re the owner/first-user.

It’s recommended for security reasons that you define a non-administrative user to do your web browsing and other normal activities, and only run as an administrator when you have to install a program or do system-admin tasks.

Most Windows users ignore that advice because it’s somewhat inconvenient, so security be damned, they run with administrative privilege all the time, which puts them at risk when web browsing.

That said, I haven’t installed Chromium Edge myself yet so the above is a guess at the meaning of your warning message.

18 posted on 08/22/2019 7:02:21 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 17 | View Replies]

To: dayglored

I’m a Windows fan, but, really, who uses any MS browser?


19 posted on 08/22/2019 7:03:48 PM PDT by KevinB ("Ignorance more frequently begets confidence than does knowledge." - Charles Darwin)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

“Most Windows users ignore that advice because it’s somewhat inconvenient”

It’s not only inconvenient it is not readily apparent how to do that.


20 posted on 08/22/2019 7:06:47 PM PDT by Lurkina.n.Learnin (If you want a definition of "bullying" just watch the Democrats in the Senate)
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-23 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson