upvote
They should have paid him at least a $1 million bounty if they're going to ask for editorial control of the disclosure.
reply
Love to hear more on the motivation for agreeing to this.

e.g. The $5000? Amnesty from being sued?

reply
Sounds like he’s gotten bug bounties from MS in the past. Might be forward thinking to keep the relationship amicable going forward.

Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.

And he’s 16. Parents might have had a say.

reply
Also he's 16. I'd definitely be less willing to push back (especially on something like this) at his age
reply
At that age in the mid 2000s, I would be foaming at the mouth to tell a FANG company to eat dirt over something like a disclosure + unpaid bounty. But if he got the money and didn't negotiate... You live and you learn.
reply
iamverybadass
reply
Of course not. You don’t push back on something like that. You hire a lawyer and let them do the pushing for you. If you contact the right NGO, they might even give you one for free.

There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.

reply
I don't know about you, but when I was 16, I never hired a lawyer, and none of the other 16 year olds I knew had either
reply
I've seen hackers. Even if you do it right you're still going to get banned from the internet till you are 18 and dating Angelina Jolie is not the draw it was 20 years ago....
reply
> dating Angelina Jolie is not the draw it was 20 years ago....

not not either. where do I sign up?

reply
She’s glorious in the movie, though she does play the part of an extremely high maintenance woman uncannily well…
reply
There are so many great one liners in that move. An underrated one is when Dade's mom opens the door, sees Acid Burn and says "now I see what all the fuss is about".
reply
I mean when you're sixteen, you can sign a legally binding contract (might depend on the jurisdiction). Usually you have to be above the age of majority (18) or be emancipated before you can enter into a binding contract.
reply
Not getting your life ruined by getting sued by a trillion dollar company sounds like a pretty good motivation
reply
Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed. I wonder what’s the consensus on this? Do people normally report it or not?

On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.

reply
I think my take would be to report it anonymously (via support/marketing/etc.) and in the report strongly encourage them to create a path for security reports (either via a bounty or just a security email). When fixed or actually dismissed post publicly on anonymous channels, with a section saying how they could have created a channel for these reports.
reply
>Do people normally report it or not?

if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.

but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.

otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.

reply
My issue was knowing that reporting would allow them to possibly discover my identity. Discovering the vul in itself may instead be considered unauthorized access.
reply
don't worry you are popular with me
reply
i think the answer is simple: they're a kid, and microsoft bullied them.
reply
reminds me of a former job in which my goodbye letter was heavily editorialized...
reply
Would love to hear more.
reply
I will tell my story: I found a huge accounting error that allowed for several employees to embezzle funds. I disclosed it to the main stakeholders and some people went to jail. The accounting team still refused to acknowledge that the mistake was theirs, so I left on principle.

A few weeks later, I was talking to an old colleague and they revealed that the story that came from stakeholders was that the accounting team found the error, and I left in disgrace (despite that not being my department?).

So if you find an embarrassing mistake and you do not control the narrative, you have to proceed very carefully.

reply
Had one like that. I quit and they blamed me for a project failure after the fact. That pissed off a couple of colleagues who thought it might happen to them. They also quit leaving them entirely without a software team. Set them back ten years because they didn’t make the market in time.

Write everything down and make sure everyone knows you’re writing it down. Saves a lot of hassle like that.

reply
> the story that came from stakeholders was that the accounting team found the error, and I left in disgrace (despite that not being my department?).

That sounds like defamation to me.

reply
_I am jack's complete lack of surprise_

This is a company that has engaged in heavy monopolistic behavior and violating US anti-trust laws with reckless abandon. They have even pioneered the infamous "embrace, extend, extinguish" strategy.

M$ will never change. The modus operandi is always the same, regardless of which ever lame MBA douchebag is running the shit show.

If we want to actually care , rather than spew off platitudes, break up big tech.

reply