Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.
And he’s 16. Parents might have had a say.
There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.
not not either. where do I sign up?
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.