upvote
Sounds like he’s gotten bug bounties from MS in the past. Might be forward thinking to keep the relationship amicable going forward.

Giving the benefit of the doubt to Microsoft it seems like a pretty complete write up. If the changes weren’t material that might have been part of it too.

And he’s 16. Parents might have had a say.

reply
Also he's 16. I'd definitely be less willing to push back (especially on something like this) at his age
reply
At that age in the mid 2000s, I would be foaming at the mouth to tell a FANG company to eat dirt over something like a disclosure + unpaid bounty. But if he got the money and didn't negotiate... You live and you learn.
reply
iamverybadass
reply
Of course not. You don’t push back on something like that. You hire a lawyer and let them do the pushing for you. If you contact the right NGO, they might even give you one for free.

There’s no way I’d sign any agreement with a company like Microsoft regarding an issue like that without a lawyer. I’d rather not disclose at all if those were the only options.

reply
I don't know about you, but when I was 16, I never hired a lawyer, and none of the other 16 year olds I knew had either
reply
I've seen hackers. Even if you do it right you're still going to get banned from the internet till you are 18 and dating Angelina Jolie is not the draw it was 20 years ago....
reply
> dating Angelina Jolie is not the draw it was 20 years ago....

not not either. where do I sign up?

reply
She’s glorious in the movie, though she does play the part of an extremely high maintenance woman uncannily well…
reply
There are so many great one liners in that move. An underrated one is when Dade's mom opens the door, sees Acid Burn and says "now I see what all the fuss is about".
reply
I mean when you're sixteen, you can sign a legally binding contract (might depend on the jurisdiction). Usually you have to be above the age of majority (18) or be emancipated before you can enter into a binding contract.
reply
Not getting your life ruined by getting sued by a trillion dollar company sounds like a pretty good motivation
reply
Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed. I wonder what’s the consensus on this? Do people normally report it or not?

On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.

reply
I think my take would be to report it anonymously (via support/marketing/etc.) and in the report strongly encourage them to create a path for security reports (either via a bounty or just a security email). When fixed or actually dismissed post publicly on anonymous channels, with a section saying how they could have created a channel for these reports.
reply
>Do people normally report it or not?

if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.

but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.

otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.

reply
My issue was knowing that reporting would allow them to possibly discover my identity. Discovering the vul in itself may instead be considered unauthorized access.
reply
don't worry you are popular with me
reply
i think the answer is simple: they're a kid, and microsoft bullied them.
reply