Unsurprisingly, this new announcement comes during the Black Hat security conference in Las Vegas, with Redmond inviting attendees to visit its boot and win prizes such as Xbox One consoles, Surface 3 tablets, or MSDN subscriptions.
Key among these were a doubling of the Bounty for Defense – from $50,000 to $100,000 – which Microsoft security architect, Jason Shirk, argued will “bring defense up on a par with offense” and “rewards the novel defender equally for their research”.
Now that Windows 10 is here and off to a fast start, Microsoft wants to ensure that it stays on top of security vulnerabilities.
The Online Service Bug Bounties program has been expanded to include Azure Active Directory and the Microsoft Account service, in addition to Office 365 and the other Azure services that were previously eligible. Successful testers can see their achievements noted in the Bounty Honor Roll. In actuality, its bug bounty program is designed to help the company address critical vulnerabilities and reward those who tinker with Microsoft’s systems and services to find them. United Airlines recently rewarded two researchers with over a million air miles each for discovering a remote-code execution flaw on the airline’s website, The Christian Science Monitor reported. The company is promoting a new bonus for any bug bounties awarded between August. 5 and October. 5. Payouts during this period will be twice the normal amount meaning researchers can, for example, earn up to $30,000 for an Authentication vulnerability submission.
And last but not least, Microsoft also announced that it has added RemoteApp on the list of domains included in the Online Services Bug Bounty, so if you find a security bug in this application, you can once again be paid for providing all details to Microsoft.
