Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Microsoft: Reckon our code is crap? Prove it and $30k could be yours (Edge Bug Bounty Program)
The Register ^ | Aug 21, 2019 | Richard Speed

Posted on 08/21/2019 9:03:52 PM PDT by dayglored

Doors on the Edge Insider Bounty Program flung open

Having finally pushed out the first Beta preview of its Chromium-based browser, Microsoft has launched a bounty programme aimed at getting researchers to kick the tyres on its latest and greatest.

Up to $30k is available to researchers who find what Microsoft deems "critical and important" vulnerabilities in the Beta and Dev channels of Chromium Edge. The Canary channel is excluded because, well, it seems hardly fair to poke holes in daily builds that are, by definition, not fit for public consumption.

Interestingly, up to $15k is available to anyone who discovers critical remote code execution and "design issues" in the original EdgeHTML version still lurking in the Slow Ring of the Windows 10 Insider Preview.

Just think, if a few dozen researchers are lured by that $15k, it could double the not-just-downloading-Chrome usage of old Edge overnight.

Snark aside, Microsoft really wants researchers to start thumping Chromium Edge, and has stated that a 2X multiplier is available via the Researcher Recognition Program and the company will pay out as soon the reproduction and assessment has been completed of each submission.

Of course, with Edge being Chromium-based, Chrome's own reward programme is a consideration, so Microsoft is keen on reports that reproduce on Edge rather than Chrome. Severity, impact and "report quality" are also factors, so "Yo browser sucks, Micro$oft" is unlikely to go down well.

Microsoft is also looking for reports from macOS Edge users in addition to those running the browser on fully patched versions of Windows 7 SP1 and 8.1.

It isn't clear what that means after January 2020, when poor old Windows 7 is due a visit from an engineer in a high-viz jacket, carrying an axe. ®


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: bugbounty; chrome; chromium; chromiumedge; edge; microsloth; microsoft; onetokeovertheline; windowspinglist
Navigation: use the links below to view more comments.
first previous 1-2021-23 last
To: bigbob

It’d be more fun going with the hooker.


21 posted on 08/22/2019 7:14:56 PM PDT by Lurkina.n.Learnin (If you want a definition of "bullying" just watch the Democrats in the Senate)
[ Post Reply | Private Reply | To 6 | View Replies]

To: minnesota_bound

Eh, unfortunately, that’s Win7’s UAC priviledged elevation for Admin accounts. Try loging in as a Regular User and see if it runs. Or make a Regular User account and do a Run As to the regular user.

Still rooting for you to get 30K though -split two ways of course.


22 posted on 08/22/2019 7:22:30 PM PDT by Justa
[ Post Reply | Private Reply | To 17 | View Replies]

To: minnesota_bound

I opened task manager and it shows about 20 msedge.exe lines and I only have 1 tab.


23 posted on 08/22/2019 9:09:18 PM PDT by minnesota_bound
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-23 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson