As Microsoft have no intensions of ever paying me for all my submitted vulnerabilities I am forced to do this. Countdown starts today- then I will post them all public. Ms is just trying to get time to patch them then never pay me. I have for over 100.000$ in submissions. 14
-
Show this thread
-
Replying to @jonasLyk
@jonasLyk unfortunately they are their rules. They decide which bug worth their money and which doesn't. Responsible disclosure was "invented" in order to solve these cases. You give 90 days. If they believe it does not worth a fix, you drop it. That simple.1 reply 1 retweet 7 likes -
This Tweet is unavailable.
-
It does benefit both parties, when both parties behave responsibly. But it is a prisoner's dilemma problem: both the vendor and the finder are standing in a shallow pool of gasoline holding matches, now how would you like to proceed?
1 reply 0 retweets 0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.