For years, Microsoft has refused to offer financial rewards to researchers who tell the company about security flaws in its software, even as Google GOOG -1.73% and Facebook FB -1.68% have ratcheted up their so-called “bug bounty” programs. Now the software giant has suddenly changed its mind–and it’s even offering even bigger bounties in some cases than those competitors.
On Tuesday Microsoft announced that it’s now willing to pay up to $100,000 for information about security bugs that can be used to bypass the defenses of Windows, starting with the upcoming preview version of Windows 8.1 to be released later this month. For researchers who also detail new defensive techniques for preventing similar bugs from being exploited in the future, Microsoft will pitch in an extra $50,000 “Defense Bonus” per submission.
|