Skip to main content
  1. Home
  2. Computing
  3. News

Microsoft will pay you up to $250,000 to find Spectre-like flaws

Add as a preferred source on Google

If you know how to test hardware and software and how to identify vulnerabilities in them, then there’s some real money to be made. Some manufacturers and developers will pay tons of cash to anyone who can pick out defects in their products that can lead to system breaches — all it takes is some know-how and a little patience. Microsoft is one such company, and it’s now paying up to $250,000 for identifying vulnerabilities related to Meltdown and Spectre.

In case you’ve forgotten, these two vulnerabilities have been causing quite a stir over the last several months. They impact almost all CPUs in use today to one extent or another, including Intel, AMD, and ARM processors going back a decade or so. Fixing the bugs, which involve “speculative execution” that is used to speed up processing, has caused system crashes, reboots, and poor performance, and Intel in particular has struggled to create a stable solution.

Recommended Videos

Microsoft has now added those kinds of vulnerabilities to its bug bounty program. Phillip Misner, principal security group manager for Microsoft’s security response center, describes the new bounty:

“Speculative execution is truly a new class of vulnerabilities, and we expect that research is already underway exploring new attack methods. This bounty program is intended as a way to foster that research and the coordinated disclosure of vulnerabilities related to these issues. Tier 1 focuses on new categories of attacks involving speculative execution side channels.”

There are four tiers in the Speculative Execution Bounty Program, as follows:

  • Tier 1: New categories of speculative execution attacks, up to $250,000
  • Tier 2: Azure speculative execution mitigation bypass, up to $200,000
  • Tier 3: Windows speculative execution mitigation bypass, up to $200,000
  • Tier 4: Instance of a known speculative execution vulnerability (such as CVE-2017-5753) in Windows 10 or Microsoft Edge. This vulnerability must enable the disclosure of sensitive information across a trust boundary, up to $25,000

Microsoft will be sharing whatever research is uncovered by the bounty program. This will allow collaboration between all of the involved parties to create solutions to the vulnerabilities and create a more secure environment for users.

If you’re someone who knows how to dig into systems and find flaws, then you’ll want to take a look at Microsoft’s standard terms and conditions for its bug bounty programs. There’s some real money to be made, and so you can gain some financial benefit to go with the good feelings that come with bringing some better security to our computing lives.

Mark Coppock
Former Computing Writer
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
This GitHub project wants to strip AI watermarks from your content, and things are getting interesting
This open-source tool is trying to remove the fingerprints AI leaves behind
Electronics, Phone, Mobile Phone

AI companies are increasingly looking for ways to mark content generated by their models. Now, someone has built an open-source tool designed to remove some of those marks.

A GitHub project called watermarks-remover is designed to strip different types of AI provenance signals from text and files. According to its documentation, it can work with invisible Unicode characters, statistical text watermarks and metadata embedded in formats including PNG, JPEG, SVG, PDF, DOCX, ODT, HTML and Markdown.

Read more
Lenovo’s answer to the MacBook Neo could be a peppy Vibe laptop
Affordable and eye-catching Lenovo laptops could soon challenge the MacBook Neo
Computer, Electronics, Laptop

Apple's MacBook Neo has given Windows laptop makers something to think about, and Lenovo could be the latest company preparing an answer.

Windows Latest has obtained images of an upcoming budget laptop called the Lenovo IdeaPad Vibe, which is expected to come in both Qualcomm Snapdragon and AMD versions. It also appears Lenovo isn't playing it safe with the design, as the laptop is shown in seven different colors.

Read more
Claude can now pull data from your browser tabs and keep working on your desktop
Claude in Chrome just merged with Cowork for uninterrupted cross device sessions.
claude-chrome-extension-cowork-session

Anthropic just made its Claude browser extension a lot smarter, and it can remember your conversations on desktop, web, or mobile. The Claude in Chrome side panel now runs as a full Claude Cowork session, meaning your conversations, skills, and connectors all carry over between your browser and Claude's desktop, web, and mobile apps. Before this update, browser sessions stayed completely separate from everything else, so switching devices meant starting over.

https://www.youtube.com/watch?v=C-5wF6tkQ2Q

Read more