A story from the vaults of my frustrating experiences with MSRC which culminated in someone else getting a bounty payment for a bug I’d simultaneously found which MSRC had explicitly told me would be out of scope 🫠
.@msftsecresponse is driving me absolutely nuts with their inconsistent bounty rewads of which I've received none. A lot of this is going to sound like whinging but bear with me. tl;dr I _may_ have been scammed out of a $10-30k reward. 🧵