Microsoft's Legal Threat Against Security Researcher Backfires
Source: TechCrunch
Microsoft's threat of criminal referral and legal action against a security researcher over responsible vulnerability disclosure has drawn public criticism from the security community. The company's move—framed in corporate language—shows how dominant tech firms resort to legal intimidation when researchers bypass preferred disclosure channels, a tactic that typically generates more reputational damage than the original vulnerability. The incident suggests that major software companies' "bug bounty" programs function partly as legal cover and gatekeeping mechanisms rather than genuine invitations for security collaboration.