Microsoft readiness to pay , up to one hundred thousand dollars, for discovering a vulnerability in the IoT platform , on a Linux kernel base and using sandbox isolation for core services and applications. The reward is promised for demonstrating vulnerabilities in the subsystem (root of trust implemented in the chip) or (sandbox).
The reward is part of a three-month , which will run from June 1 to August 31, 2020. The initiative specifically targets Azure Sphere OS and does not include cloud subsystems, which are already covered by a separate reward program. To be eligible for the reward, one must demonstrate a vulnerability that could lead to the execution of unsigned third-party code, interception of authentication parameters, privilege escalation, modification of settings, or bypassing firewall restrictions through local (application compromise) or remote attacks. To facilitate research, Microsoft has expressed its willingness to provide participants access to products and services, Azure Sphere SDK, technical documentation, and ensure communication channels with the platform developers.
The Azure Sphere platform is designed for creating Internet of Things devices based on energy-efficient microcontrollers (MCU) with integrated peripheral subsystems. Azure Sphere is used in commercial equipment, including by companies like Starbucks. A key feature of the platform is the Pluton subsystem, which provides hardware resources for encryption, secure key storage, and performing complex cryptographic operations. Pluton includes a separate specialized processor, a cryptographic engine, a hardware random number generator, and an isolated key storage.
Additionally, it can be noted on the attempted sale by an unknown individual of content from private Microsoft GitHub repositories. The unknown individual claimed to have downloaded about 500 GB of data from Microsoft’s private repositories hosted on GitHub and provided screenshots and 1 GB of data as proof. Most participants found the evidence unconvincing, as screenshots can be easily fabricated, and the data contained some nonsensical set of files with text in Chinese, tests, and code snippets. One of Microsoft's engineers stated that the leak is likely a hoax, as Microsoft has a policy that projects hosted in private GitHub repositories must become public within 30 days.
Source: opennet.ru
