Researcher seems a bit unhinged.
GitHub bans security researcher who posted zero-day Windows exploits
31–40 of 274 posts
Re: GitHub bans security researcher who posted zero-day Windows exploits
#32I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.
Not to mention all the other people who find 0-days. Reputation matters a lot.
If researchers stop believing MS will treat them fairly it's bad news for the entire security industry.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#33If my software winds up with a zero day on GitHub, will Microsoft nuke that account, too?
Re: GitHub bans security researcher who posted zero-day Windows exploits
#34Is there any public word from Microsoft about what is going on here? Why would both Microsoft and Gitlab ban the user? I thought both platforms allowed hosting exploits and security research as long as everything is clearly marked up-front, I'm guessing some rules were broken?
Re: GitHub bans security researcher who posted zero-day Windows exploits
#35I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.
Not to mention all the other people who find 0-days. Reputation matters a lot.
Is it really fiscally responsible to tie your company's future to that?
I wonder if anyone tracks metrics for this stuff. Percentage of stuff with a repo there is probably still high, but what's happening with stuff like github actions, and are devs directly pushing to github, or are they just mirroring an internal / other provider's git repo to it?
Re: GitHub bans security researcher who posted zero-day Windows exploits
#36This might not be true of small companies (and is a reason why small companies shouldn't run bug bounty programs), but it is definitely true of FAANG/MAG7-scale companies.
This doesn't mean these bounty programs err on the side of paying out, or that they won't routinely make decisions that will piss you off. It does however work against claims that they're withholding payouts vindictively.
[†] Only hedging because it's been a minute since I've talked to anyone at Microsoft.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#37What's the backstory on this researcher? They seem to have a personal vendetta against Microsoft and thus releasing zero days that he found with the help of AI? Seems like the gold rush period is over for bounty hunters and its more about who has access to hardware/token capital.
> They seem to have a personal vendetta against Microsoft Probably because they were forced to use MS-DOS when so many better options were killed off by Microsoft's monopolistic and anti-consumer underhanded business tactics... I might be projecting.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#38Researcher seems a bit unhinged.
This often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#39Also recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...
I think you're going down a bad route when you start inserting gratuitous insults into your summaries of what other people said.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#40Also recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...
I think you're going down a bad route when you start inserting gratuitous insults into your summaries of what other people said.
I'm certain that the multi-trillion dollar company with a history of antisocial and anti-consumer behavior will survive some petty insults.
Though, if people who control purchasing (and/or regulatory) power tend to link increasing use of LLMs and layoffs because "AI means we don't need all those programmers and managers" to substantial and ongoing reductions in quality of the company's software and services, the discussions customers have with MSFT salesfolk may cause the company to "change course", as it were. Intermittent grassroots petty insults are one way to keep folks reminded of the stuff that CEOs and salesfolks would rather you forget.