Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

31–40 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#31

Researcher seems a bit unhinged.

This often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#32

I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.

Not to mention all the other people who find 0-days. Reputation matters a lot.

Yep, and its a really small world out there.

If researchers stop believing MS will treat them fairly it's bad news for the entire security industry.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#34

Is there any public word from Microsoft about what is going on here? Why would both Microsoft and Gitlab ban the user? I thought both platforms allowed hosting exploits and security research as long as everything is clearly marked up-front, I'm guessing some rules were broken?

[flagged]

Re: GitHub bans security researcher who posted zero-day Windows exploits

#35

I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.

Not to mention all the other people who find 0-days. Reputation matters a lot.

Not to mention all the startups being founded right now. Sure, github's still the default, and maybe you can still monetize stars or something, but it's also a clown show from an availability, feature roadmap and company policy perspective.

Is it really fiscally responsible to tie your company's future to that?

I wonder if anyone tracks metrics for this stuff. Percentage of stuff with a repo there is probably still high, but what's happening with stuff like github actions, and are devs directly pushing to github, or are they just mirroring an internal / other provider's git repo to it?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#36
No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants.

This might not be true of small companies (and is a reason why small companies shouldn't run bug bounty programs), but it is definitely true of FAANG/MAG7-scale companies.

This doesn't mean these bounty programs err on the side of paying out, or that they won't routinely make decisions that will piss you off. It does however work against claims that they're withholding payouts vindictively.

[†] Only hedging because it's been a minute since I've talked to anyone at Microsoft.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#37
post #28

What's the backstory on this researcher? They seem to have a personal vendetta against Microsoft and thus releasing zero days that he found with the help of AI? Seems like the gold rush period is over for bounty hunters and its more about who has access to hardware/token capital.

> They seem to have a personal vendetta against Microsoft Probably because they were forced to use MS-DOS when so many better options were killed off by Microsoft's monopolistic and anti-consumer underhanded business tactics... I might be projecting.

I was forced to use ms basic on my c64. Never forgive, never forget.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#38

Researcher seems a bit unhinged.

This often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.

SandboxEscaper is still alive, but yeah, Eclipse's prolific vuln dropping reminds me of her.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#39
post #11

Also recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...

I think you're going down a bad route when you start inserting gratuitous insults into your summaries of what other people said.

I disagree with policing someone elses language like this in the first place, but it's only one insult and it's just "Microslop".

Re: GitHub bans security researcher who posted zero-day Windows exploits

#40
post #11

Also recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...

I think you're going down a bad route when you start inserting gratuitous insults into your summaries of what other people said.

> I think you're going down a bad route when you start inserting gratuitous insults into your summaries of what other people said.

I'm certain that the multi-trillion dollar company with a history of antisocial and anti-consumer behavior will survive some petty insults.

Though, if people who control purchasing (and/or regulatory) power tend to link increasing use of LLMs and layoffs because "AI means we don't need all those programmers and managers" to substantial and ongoing reductions in quality of the company's software and services, the discussions customers have with MSFT salesfolk may cause the company to "change course", as it were. Intermittent grassroots petty insults are one way to keep folks reminded of the stuff that CEOs and salesfolks would rather you forget.

Post reply on HN