Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

41–50 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#41
post #28

What's the backstory on this researcher? They seem to have a personal vendetta against Microsoft and thus releasing zero days that he found with the help of AI? Seems like the gold rush period is over for bounty hunters and its more about who has access to hardware/token capital.

> They seem to have a personal vendetta against Microsoft Probably because they were forced to use MS-DOS when so many better options were killed off by Microsoft's monopolistic and anti-consumer underhanded business tactics... I might be projecting.

What were the "so many better options" during that period? Have we found the only remaining CP/M fan?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#42
post #41
post #28

Earlier quoted context omitted.

> They seem to have a personal vendetta against Microsoft Probably because they were forced to use MS-DOS when so many better options were killed off by Microsoft's monopolistic and anti-consumer underhanded business tactics... I might be projecting.

What were the "so many better options" during that period? Have we found the only remaining CP/M fan?

a bit later, but not much: OS/2

Re: GitHub bans security researcher who posted zero-day Windows exploits

#43

What's the backstory on this researcher? They seem to have a personal vendetta against Microsoft and thus releasing zero days that he found with the help of AI? Seems like the gold rush period is over for bounty hunters and its more about who has access to hardware/token capital.

It sounds like they're pissed because they produced a large number of high-value exploits, sent them to MS, were treated like crap, and then MS refused to honor their own published bounties:

> But to save money, Microsoft fired the skilled people, leaving flowchart followers. I wouldn't be surprised if Microsoft closed the case after the reporter refused to submit a video of the exploit, since that's apparently an MSRC requirement now."

If I spent years learning your system, then gift wrapped zero-days that are devastating at multiple levels of your stack for you, and the response was flow chart tech support with a "buy a webcam" cherry on top, I'd be pretty pissed too. The bounties for these (which apparently work, since they're under active exploitation) add up to mid six figures, and, apparently, there's a pile of additional ones in the wings.

Bug bounties are already exploitative (they pay 10x higher wages to people that write the bugs than the people that find them, and finding them is generally much harder).

Breaking trust by refusing to pay up when the issues are filed through official channels is unprofessional and sleazy.

If this researcher actually had a vendetta, I'd expect them to just sell the remaining zero-days to the highest bidder.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#45

Is there any public word from Microsoft about what is going on here? Why would both Microsoft and Gitlab ban the user? I thought both platforms allowed hosting exploits and security research as long as everything is clearly marked up-front, I'm guessing some rules were broken?

[flagged]

Usually, when intentional backdoors like that get found and fixed, the 'someone else' stays silent. Otherwise, they provide proof that they've been planting backdoors, and that's much worse than having a hole plugged.

To get an idea of how this stuff usually works, start with the Simple Sabotage field manual:

https://ia601309.us.archive.org/14/items/Simplesabotage/Simp...

Re: GitHub bans security researcher who posted zero-day Windows exploits

#46

What's the backstory on this researcher? They seem to have a personal vendetta against Microsoft and thus releasing zero days that he found with the help of AI? Seems like the gold rush period is over for bounty hunters and its more about who has access to hardware/token capital.

We're witnessing the industrialization of intelligence.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#47
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

To corroborate, working in bug bounty triage, I never saw any evidence of reluctance to pay out.† The worst company-side behavior I observed was asking researchers to "please stay away from X" in their proof-of-concepts and then making higher payouts to researchers who ignored that instruction (because, after all, the demonstrated risk was higher!).

On the other side of things, I saw one major program pay out at an inappropriately high tier, over and over again, because a long time ago the researcher had successfully argued that his garden-variety XSS exploit could be used to generate an effect that was listed at a higher payout rate, and then he made sure that whenever he found an XSS, he included a proof-of-concept generating that same effect. Other researchers reporting XSS got the listed XSS rate.

† Actually, I can think of one time. Someone achieved the holy grail and installed a webshell on a company server, which under current guidelines would have been worth more than $10k. However, they didn't uninstall the webshell. They just filed their report and left it up. This enraged the head of the program, who commented specifically that he didn't want to pay out a bounty because of it. I don't recall whether a bounty was ultimately paid or not.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#48

Researcher seems a bit unhinged.

This often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.

Passed away? What evidence do you have around that statement?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#49
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

It all started because the bureaucracy refused to even consider Bluehammer when they couldn't cajole the reporter into providing video footage.

And then to double down and ban accounts because you'd rather not fix the bureaucracy is really just a bad look. I'm not quite sure why MS is getting the benefit of the doubt from you.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#50

Earlier quoted context omitted.

I think you're going down a bad route when you start inserting gratuitous insults into your summaries of what other people said.

I disagree with policing someone elses language like this in the first place, but it's only one insult and it's just "Microslop".

I don't think you should insert any number of insults into summaries of what other people said. It serves no purpose other than degrading the quality of discussion. If someone posted this comment:

> Satya Nadella says as much as 30% of Microsoft code is written by AI. More like Microslop, haha!

we'd all recognize that the last sentence is pointless name-calling (and thus violates the HN guidelines). But by interleaving the insult, it's easy to trick oneself into thinking that it's meaningful commentary. The quality of HN as a discussion forum requires holding ourselves to a higher standard than that.

Post reply on HN