Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

111–120 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#111

Is there any public word from Microsoft about what is going on here? Why would both Microsoft and Gitlab ban the user? I thought both platforms allowed hosting exploits and security research as long as everything is clearly marked up-front, I'm guessing some rules were broken?

[flagged]

I'm not a BitLocker user or expert, but I thought I'd read that if you used a BitLocker PIN, the exploit didn't work. If the gov't asked MSFT to deploy an exploit, wouldn't they make it work PINlessly?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#112
post #102
post #42

Earlier quoted context omitted.

a bit later, but not much: OS/2

The fizzling of OS/2 was as much IBM's fault as anything. If they'd paid more attention to it sooner, MS might never have shipped Windows; they'd just have made their office applications OS/2 GUI programs. But IBM was too fixated on its mainframes to realize that they were giving away the PC market to MS (again--they did it the first time by licensing DOS to MS).

Before Facebook, I used Friendster. Years later, I read how Friendster execs were too busy patting themselves on the back and flying around on private jets to get around to fixing the horrendous site lag of sometimes a minute to even sign into the web app. How could a company's leadership be so foolish? I understood this paled in comparison to the doomed arrogance of IBM's leaders when I read stories about IBM's downfall in the delightful book In Search of Stupidity: Over 20 Years of High-Tech Marketing Disasters.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#113

Lol, they ban a security researcher from Github for embarassing them, but massgrave's Microsoft Activation Scripts isn't just still on Github but verified ? Make it make sense, Microsoft.

Github's anti-piracy enforcement is a joke and always has been.

Example: https://lowendbox.com/blog/will-github-ever-remove-this-null...

Re: GitHub bans security researcher who posted zero-day Windows exploits

#114
post #105

Earlier quoted context omitted.

ooc, would you claim its the responsibility of the security researcher to remove the webshell, or the company's as soon as they were notified? was it publically discoverable and exploitable or was there some form of protection?

I would agree it's the researcher's responsibility. It's not that the company put up a webshell for kicks. The researcher found an exploit (good), and used it to install a webshell, demonstrating the highest possible risk (fine). Once the shell is up, anyone who finds the URL has code execution on the server, because that's what a webshell is. Using it is a different skill than installing it. Imagine I figure out how…

If the URL was unpublished, isn't that the same-ish as password protected?

All about bits of entropy i.e. difficulty if guessing.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#115
post #11

Also recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...

I think you're going down a bad route when you start inserting gratuitous insults into your summaries of what other people said.

Ooops. Just copilot-made mistake of 30% comment that been AI generated. Kidding.

Actually I was a reference of Microsoft banning people on their Discord.

Because out of top "evil corps" Microsoft seem to have worst PR department.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#116
post #83
post #37

Earlier quoted context omitted.

I was forced to use ms basic on my c64. Never forgive, never forget.

I always found it weird to ship a BASIC interpreter that didn't have specialised commands (unless you count POKE) to access the graphics and sound capabilities of a computer like the C64. Some computers of the same era had vastly superior BASICs (such as Sinclair BASIC).

OTOH, I learned a hell of a lot about microprocessor internals by using POKE.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#117

Earlier quoted context omitted.

Not to mention all the other people who find 0-days. Reputation matters a lot.

Yep, and its a really small world out there. If researchers stop believing MS will treat them fairly it's bad news for the entire security industry.

Well. Its a bad news for society as whole.

Security industry going to be okay - someone will always pay for 0-days. If vendors wont pay its just gonna be US agencies, Israel resellers, China or Russia.

If you don't feed your army, you will soon feed someone's else's.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#118
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

The bug this guy brings up is very obviously a Bitlocker backdoor and raises very serious questions about what Microsoft is doing with the encryption. Pretty certainly they're able to decode the volumes without the user's key, which is extremely concerning.

Looks like they're trying to make it disappear, but it's in the wild now.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#119

Very important info: https://www.theregister.com/security/2026/05/28/microsoft-0-... In the linked Microsoft blog post, they say : > The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk. So are they lying ? Why would Nightmare-Eclipse not report them if they are not ? It's a very weird situation

> the disclosures put our customers at unnecessary risk. That statement irks me. Responsible disclosure or not, It's Microsoft themselves that put their customers at risk, not the researcher.

Especially since the only explanation for why this exists is as a backdoor.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#120

I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.

But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.

I'm not sure if this is an unintentional mistake. Gitlab did not perform a ban. Github performed the ban. Github is fully-owned by Microsoft.
Post reply on HN