Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

181–190 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#181
post #172
post #163

Earlier quoted context omitted.

If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to th…

You now have the worst of both worlds. You report yourself to the police for trying to hack into a computer-system and you report yourself to the website that can now decide to sue you. All of that without any benefits.

Is this purely theoretical? Asking since we don’t wanna encourage making the world worse if there is indeed a clever way to stay safe - has anyone been hassled after reporting to the Finnish Cyber Security Centre?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#182
post #172
post #163

Earlier quoted context omitted.

If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to th…

You now have the worst of both worlds. You report yourself to the police for trying to hack into a computer-system and you report yourself to the website that can now decide to sue you. All of that without any benefits.

Sir, this is not USA, don't assume stuff fucked up there is fucked up everywhere

Re: GitHub bans security researcher who posted zero-day Windows exploits

#183

I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.

But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.

Well, after they didn't pay him for previous bugs. Not an excuse but certainly a reason.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#186

Earlier quoted context omitted.

Ever considered these aren't the full set of exploits the researcher discovered? Or that he can find more since he found these? If I found a bunch, I'd certainly withhold a few as insurance.

Sure, but GitHub and Gitlab aren’t the only two ways to share code on the Internet. The conspiracy theories about two unrelated companies shutting down his git accounts to prevent him from releasing these supposed exploits are reaching pretty deep into conspiracy theory nonsense. The conspiracy theories can’t even agree if he was banned for posting them or because he hadn’t posted them but might post them.

Is Gitlab also part of this? This is disappointing but unsurprising :(

Re: GitHub bans security researcher who posted zero-day Windows exploits

#187
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

If they were smart after the ban, they'd hire him for mucho dinero. These corporations are nervous but if they're not stupid they pay out. It's Microsoft, so it's perhaps nof the most progressive when it comes to these things, so who knows if they've realized it.

They are supposedly disgruntled ex microsoft. I dont know if they would accept a payout

Re: GitHub bans security researcher who posted zero-day Windows exploits

#188
post #163
post #131

I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…

If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to th…

I should have known this exists, yet I didn't. Thanks for pointing it out.

This seems to be a direct link to a web form to report (in English): https://eservices.traficom.fi/ContactForms/form/haavoittuvuu...

In particular, note that all the fields asking for personal information disappear if you select "Yes" in "I am submitting an anonymous tip" field.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#190
This situation highlights the inherent conflict of interest in Microsoft owning GitHub. While GitHub has clear terms of service regarding the hosting of active, weaponized exploits, the optics of banning a researcher who specifically targeted Windows are always going to look vindictive, regardless of the justification.
Post reply on HN