Earlier quoted context omitted.
I should have known this exists, yet I didn't. Thanks for pointing it out. This seems to be a direct link to a web form to report (in English): https://eservices.traficom.fi/ContactForms/form/haavoittuvuu... In particular, note that all the fields asking for personal information disappear if you select "Yes" in "I am submitting an anonymous tip" field.
Just to play devil's advocate, couldn't sending zero-day exploits to a foreign nation's intelligence service potentially cause the sender significantly more trouble.
GitHub bans security researcher who posted zero-day Windows exploits
211–220 of 274 posts
Re: GitHub bans security researcher who posted zero-day Windows exploits
#212I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…
Re: GitHub bans security researcher who posted zero-day Windows exploits
#213I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…
I tried three different contacts I could find, only one came back to me and wanted to know what the systems did what the risk was etc. I pointed out I have no idea, and I'm absolutely not logging into mysterious systems to find out - pass it to your own IT so they can see what needs to be changed, rotated etc.
I did eventually get a message back from someone who thanked me for my diligence and said it was solved as they had now removed the photo... I really hope they had someone who understood look at it, but I decided not to engage further...
Re: GitHub bans security researcher who posted zero-day Windows exploits
#214Earlier quoted context omitted.
Microsoft hasn’t particuarly cared about consumers pirating Windows for more than a decade. I’m pretty sure they make close to 0 money off Windows licensing to consumers.
A quote from Billy G comes to mind > Although about 3 million computers get sold every year in China, people don't pay for the software. Someday they will, though," Gates told an audience at the University of Washington. "And as long as they're going to steal it, we want them to steal ours. They'll get sort of addicted, and then we'll somehow figure out how to collect sometime in the next decade. Microsoft's attitude…
Re: GitHub bans security researcher who posted zero-day Windows exploits
#215I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…
If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to th…
The CCC (Chaos Computer Club) in germany will probably do the same.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#216Re: GitHub bans security researcher who posted zero-day Windows exploits
#217In the past recent months i've been dealing with a lot of strange digital responses at various related things. It caused a lot of frustration and i couldn't exactly pinpoint what i was doing wrong. Then i read this sentence in the article: "But to save money, Microsoft fired the skilled people, leaving flowchart followers." Flowchart followers.. Now those are nice words to remember. It says it all. Not paid to think,…
A lot of blue collar trades - mechanic/electrician/builder etc following the `flowchart` is the `law` of the land and process is written in blood and liability Whereas IT/Ops/developers see themselves as artisinal, free thinking, intellectual beings. Where skill is related to shortcuts, hacks, and thinking outside the box compared to following process
Re: GitHub bans security researcher who posted zero-day Windows exploits
#218Earlier quoted context omitted.
I should have known this exists, yet I didn't. Thanks for pointing it out. This seems to be a direct link to a web form to report (in English): https://eservices.traficom.fi/ContactForms/form/haavoittuvuu... In particular, note that all the fields asking for personal information disappear if you select "Yes" in "I am submitting an anonymous tip" field.
Just to play devil's advocate, couldn't sending zero-day exploits to a foreign nation's intelligence service potentially cause the sender significantly more trouble.
The other angle is that you are obviously doing it in good faith, on the assumption that they will try to work with the vendor to fix and responsibly disclose the vulnerability
Re: GitHub bans security researcher who posted zero-day Windows exploits
#219Earlier quoted context omitted.
Well. Its a bad news for society as whole. Security industry going to be okay - someone will always pay for 0-days. If vendors wont pay its just gonna be US agencies, Israel resellers, China or Russia. If you don't feed your army, you will soon feed someone's else's.
It's had bad news only for Windows buerocrats. Good orgs don't use Windows.
Is this just your way of saying that only tiny, weird, companies are "good"?
Re: GitHub bans security researcher who posted zero-day Windows exploits
#220Earlier quoted context omitted.
If it's anything like the Dutch or German infosec agencies, "worst of both worlds" is about as far from the truth as you can get. Maybe it works that way in Saudi Arabia but it's not "reporting yourself" here
I wouldn't trust anything like that in Germany, where everything is rules-based. Hacking is illegal, so if the police find out you hacked and can prove it, they will arrest you and you will be convicted, period. In Germany there's no common sense applied to the rules. Arguing that you hacked and then reported it responsibly won't reduce your criminal penalty for hacking.
There are some infamous counter-examples, but you can find these in any country and it's these that make the news.