Live data from Hacker News

Microsoft 0-day feud escalates as researcher threatens another exploit dump

theregister.com

31–40 of 103 posts

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#32

Earlier quoted context omitted.

or everyone just dump all their exploits on Saturday morning 2AM, then buy puts.

> or everyone just dump all their exploits on Saturday morning 2AM, then buy puts. But nobody can buy PUTs at 2am on a saturday morning? You should buy PUTs on a friday before close then dump the exploits no?

[deleted]

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#33

Earlier quoted context omitted.

or everyone just dump all their exploits on Saturday morning 2AM, then buy puts.

> or everyone just dump all their exploits on Saturday morning 2AM, then buy puts. But nobody can buy PUTs at 2am on a saturday morning? You should buy PUTs on a friday before close then dump the exploits no?

Short via Hyperliquid or some other crypto exchange that tokenizes stock? HL does have a trading pair for MSFT and trades 24/7.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#34
post #30
post #26

Earlier quoted context omitted.

Something I've never understood about TPM attestation, is what happens if you plug the TPM into a microcontroller and give it all the same measurements that it would normally receive during a normal boot? Would that let you spoof attestations?

TPM-only saves you against someone pulling your drive. Probably more than enough for a USB drive. Enable startup PIN if you’re worried about someone grabbing the whole laptop.

[deleted]

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#35

At the end of the day, Microsoft won't care how bad any of this will make them look. Their reputation has been abysmal for decades, but none of it actually seems to have any kind of negative effect on their bottom line.

Because they mainly care about their reputation in C suites not internet forums.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#36
post #30
post #26

Earlier quoted context omitted.

Something I've never understood about TPM attestation, is what happens if you plug the TPM into a microcontroller and give it all the same measurements that it would normally receive during a normal boot? Would that let you spoof attestations?

TPM-only saves you against someone pulling your drive. Probably more than enough for a USB drive. Enable startup PIN if you’re worried about someone grabbing the whole laptop.

[deleted]

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#37
post #30
post #26

Earlier quoted context omitted.

Something I've never understood about TPM attestation, is what happens if you plug the TPM into a microcontroller and give it all the same measurements that it would normally receive during a normal boot? Would that let you spoof attestations?

TPM-only saves you against someone pulling your drive. Probably more than enough for a USB drive. Enable startup PIN if you’re worried about someone grabbing the whole laptop.

I think it does not make much sense to protect the USB drive, as you won't be able to access it from another computer which is what USB drives are for. It makes sense to protect interval drives, but it is unlikely that someone would remove the drives and leave an expensive laptop to the owner.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#38
post #30
post #26

Earlier quoted context omitted.

Something I've never understood about TPM attestation, is what happens if you plug the TPM into a microcontroller and give it all the same measurements that it would normally receive during a normal boot? Would that let you spoof attestations?

TPM-only saves you against someone pulling your drive. Probably more than enough for a USB drive. Enable startup PIN if you’re worried about someone grabbing the whole laptop.

I'm asking about TPM attestation in general, not Bitlocker
Post reply on HN