Microsoft 0-day feud escalates as researcher threatens another exploit dump
31–40 of 103 posts
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#32Earlier quoted context omitted.
or everyone just dump all their exploits on Saturday morning 2AM, then buy puts.
> or everyone just dump all their exploits on Saturday morning 2AM, then buy puts. But nobody can buy PUTs at 2am on a saturday morning? You should buy PUTs on a friday before close then dump the exploits no?
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#33Earlier quoted context omitted.
or everyone just dump all their exploits on Saturday morning 2AM, then buy puts.
> or everyone just dump all their exploits on Saturday morning 2AM, then buy puts. But nobody can buy PUTs at 2am on a saturday morning? You should buy PUTs on a friday before close then dump the exploits no?
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#34Earlier quoted context omitted.
Something I've never understood about TPM attestation, is what happens if you plug the TPM into a microcontroller and give it all the same measurements that it would normally receive during a normal boot? Would that let you spoof attestations?
TPM-only saves you against someone pulling your drive. Probably more than enough for a USB drive. Enable startup PIN if you’re worried about someone grabbing the whole laptop.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#35At the end of the day, Microsoft won't care how bad any of this will make them look. Their reputation has been abysmal for decades, but none of it actually seems to have any kind of negative effect on their bottom line.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#36Earlier quoted context omitted.
Something I've never understood about TPM attestation, is what happens if you plug the TPM into a microcontroller and give it all the same measurements that it would normally receive during a normal boot? Would that let you spoof attestations?
TPM-only saves you against someone pulling your drive. Probably more than enough for a USB drive. Enable startup PIN if you’re worried about someone grabbing the whole laptop.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#37Earlier quoted context omitted.
Something I've never understood about TPM attestation, is what happens if you plug the TPM into a microcontroller and give it all the same measurements that it would normally receive during a normal boot? Would that let you spoof attestations?
TPM-only saves you against someone pulling your drive. Probably more than enough for a USB drive. Enable startup PIN if you’re worried about someone grabbing the whole laptop.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#38Earlier quoted context omitted.
Something I've never understood about TPM attestation, is what happens if you plug the TPM into a microcontroller and give it all the same measurements that it would normally receive during a normal boot? Would that let you spoof attestations?
TPM-only saves you against someone pulling your drive. Probably more than enough for a USB drive. Enable startup PIN if you’re worried about someone grabbing the whole laptop.