Live data from Hacker News

Microsoft 0-day feud escalates as researcher threatens another exploit dump

theregister.com

81–90 of 103 posts

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#81
I know this is a cynical approach, but I imagine most security flaws in Microsoft products are somewhat intentional. Either by purposefully putting them there or by willingly ignoring them.

It’s widely known how much Microsoft cooperates with three letter agencies. I think they are in a bind on how to act in these situations. They don’t want to acknowledge or fix the 0-day vulnerabilities because they don’t know if those are in use via state sponsored operations. Either they deal with customer fallout or they deal with the grief from their agency liaisons that they interrupted a multi-year operation by fixing the 0-day.

Vulnerability researchers really should avoid reporting to Microsoft and just sell them instead.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#82

Attacking the messenger is an age-old trend in the bug reporting arena. Microsoft has the backing of many governments, and has access to the best legal teams possible, leaving this guy in a world of hurt. Microsoft seems to have brought this on themselves by creating a complex and user-hostile bug reporting system. It seems to me that they could have offered this person a job or a contract, because Eclipse has been a…

Worse is that they proud themselves of having a security culture since XP SP2, hence having even a security conference and related podcast.

So something went down really bad on their side.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#83
post #67
post #59

Earlier quoted context omitted.

I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.

Now iOS 0-day is worth up to $2,000,000 on gray market so Apple kind a take it seriously.

When someone says memory corruption is nothing special, they aren't the ones paying those amounts.

Naturally there are other kinds of bugs as well.

However reducing 70% of root causes, saves a bunch of money already.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#84
I was reding about this yesterday and my tinfoil hat started to rustle in the drawer.

It sounded like it really could have been a backdoor, that was complicated enough to not be an easy replacement to roll out without being detected, so Microslop tried to shut down the discovery as soon as possible, annoyed the wrong researcher and now they're at risk of really having to remove their back door to an administration that is not exactly understanding.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#85

Attacking the messenger is an age-old trend in the bug reporting arena. Microsoft has the backing of many governments, and has access to the best legal teams possible, leaving this guy in a world of hurt. Microsoft seems to have brought this on themselves by creating a complex and user-hostile bug reporting system. It seems to me that they could have offered this person a job or a contract, because Eclipse has been a…

I am really somehow happy about this feud as it really demasks Microsoft. The signal Microsoft sends to their costumers (also corporate and government) is IMHO as disasterous as it is to security researchers.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#86
post #44

this is from 2010 but says that microsoft was not going to pay bug bounties https://www.computerworld.com/article/1510124/microsoft-no-m... did they start to do that at some point, or is this a pressure (blackmail?) campaign to get the to do that? I have no love for, but rather hate for, Microsoft, so I'm not suggesting blackmail in the sense of defending them, but it's something they could claim. this is on Microsof…

They’re supposed to. Instead they have a reputation for telling researchers that their disclosure isn’t actually a vulnerability and doesn’t qualify for a bounty or recognition, then quietly patching said non-vulnerability with a suspicious degree of urgency.

Happened to me when I reported that I could get Azure to issue me a certificate for a domain I don’t own.

Rejected, then quietly fixed a couple of months later.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#88

bold move in the age of llm 0 days. this will be worse than geohot and sony

Off-topic, but I found his diss track years after the fact and actually reallly respect he could put together and perform a pretty smooth, catchy, witty track in what must have been a stressful time.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#89
post #88

bold move in the age of llm 0 days. this will be worse than geohot and sony

Off-topic, but I found his diss track years after the fact and actually reallly respect he could put together and perform a pretty smooth, catchy, witty track in what must have been a stressful time.

geohot is a main character in this world tbh

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#90
post #27

I read a little about BitLocker. It seems to store the encryption key in TPM and acquire it automatically after boot. I wonder, can encryption key be extracted by inserting a rogue PCIe card and reading it from memory, or by inserting a rogue DDR memory card with a backdoor to read the key from it, or by sniffing CPU - TPM bus?

yes sniffing is possible, for now im waiting for some pluton variant to start making its way into the chip and die stream. the concept is to shield the TPM its bus, and any keys whith the CPU chip.

Current TPMs already have the ability to encrypted the comms to the CPU. Motherboard manufacturers just don't bother implementing it.
Post reply on HN