Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

101–110 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#101

Very important info: https://www.theregister.com/security/2026/05/28/microsoft-0-... In the linked Microsoft blog post, they say : > The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk. So are they lying ? Why would Nightmare-Eclipse not report them if they are not ? It's a very weird situation

> the disclosures put our customers at unnecessary risk.

That statement irks me. Responsible disclosure or not, It's Microsoft themselves that put their customers at risk, not the researcher.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#102
post #42
post #41

Earlier quoted context omitted.

What were the "so many better options" during that period? Have we found the only remaining CP/M fan?

a bit later, but not much: OS/2

The fizzling of OS/2 was as much IBM's fault as anything. If they'd paid more attention to it sooner, MS might never have shipped Windows; they'd just have made their office applications OS/2 GUI programs. But IBM was too fixated on its mainframes to realize that they were giving away the PC market to MS (again--they did it the first time by licensing DOS to MS).

Re: GitHub bans security researcher who posted zero-day Windows exploits

#103
post #93

Earlier quoted context omitted.

“False analogy” isn’t a counterpoint, it's a deflection. What part of the mapping breaks for you?

False analogy isn’t a deflection, it’s a logical fallacy.

Because you don't agree doesn't make the legitimate callout (i.e., victim-blaming “what were you wearing” vs. calling someone “unhinged” after they've endured repeated abuse/stress) a logical fallacy. Rather it positions you in opposition.

Everything you disagree with isn't incorrect.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#104
post #80

Earlier quoted context omitted.

> and the response was flow chart tech support with a "buy a webcam" cherry on top I feel safe in saying that they don't want a video of you at your keyboard typing stuff. An exploit video is a recording of your screen, not of you.

Which, if any of the exploits require anything that isn't on-screen (USB or other HID, key combination), requires a reboot, or anything done before Windows has fully booted, means one must have an external camera Doesn't sound like it for these exploits specifically (except Yellow Key), but I could be wrong, and again: that's just for these exploits specifically

> (USB or other HID, key combination)

I don't think you'd need an external camera for that. What you're doing would be mentioned in the accompanying report.

I do agree with you about the boot process, though.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#105
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

To corroborate, working in bug bounty triage, I never saw any evidence of reluctance to pay out.† The worst company-side behavior I observed was asking researchers to "please stay away from X" in their proof-of-concepts and then making higher payouts to researchers who ignored that instruction (because, after all, the demonstrated risk was higher!). On the other side of things, I saw one major program pay out at an i…

ooc, would you claim its the responsibility of the security researcher to remove the webshell, or the company's as soon as they were notified? was it publically discoverable and exploitable or was there some form of protection?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#106
post #105

Earlier quoted context omitted.

To corroborate, working in bug bounty triage, I never saw any evidence of reluctance to pay out.† The worst company-side behavior I observed was asking researchers to "please stay away from X" in their proof-of-concepts and then making higher payouts to researchers who ignored that instruction (because, after all, the demonstrated risk was higher!). On the other side of things, I saw one major program pay out at an i…

ooc, would you claim its the responsibility of the security researcher to remove the webshell, or the company's as soon as they were notified? was it publically discoverable and exploitable or was there some form of protection?

I would agree it's the researcher's responsibility. It's not that the company put up a webshell for kicks. The researcher found an exploit (good), and used it to install a webshell, demonstrating the highest possible risk (fine).

Once the shell is up, anyone who finds the URL has code execution on the server, because that's what a webshell is. Using it is a different skill than installing it.

Imagine I figure out how to jackpot your bank's ATMs, and I demonstrate this by setting a public ATM into "press button to receive $20" mode, pressing the button, getting $20, and sending you a letter describing how I did that, with the $20 scrupulously enclosed. Meanwhile, the ATM remains in the state of "press button to receive $20". How happy would you be?

Was it publicly discoverable?

Technically, yes, though realistically you'd have to guess the URL. I would find it pretty funny if one attacker got access somewhere by guessing the URL of a webshell installed by a different, more self-sufficient attacker, but that's not to say it doesn't happen.

Was it publicly exploitable?

Yes; the researcher didn't set up any authentication or anything.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#108
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

If they were smart after the ban, they'd hire him for mucho dinero. These corporations are nervous but if they're not stupid they pay out. It's Microsoft, so it's perhaps nof the most progressive when it comes to these things, so who knows if they've realized it.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#109
post #11

Also recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...

I think you're going down a bad route when you start inserting gratuitous insults into your summaries of what other people said.

Transforming 'Micro$oft's' name as a form of commentary is a time-honored tradition.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#110

Very important info: https://www.theregister.com/security/2026/05/28/microsoft-0-... In the linked Microsoft blog post, they say : > The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk. So are they lying ? Why would Nightmare-Eclipse not report them if they are not ? It's a very weird situation

> the disclosures put our customers at unnecessary risk. That statement irks me. Responsible disclosure or not, It's Microsoft themselves that put their customers at risk, not the researcher.

The industry, on average, approves of responsible disclosure because there's a tacit agreement that making risk-proof software isn't feasible. Though admittedly some companies don't seem to be trying very hard anymore.

It's not a dichotomy either, they can both have put the customers at risk.

Post reply on HN