Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

151–160 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#151
post #131

I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…

You could try reporting them (the exploits) anonymously to a government agency

Re: GitHub bans security researcher who posted zero-day Windows exploits

#152

Earlier quoted context omitted.

Yes they definitely did that. Find evidence to the contrary.

Is this sarcasm? Or are you saying that the onus of providing proof is not on the those making the claim, but instead that the onus of proof is on those who did not make the claim?

You don't need to be Sherlock Holmes to draw that conclusion.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#153
In the past recent months i've been dealing with a lot of strange digital responses at various related things. It caused a lot of frustration and i couldn't exactly pinpoint what i was doing wrong. Then i read this sentence in the article:

"But to save money, Microsoft fired the skilled people, leaving flowchart followers."

Flowchart followers.. Now those are nice words to remember. It says it all. Not paid to think, but to follow pre-paved processes. My guess is that in the near future one will have to deal with a lot more flowchart followers, wether they be digital or actual human beings.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#154
post #91

Earlier quoted context omitted.

Outside of legally, I’m not aware of any framework where “creates an editorial responsibly” makes sense. Even beyond that… most business relationships wouldn’t involve an expectation that Microsoft does things for other entities that it does for itself.

I’m thinking of § 230 of the CDA [1], where the line between publisher/speaker and not can come down to editorial discretion. [1] https://en.wikipedia.org/wiki/Section_230

Per your source:

1. Section 230 was largely enacted in 1996 to solve the 1995 ruling that "because Prodigy had taken an editorial role with regard to customer content, it was a publisher and was legally responsible for libel committed by its customers" (i.e. one of the biggest purposes of section 230 was to allow companies to make editorial decisions without causing them to become legally liable as a result).

2. The law was "designed to override the decision…, so that a service provider could moderate content as necessary and would not have to act as a wholly neutral conduit."

3. However, Trump has challenged that, including with Executive Orders, although I don't think Trump's rationale is well thought through, including because he explicitly complained that his posts like "Any difficulty and we will assume control but, when the looting starts, the shooting starts" being taken down was a specific example of why 230 should be revoked.

4. And some think the opposite as well, such as Democratic leaders who "believed that Section 230 led the companies to fail to take any preemptive action against the people who had planned and executed the Capitol riots" for example.

EFF's take on 230 ( https://www.eff.org/issues/cda230 ) includes:

> Section 230 allows for web operators, large and small, to moderate user speech and content as they see fit. This reinforces the First Amendment’s protections for publishers to decide what content they will distribute. Different approaches to moderating users’ speech allows users to find the places online that they like, and avoid places they don’t.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#155

In the past recent months i've been dealing with a lot of strange digital responses at various related things. It caused a lot of frustration and i couldn't exactly pinpoint what i was doing wrong. Then i read this sentence in the article: "But to save money, Microsoft fired the skilled people, leaving flowchart followers." Flowchart followers.. Now those are nice words to remember. It says it all. Not paid to think,…

A lot of blue collar trades - mechanic/electrician/builder etc following the `flowchart` is the `law` of the land and process is written in blood and liability

Whereas IT/Ops/developers see themselves as artisinal, free thinking, intellectual beings. Where skill is related to shortcuts, hacks, and thinking outside the box compared to following process

Re: GitHub bans security researcher who posted zero-day Windows exploits

#156
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

Read the write up on YellowKey. [1] It sounds like, in at least some instances, he's publishing official Microsoft backdoors probably used by US intelligence agencies et al. It turns out that Bitlocker is insecure and backdoored. Something noooobody expected after TrueCrypt just mysteriously and suddenly shut their doors one day, removed all downloads, and recommended everybody move to Microsoft's BitLocker. lol. [1]…

It's not a backdoor, Microsoft doesn't need a backdoor to bypass BitLocker because they can sign payloads that'll pass the TPM.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#158

I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.

But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.

Are you sure?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#159

Is there any public word from Microsoft about what is going on here? Why would both Microsoft and Gitlab ban the user? I thought both platforms allowed hosting exploits and security research as long as everything is clearly marked up-front, I'm guessing some rules were broken?

[flagged]

There's zero proof it's an intentional backdoor, it's just FUD spread by the exploit author which is probably not helping his case and may be reason for his ban.

Microsoft doesn't need to put in a backdoor on disk because they can make payloads that'll pass the TPM and not need a single trace on the disk.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#160
post #147

Earlier quoted context omitted.

Is this sarcasm? Or are you saying that the onus of providing proof is not on the those making the claim, but instead that the onus of proof is on those who did not make the claim?

Sure you can provide an alternative explanation? Otherwise, that's the best we have.

> Sure you can provide an alternative explanation?

In terms of a possible explanation for why GitLab would take an action, was it considered whether the (disturbed?) user violated GitLab's Terms of Service? Is the assumption that GitLab didn't just enforce their ToS, but that they're instead more likely to be secretly acquiescing to backroom bullying between companies over specific users?

Post reply on HN