Earlier quoted context omitted.
Read the write up on YellowKey. [1] It sounds like, in at least some instances, he's publishing official Microsoft backdoors probably used by US intelligence agencies et al. It turns out that Bitlocker is insecure and backdoored. Something noooobody expected after TrueCrypt just mysteriously and suddenly shut their doors one day, removed all downloads, and recommended everybody move to Microsoft's BitLocker. lol. [1]…
It's not a backdoor, Microsoft doesn't need a backdoor to bypass BitLocker because they can sign payloads that'll pass the TPM.
GitHub bans security researcher who posted zero-day Windows exploits
161–170 of 274 posts
Re: GitHub bans security researcher who posted zero-day Windows exploits
#162Re: GitHub bans security researcher who posted zero-day Windows exploits
#163I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…
Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to the common good.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#164Also recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...
If they're using the "write lots of mediocore code faster" approach to AI and not the "write better code more slowly" approach, this is a security nightmare.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#165I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…
Re: GitHub bans security researcher who posted zero-day Windows exploits
#166In the past recent months i've been dealing with a lot of strange digital responses at various related things. It caused a lot of frustration and i couldn't exactly pinpoint what i was doing wrong. Then i read this sentence in the article: "But to save money, Microsoft fired the skilled people, leaving flowchart followers." Flowchart followers.. Now those are nice words to remember. It says it all. Not paid to think,…
Re: GitHub bans security researcher who posted zero-day Windows exploits
#167Earlier quoted context omitted.
It's not a backdoor, Microsoft doesn't need a backdoor to bypass BitLocker because they can sign payloads that'll pass the TPM.
Why would it not be? Microslop doesn't need to make such a backdoor, but it's still a lot more convenient to make one generic backdoor than many signed ones.
Far safer than a backdoor and no evidence.
But the slop in your comment here indicates you're arguing in bad faith.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#168Researcher seems a bit unhinged.
This often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.
The style is the same, and it appears that SandboxEscaper has previously been fired by MSFT. (they are not dead) https://github.com/BigPolarBear1/The_story
SandboxEscaper, who has not really been very active online, started blogging again right before NightmareEclipse showed up. They've been offering to sell Microsoft related bugs. https://weirdquadratic.blogspot.com
OTOH, there's evidence against my theory in the form of prior tweets by the "ChaoticEclipse0" account, which include references to their age and writing in Moroccoan Darija https://x.com/ChaoticEclipse0/status/1332337678470291459
The twitter account was silent between aug 17 2023 and apr 3 2026, so it's not necessarily the same person using it anymore.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#169Earlier quoted context omitted.
I would agree it's the researcher's responsibility. It's not that the company put up a webshell for kicks. The researcher found an exploit (good), and used it to install a webshell, demonstrating the highest possible risk (fine). Once the shell is up, anyone who finds the URL has code execution on the server, because that's what a webshell is. Using it is a different skill than installing it. Imagine I figure out how…
I.. just can't wrap my head around that. Once the notification is in and the shell demostrating it is up it should be immediate redeploy to a clean state, fix the hole, redeploy to a patched state. The shell disappears on step one. Instead some moron has the audacity to get all hurt because the broken system he is responsible for has not been patched back by the attackers? What is this lunacy?
Re: GitHub bans security researcher who posted zero-day Windows exploits
#170I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…
You could try reporting them (the exploits) anonymously to a government agency