Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

161–170 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#161

Earlier quoted context omitted.

Read the write up on YellowKey. [1] It sounds like, in at least some instances, he's publishing official Microsoft backdoors probably used by US intelligence agencies et al. It turns out that Bitlocker is insecure and backdoored. Something noooobody expected after TrueCrypt just mysteriously and suddenly shut their doors one day, removed all downloads, and recommended everybody move to Microsoft's BitLocker. lol. [1]…

It's not a backdoor, Microsoft doesn't need a backdoor to bypass BitLocker because they can sign payloads that'll pass the TPM.

Why would it not be? Microslop doesn't need to make such a backdoor, but it's still a lot more convenient to make one generic backdoor than many signed ones.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#163
post #131

I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…

If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life.

Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to the common good.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#164
post #11

Also recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...

If they're using the "write lots of mediocore code faster" approach to AI and not the "write better code more slowly" approach, this is a security nightmare.

"Write better code more slowly" is just regular software development, without the LLM.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#165
post #131

I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…

Some may criticize regulations, but the EU-mandated cyber-resilience act (CRA) actually forced companies to have a clear contact point for vulnerabilities reporting, and to act upon it.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#166

In the past recent months i've been dealing with a lot of strange digital responses at various related things. It caused a lot of frustration and i couldn't exactly pinpoint what i was doing wrong. Then i read this sentence in the article: "But to save money, Microsoft fired the skilled people, leaving flowchart followers." Flowchart followers.. Now those are nice words to remember. It says it all. Not paid to think,…

Most companies providing corporate security consulting I had to deal in the past are operating on a checklist.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#167

Earlier quoted context omitted.

It's not a backdoor, Microsoft doesn't need a backdoor to bypass BitLocker because they can sign payloads that'll pass the TPM.

Why would it not be? Microslop doesn't need to make such a backdoor, but it's still a lot more convenient to make one generic backdoor than many signed ones.

They'd only need to make one payload that keeps the TPM happy, unlocks the disk and provides the files for export some way.

Far safer than a backdoor and no evidence.

But the slop in your comment here indicates you're arguing in bad faith.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#168

Researcher seems a bit unhinged.

This often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.

SandboxEscaper and Nightmare Eclipse both explicitly deny this, but I'm pretty sure they're the same person.

The style is the same, and it appears that SandboxEscaper has previously been fired by MSFT. (they are not dead) https://github.com/BigPolarBear1/The_story

SandboxEscaper, who has not really been very active online, started blogging again right before NightmareEclipse showed up. They've been offering to sell Microsoft related bugs. https://weirdquadratic.blogspot.com

OTOH, there's evidence against my theory in the form of prior tweets by the "ChaoticEclipse0" account, which include references to their age and writing in Moroccoan Darija https://x.com/ChaoticEclipse0/status/1332337678470291459

The twitter account was silent between aug 17 2023 and apr 3 2026, so it's not necessarily the same person using it anymore.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#169
post #135

Earlier quoted context omitted.

I would agree it's the researcher's responsibility. It's not that the company put up a webshell for kicks. The researcher found an exploit (good), and used it to install a webshell, demonstrating the highest possible risk (fine). Once the shell is up, anyone who finds the URL has code execution on the server, because that's what a webshell is. Using it is a different skill than installing it. Imagine I figure out how…

I.. just can't wrap my head around that. Once the notification is in and the shell demostrating it is up it should be immediate redeploy to a clean state, fix the hole, redeploy to a patched state. The shell disappears on step one. Instead some moron has the audacity to get all hurt because the broken system he is responsible for has not been patched back by the attackers? What is this lunacy?

It's at the minimum a bit impolite to leave the system more vulnerable in between sending the report and the report being received and acted on.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#170
post #131

I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…

You could try reporting them (the exploits) anonymously to a government agency

So they can exploit it in secret for their own benefit?
Post reply on HN