Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

201–210 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#201
post #163

Earlier quoted context omitted.

If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to th…

I should have known this exists, yet I didn't. Thanks for pointing it out. This seems to be a direct link to a web form to report (in English): https://eservices.traficom.fi/ContactForms/form/haavoittuvuu... In particular, note that all the fields asking for personal information disappear if you select "Yes" in "I am submitting an anonymous tip" field.

Just to play devil's advocate, couldn't sending zero-day exploits to a foreign nation's intelligence service potentially cause the sender significantly more trouble.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#202
post #173
post #172

Earlier quoted context omitted.

You now have the worst of both worlds. You report yourself to the police for trying to hack into a computer-system and you report yourself to the website that can now decide to sue you. All of that without any benefits.

If it's anything like the Dutch or German infosec agencies, "worst of both worlds" is about as far from the truth as you can get. Maybe it works that way in Saudi Arabia but it's not "reporting yourself" here

I wouldn't trust anything like that in Germany, where everything is rules-based. Hacking is illegal, so if the police find out you hacked and can prove it, they will arrest you and you will be convicted, period. In Germany there's no common sense applied to the rules. Arguing that you hacked and then reported it responsibly won't reduce your criminal penalty for hacking.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#203

Earlier quoted context omitted.

It all started because the bureaucracy refused to even consider Bluehammer when they couldn't cajole the reporter into providing video footage. And then to double down and ban accounts because you'd rather not fix the bureaucracy is really just a bad look. I'm not quite sure why MS is getting the benefit of the doubt from you.

They also silently patched RedSun, didn't issue a CVE until much later. There's something fishy going on with these vulnerabilities. I'm not one for conspiracies but it's not a good look for Microsoft, they are obviously trying to cover something up.

They are probably the NSA backdoors

Re: GitHub bans security researcher who posted zero-day Windows exploits

#204

Very important info: https://www.theregister.com/security/2026/05/28/microsoft-0-... In the linked Microsoft blog post, they say : > The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk. So are they lying ? Why would Nightmare-Eclipse not report them if they are not ? It's a very weird situation

Yeah, but the customer in this statement being entities that requested this backdoor. Not the people/companies who paid for the licences.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#205
post #43

Earlier quoted context omitted.

It sounds like they're pissed because they produced a large number of high-value exploits, sent them to MS, were treated like crap, and then MS refused to honor their own published bounties: > But to save money, Microsoft fired the skilled people, leaving flowchart followers. I wouldn't be surprised if Microsoft closed the case after the reporter refused to submit a video of the exploit, since that's apparently an MS…

> If this researcher actually had a vendetta, I'd expect them to just sell the remaining zero-days to the highest bidder. selling to the highest bidder doesn’t generate headlines though.

Oh it does, but they don't say "Researcher sells exploits to the highest bidder", they say "Handala group shuts down nuclear power plant"

Re: GitHub bans security researcher who posted zero-day Windows exploits

#206
post #163
post #131

I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…

If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to th…

Were you somehow able to intuit that parent is Finnish?

I'm intrigued by your post -- I used to tell people send things like this to CERT/CC... but it's been so long since I dabbled in that world that my contacts have departed and the current administration is so erratic that paired with Finland's recent rejection of neutrality and ascension into NATO that I would frankly agree that your CERT may be a better fit for the majority of people.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#207

Very important info: https://www.theregister.com/security/2026/05/28/microsoft-0-... In the linked Microsoft blog post, they say : > The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk. So are they lying ? Why would Nightmare-Eclipse not report them if they are not ? It's a very weird situation

>Why would Nightmare-Eclipse not report them if they are not ?

Maybe they're a foreign intelligence cutout masquerading as a burned researcher.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#208

Earlier quoted context omitted.

I should have known this exists, yet I didn't. Thanks for pointing it out. This seems to be a direct link to a web form to report (in English): https://eservices.traficom.fi/ContactForms/form/haavoittuvuu... In particular, note that all the fields asking for personal information disappear if you select "Yes" in "I am submitting an anonymous tip" field.

Just to play devil's advocate, couldn't sending zero-day exploits to a foreign nation's intelligence service potentially cause the sender significantly more trouble.

Just to play devil's advocate

Why?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#209

Earlier quoted context omitted.

Sir, this is not USA, don't assume stuff fucked up there is fucked up everywhere

It's starting to be so common on the internet, clueless US residents not really grokking things aren't as bad in other places as in the US, that I'm starting to think that maybe this is some sort of psychological defense mechanism? You've heard how great and exceptional your country is since you were born, and suddenly evidence is being pointed to that maybe that wasn't so true, so your brain is trying to reason away…

> You've heard how great and exceptional your country is since you were born, and suddenly evidence is being pointed to that maybe that wasn't so true, so your brain is trying to reason away how clearly this can't be true, you cannot been lied to your entire life...

You are describing cognitive dissonance, I suspect most people do have it about their country (unless they really like history in which case they are aware of the fucked up things their country has done and there is much less dissonance) but the average US citizen is very much an outlier by the standard of western countries.

Even the smart ones who do know history often only know their side of it from their point of view and many of them have very little understanding of the world beyond their borders (because they simply have no need to).

They just seem to blur the border between nationalism and patriotism more than most countries.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#210

User also got themselves banned from Gitlab, an unrelated company. Their quotes in the article are threatening violence and destruction toward Microsoft. I don’t know what’s going on, but given that they’re getting banned from multiple unrelated organizations and threatening to “crush their bones” and such, I suspect this is probably just a regular old case of someone being abusive and unhinged, getting banned becaus…

Before we go down the road of analyzing someone's reaction, we should first analyze what they're reacting to: How much money did microsoft bilk this person out of? What is a reasonable reaction to someone taking that much money out of your paycheck?

Also, as a practical matter, maybe do as someone says if they have this many zero days sitting around?

While they may have violated various TOS, it's my understanding that dropping a zero day like one would drop the mic at the end of an epic rant is not inherently illegal.

Maybe don't piss off your betters?

Post reply on HN