Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

221–230 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#221

Earlier quoted context omitted.

A quote from Billy G comes to mind > Although about 3 million computers get sold every year in China, people don't pay for the software. Someday they will, though," Gates told an audience at the University of Washington. "And as long as they're going to steal it, we want them to steal ours. They'll get sort of addicted, and then we'll somehow figure out how to collect sometime in the next decade. Microsoft's attitude…

Is there any other OS that gets pirated these days? Are Hackintosh still a thing?

> Are Hackintosh still a thing?

A dying breed, most Intel machines have already fallen out of support and the few remaining ones (e.g. 2019 16-inch MBP) won't get any new OS updates after end of this year.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#222

Earlier quoted context omitted.

You could try reporting them (the exploits) anonymously to a government agency

The German "Chaos Computer Club" (hacker club) has a disclosure service. They approach the affected party as the club, hiding the persons identity. Not sure if they do it internationally as the page is in German. But nice idea and not a government agency. https://www.ccc.de/disclosure

They did notify Collins Aerospace in the past, so I assume they do report internationally.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#223
post #171

Earlier quoted context omitted.

I wouldn't be surprised if this was intentionally put in, but I think its important to clarify that the encryption itself wasn't broken, and with this exploit specifically the drive also has to remain inside the original PC/TPM. It's a boot authentication bypass, not an encryption break. As far as we know, having TPM+Pin or TPM+Startup Key breaks the exploit. TPM only was always known to be basically ineffective agai…

I know someone who works for a nefarious gov org and they never put the bitlocker keys in the TPM on their laptops. You have to enter the password yourself on power up. Wonder if they knew about this.

You don't need to be thinking of any specific vulnerability to realize that putting the decryption key next to the data you're trying to protect is a dumb idea.

If for example a laptop like that gets lost or stolen, the attacker has the data and the key, in a box they physically hold, with no attempt limit, and unless they actively mess with the boot process, it will happily load the key into memory for them. If it's a discrete TPM the attacker can likely sniff the key on the wire. If that doesn't work, they just need to find a vuln anywhere in the secure boot process, or in Windows, and again, they have the key. And if that doesn't work, they could sniff the memory bus, or do a cold boot attack (again, with unlimited attempts unless they irreparably damage the mainboard/TPM in the process).

Re: GitHub bans security researcher who posted zero-day Windows exploits

#224

Earlier quoted context omitted.

Sir, this is not USA, don't assume stuff fucked up there is fucked up everywhere

It's starting to be so common on the internet, clueless US residents not really grokking things aren't as bad in other places as in the US, that I'm starting to think that maybe this is some sort of psychological defense mechanism? You've heard how great and exceptional your country is since you were born, and suddenly evidence is being pointed to that maybe that wasn't so true, so your brain is trying to reason away…

That sounds a lot like the assumption that crime rates are better in less populous areas - just because there is less reporting doesn't mean that it isn't there.

Have you been to the US? If not how can you be certain that the US is truly worse?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#225
post #136

Earlier quoted context omitted.

It's had bad news only for Windows buerocrats. Good orgs don't use Windows.

I have now worked for/with a significant percentage of the fortune 500. All used Windows in some capacity. Is this just your way of saying that only tiny, weird, companies are "good"?

These days corporate security treats these workstations like a dummy terminal. No secrets live on the workstation. You have to re-auth with sso constantly with biometrics and are basically editing data that is in a cloud. So the risk to a corp is minimal where even in the worst case they are insured.

Zero days like this are being disclosed regularly so the idea of securing a windows workstation is tantalizing but you'll never feel satiated trying to drink that water so don't even try.

So yea there's plenty of windows users but we're certainly not hosting anything important on those boxes and would frankly be aghast at the suggestion.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#226

In the past recent months i've been dealing with a lot of strange digital responses at various related things. It caused a lot of frustration and i couldn't exactly pinpoint what i was doing wrong. Then i read this sentence in the article: "But to save money, Microsoft fired the skilled people, leaving flowchart followers." Flowchart followers.. Now those are nice words to remember. It says it all. Not paid to think,…

A lot of blue collar trades - mechanic/electrician/builder etc following the `flowchart` is the `law` of the land and process is written in blood and liability Whereas IT/Ops/developers see themselves as artisinal, free thinking, intellectual beings. Where skill is related to shortcuts, hacks, and thinking outside the box compared to following process

These get trained to be able to reason about why the flowchart is the way it is or outright to construct it. If you can't create a flowchart yourself, you shouldn't direct work following it. Following the flowchart is, so that you don't make mistakes on execution, because there will eventually be mistakes, it's not intended that it saves you from knowing what you do in the first place. In other words: you follow a flowchart to prevent accidental deviations from the process. Once you question, what you actually should do, the flowchart is useless as guidance.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#227
post #173

Earlier quoted context omitted.

If it's anything like the Dutch or German infosec agencies, "worst of both worlds" is about as far from the truth as you can get. Maybe it works that way in Saudi Arabia but it's not "reporting yourself" here

I wouldn't trust anything like that in Germany, where everything is rules-based. Hacking is illegal, so if the police find out you hacked and can prove it, they will arrest you and you will be convicted, period. In Germany there's no common sense applied to the rules. Arguing that you hacked and then reported it responsibly won't reduce your criminal penalty for hacking.

> I wouldn't trust anything like that in Germany [...] Hacking is illegal, so if the police find out you hacked and can prove it, they will arrest you and you will be convicted, period.

This is rather hilarious to read as a reply to someone whose day job is literally hacking in Germany. We document it for tax reasons and sometimes are even allowed to publish it, too! Besides paying clients, we also "hack" (read: help secure) projects and blog about the vulnerabilities we've found and what the disclosure timeline was

Clearly this doesn't work as a blanket statement and coordinated vulnerability disclosure is a thing here. I can agree there are caveats but the statements as made aren't accurate

As for dealing with the government, so far as I'm aware, none of us have had bad experiences with the German IT security agency (BSI) whenever a vendor was being uncooperative (healthcare vendors tend to be very, let's say, German about whose responsibility it is when their device sends genital pictures over a network with no encryption or authentication option available in the software)

Re: GitHub bans security researcher who posted zero-day Windows exploits

#228

Earlier quoted context omitted.

Just to play devil's advocate, couldn't sending zero-day exploits to a foreign nation's intelligence service potentially cause the sender significantly more trouble.

Just to play devil's advocate Why?

it's a good question

Re: GitHub bans security researcher who posted zero-day Windows exploits

#229
post #163

Earlier quoted context omitted.

If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to th…

Were you somehow able to intuit that parent is Finnish? I'm intrigued by your post -- I used to tell people send things like this to CERT/CC... but it's been so long since I dabbled in that world that my contacts have departed and the current administration is so erratic that paired with Finland's recent rejection of neutrality and ascension into NATO that I would frankly agree that your CERT may be a better fit for…

> the current administration is so erratic that paired with Finland's recent rejection of neutrality and ascension into NATO

Not sure if this is what you mean, the comment is rather confusing to me (Finland was ever neutral? Between which states, surely not EU and Russia as they sit between? Which administration relates to Finland and is unreliable? Why would you need personal contacts to report vulnerabilities to a CERT? Etc), but they weren't rejected for NATO membership: https://en.wikipedia.org/wiki/Finland%E2%80%93NATO_relations opens with

> Finland has been a member of the North Atlantic Treaty Organization (NATO) since 4 April 2023.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#230

Earlier quoted context omitted.

I should have known this exists, yet I didn't. Thanks for pointing it out. This seems to be a direct link to a web form to report (in English): https://eservices.traficom.fi/ContactForms/form/haavoittuvuu... In particular, note that all the fields asking for personal information disappear if you select "Yes" in "I am submitting an anonymous tip" field.

Just to play devil's advocate, couldn't sending zero-day exploits to a foreign nation's intelligence service potentially cause the sender significantly more trouble.

It depends on the country apparently:

"Israel reached out to US hackers for ‘Zero Days’ tools" - https://www.timesofisrael.com/israel-reached-out-to-us-hacke...

Post reply on HN