Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

231–240 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#231
post #163

Earlier quoted context omitted.

If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to th…

> If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. The CCC (Chaos Computer Club) in germany will probably do the same.

I knew I had heard of CCC from somewhere buts its https://ccc.de which includes the https://media.ccc.de

There are some really decent technical videos on it, CCC is really awesome!

Really loved this talk in particular from CCC: https://media.ccc.de/v/33c3-8314-bootstraping_a_slightly_mor...

Re: GitHub bans security researcher who posted zero-day Windows exploits

#232

I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.

Why would they regret it? According to the person who found them, they put those vulnerabilities there for a reason.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#233
post #172

Earlier quoted context omitted.

You now have the worst of both worlds. You report yourself to the police for trying to hack into a computer-system and you report yourself to the website that can now decide to sue you. All of that without any benefits.

Is this purely theoretical? Asking since we don’t wanna encourage making the world worse if there is indeed a clever way to stay safe - has anyone been hassled after reporting to the Finnish Cyber Security Centre?

Well I'm a Finn and have reported my findings to the FCSC. Zero hassle. The folks at Traficom are a really nice and smart bunch, I have had chats with them face to face a couple of times. They are very well versed when it comes to potential issues or hassles with disclosing exploits. From what I've seen, everyone at Traficom really just wants to keep internet and information systems safe, and to provide the best support possible for IT professionals regarding cyber/information security.

You can also submit anonymously and/or via secure email: https://www.traficom.fi/en/contact-details/sending-secure-em...

This is what their privacy statement says: “Data breach information, including personal data, can be exchanged confidentially with other authorities relevant to the breach when required or permitted by law. The person who fills out the form is asked if they consent to the transfer of information to another authority."

Re: GitHub bans security researcher who posted zero-day Windows exploits

#235
Microsoft owns Github and Windows, makes sense. "Security researchers" love attention however, and I'm going to guess this one knew it would happen and is now making hay on the fact that it did. Now let me roll out the tired authoritarian excuses to wrap up the thread.

>It's a private company. They can do what they want.

>Freedom of speech isn't freedom from consequences.

>Build your own github.

Did I miss any?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#236
post #136

Earlier quoted context omitted.

It's had bad news only for Windows buerocrats. Good orgs don't use Windows.

I have now worked for/with a significant percentage of the fortune 500. All used Windows in some capacity. Is this just your way of saying that only tiny, weird, companies are "good"?

It's saying that those with Windows could be 100x more effective and secure. Wasting billions of money and a lot of time

Re: GitHub bans security researcher who posted zero-day Windows exploits

#237

Earlier quoted context omitted.

You could try reporting them (the exploits) anonymously to a government agency

So they can exploit it in secret for their own benefit?

If you have so little trust in your government (maybe you're American?) it might be time for change!

Re: GitHub bans security researcher who posted zero-day Windows exploits

#238
post #172
post #163

Earlier quoted context omitted.

If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to th…

You now have the worst of both worlds. You report yourself to the police for trying to hack into a computer-system and you report yourself to the website that can now decide to sue you. All of that without any benefits.

Reporting software vulnerabilites in Germany is the dumbest thing you can do, you WILL be arrested. There is a recent case where some company had a hardcoded database password in their EXE file and if you open it with e.g. Notepad you can see it and this already counts as "illegal hacking". https://www.heise.de/en/news/Federal-Constitutional-Court-re...

Re: GitHub bans security researcher who posted zero-day Windows exploits

#239
post #229

Earlier quoted context omitted.

Were you somehow able to intuit that parent is Finnish? I'm intrigued by your post -- I used to tell people send things like this to CERT/CC... but it's been so long since I dabbled in that world that my contacts have departed and the current administration is so erratic that paired with Finland's recent rejection of neutrality and ascension into NATO that I would frankly agree that your CERT may be a better fit for…

> the current administration is so erratic that paired with Finland's recent rejection of neutrality and ascension into NATO Not sure if this is what you mean, the comment is rather confusing to me (Finland was ever neutral? Between which states, surely not EU and Russia as they sit between? Which administration relates to Finland and is unreliable? Why would you need personal contacts to report vulnerabilities to a…

That now that they've joined NATO, it's safe to share with them.

A "neutral" country might abuse them.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#240
post #131

I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful…

sell them to a vuln or exploit broker. problem solved.
Post reply on HN