Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

241–250 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#241

Earlier quoted context omitted.

So they can exploit it in secret for their own benefit?

If you have so little trust in your government (maybe you're American?) it might be time for change!

No shit. Mind telling us how? Because elections sure aren’t going to do it.

edit: sorry, there is so much of this sentiment, and the system is proven to be rigged. We know that things have gotten bad. Really bad. And there’s little hope of it self-correcting. The corruption is too deep and now seems unabashed. I seriously do want advice on how to change things, but three out of the four boxes meant to preserve liberty have proven to be inadequate. I see no future that doesn’t involve violent upheaval. Convince me otherwise.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#242
post #171

Earlier quoted context omitted.

I wouldn't be surprised if this was intentionally put in, but I think its important to clarify that the encryption itself wasn't broken, and with this exploit specifically the drive also has to remain inside the original PC/TPM. It's a boot authentication bypass, not an encryption break. As far as we know, having TPM+Pin or TPM+Startup Key breaks the exploit. TPM only was always known to be basically ineffective agai…

I know someone who works for a nefarious gov org and they never put the bitlocker keys in the TPM on their laptops. You have to enter the password yourself on power up. Wonder if they knew about this.

The key is still in the TPM in that scenario it just requires a password to unlock it.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#243
post #83

Earlier quoted context omitted.

I always found it weird to ship a BASIC interpreter that didn't have specialised commands (unless you count POKE) to access the graphics and sound capabilities of a computer like the C64. Some computers of the same era had vastly superior BASICs (such as Sinclair BASIC).

I agree, it seems very low-effort on Commodore's part to license this lowest-common-denominator BASIC with no support for graphics and sound other than POKE. Super lame, but they got away with it.

No they didn’t. If they had, I would be typing this on my Commodore phone.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#244

In the past recent months i've been dealing with a lot of strange digital responses at various related things. It caused a lot of frustration and i couldn't exactly pinpoint what i was doing wrong. Then i read this sentence in the article: "But to save money, Microsoft fired the skilled people, leaving flowchart followers." Flowchart followers.. Now those are nice words to remember. It says it all. Not paid to think,…

A lot of blue collar trades - mechanic/electrician/builder etc following the `flowchart` is the `law` of the land and process is written in blood and liability Whereas IT/Ops/developers see themselves as artisinal, free thinking, intellectual beings. Where skill is related to shortcuts, hacks, and thinking outside the box compared to following process

It depends what your skill set is - professional engineers are qualified to make the flowcharts and sign off on designs. So it’s not about how you see yourself, it’s whether you have the experience and training to be able to follow actual engineering methodology.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#246

Earlier quoted context omitted.

Just to play devil's advocate, couldn't sending zero-day exploits to a foreign nation's intelligence service potentially cause the sender significantly more trouble.

Just to play devil's advocate Why?

Because information asymmetry benefits those with the information. If the devil understands your argument, and you don't understand the devil's argument, the devil will have information advantage.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#247
post #144

Earlier quoted context omitted.

Sadly, IPFS is compromised[0]. 0. https://specs.ipfs.tech/ipips/ipip-0383/

What does this mean and compromised in which sense?

They’re pointing out a proposal that some nodes can block pins, resulting in censorship

and that censorship at all would compromise the point of IPFS

although I disagree with both of those takes. Nodes always had discretion in IPFS, just pick a different node or pin something yourself which has pretty much always been required. Everyone can route to your pinned files while pinned.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#248

Earlier quoted context omitted.

Just to play devil's advocate Why?

Because information asymmetry benefits those with the information. If the devil understands your argument, and you don't understand the devil's argument, the devil will have information advantage.

Not everything in life deserves to have both sides aired.

For example, the Internet giving every crackpot wingnut on Earth an equal voice with scientists is how we end up with measles outbreaks.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#249
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

To corroborate, working in bug bounty triage, I never saw any evidence of reluctance to pay out.† The worst company-side behavior I observed was asking researchers to "please stay away from X" in their proof-of-concepts and then making higher payouts to researchers who ignored that instruction (because, after all, the demonstrated risk was higher!). On the other side of things, I saw one major program pay out at an i…

It happened many times to me, especially on H1 but also from senior FAANG engineers on their mailing lists. If your job is to pretend all is fine it is easy to discard valid reports.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#250
post #194

Earlier quoted context omitted.

It's at the minimum a bit impolite to leave the system more vulnerable in between sending the report and the report being received and acted on.

It didn't become any more vulnerable. This is security, you have to have procedures for when you get owned; the bug bounty program is orthogonal to that. If they wiped prod db and put up goatse on my site I would have still paid and said thank you provided I was told how that was done.

> It didn't become any more vulnerable.

That depends on how secret the URL was. If you go from needing an exploit to just visiting a guessable link, that's significantly more vulnerable.

> If they wiped prod db and put up goatse on my site I would have still paid and said thank you provided I was told how that was done.

Well most people wouldn't, and for good reason.

Post reply on HN