Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

251–260 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#251

Earlier quoted context omitted.

What does this mean and compromised in which sense?

They’re pointing out a proposal that some nodes can block pins, resulting in censorship and that censorship at all would compromise the point of IPFS although I disagree with both of those takes. Nodes always had discretion in IPFS, just pick a different node or pin something yourself which has pretty much always been required. Everyone can route to your pinned files while pinned.

Ah! Ok, when I read compromised I thought it was a proposal that introduced a security vulnerability to the tech. Thanks!

Re: GitHub bans security researcher who posted zero-day Windows exploits

#252
post #80

Earlier quoted context omitted.

Which, if any of the exploits require anything that isn't on-screen (USB or other HID, key combination), requires a reboot, or anything done before Windows has fully booted, means one must have an external camera Doesn't sound like it for these exploits specifically (except Yellow Key), but I could be wrong, and again: that's just for these exploits specifically

> (USB or other HID, key combination) I don't think you'd need an external camera for that. What you're doing would be mentioned in the accompanying report. I do agree with you about the boot process, though.

Personally I'd think Microsoft would be cool with following the report instead of demanding video evidence in the first place, but silly me thinking the trillion dollar multi-national would be reasonable

Re: GitHub bans security researcher who posted zero-day Windows exploits

#253

Is there any public word from Microsoft about what is going on here? Why would both Microsoft and Gitlab ban the user? I thought both platforms allowed hosting exploits and security research as long as everything is clearly marked up-front, I'm guessing some rules were broken?

[dead]

Re: GitHub bans security researcher who posted zero-day Windows exploits

#254

Very important info: https://www.theregister.com/security/2026/05/28/microsoft-0-... In the linked Microsoft blog post, they say : > The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk. So are they lying ? Why would Nightmare-Eclipse not report them if they are not ? It's a very weird situation

[dead]

Re: GitHub bans security researcher who posted zero-day Windows exploits

#255

Earlier quoted context omitted.

Ever considered these aren't the full set of exploits the researcher discovered? Or that he can find more since he found these? If I found a bunch, I'd certainly withhold a few as insurance.

Sure, but GitHub and Gitlab aren’t the only two ways to share code on the Internet. The conspiracy theories about two unrelated companies shutting down his git accounts to prevent him from releasing these supposed exploits are reaching pretty deep into conspiracy theory nonsense. The conspiracy theories can’t even agree if he was banned for posting them or because he hadn’t posted them but might post them.

I can see a situation where Microsoft contacted federal law enforcement to strongarm both GitLab and GitHub. But I believe all megacorps are one giant government conspiracy so consider the source.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#256

Earlier quoted context omitted.

I have now worked for/with a significant percentage of the fortune 500. All used Windows in some capacity. Is this just your way of saying that only tiny, weird, companies are "good"?

These days corporate security treats these workstations like a dummy terminal. No secrets live on the workstation. You have to re-auth with sso constantly with biometrics and are basically editing data that is in a cloud. So the risk to a corp is minimal where even in the worst case they are insured. Zero days like this are being disclosed regularly so the idea of securing a windows workstation is tantalizing but you…

> These days corporate security treats these workstations like a dummy terminal

Correct, "zero trust" is the buzzword but this is how Microsoft even recommends you set up your endpoint infra. Assume breach, treat every endpoint as if it is currently compromised or could be at any time. Laptops are basically ephemeral, when set up right, and can be wiped and re-imaged within an hour or less.

That's not unique to Windows either, that's how all employee/user endpoints should be managed.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#257

Earlier quoted context omitted.

So they can exploit it in secret for their own benefit?

If you have so little trust in your government (maybe you're American?) it might be time for change!

Considering Snowden files have shown they intentionally hoard 0days, I don't think it's so much a lack of trust as it is a proven track record of their behavior.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#258
post #80

Earlier quoted context omitted.

> and the response was flow chart tech support with a "buy a webcam" cherry on top I feel safe in saying that they don't want a video of you at your keyboard typing stuff. An exploit video is a recording of your screen, not of you.

Which, if any of the exploits require anything that isn't on-screen (USB or other HID, key combination), requires a reboot, or anything done before Windows has fully booted, means one must have an external camera Doesn't sound like it for these exploits specifically (except Yellow Key), but I could be wrong, and again: that's just for these exploits specifically

I've used cheap HDMI to USB adapters for that in the past. Worked fine albeit somewhat low res. (Still much better than a camera pointed at a screen.)

Re: GitHub bans security researcher who posted zero-day Windows exploits

#259

Earlier quoted context omitted.

Sure, but GitHub and Gitlab aren’t the only two ways to share code on the Internet. The conspiracy theories about two unrelated companies shutting down his git accounts to prevent him from releasing these supposed exploits are reaching pretty deep into conspiracy theory nonsense. The conspiracy theories can’t even agree if he was banned for posting them or because he hadn’t posted them but might post them.

I can see a situation where Microsoft contacted federal law enforcement to strongarm both GitLab and GitHub. But I believe all megacorps are one giant government conspiracy so consider the source.

At this point, the government is a megacorp conspiracy.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#260

Very important info: https://www.theregister.com/security/2026/05/28/microsoft-0-... In the linked Microsoft blog post, they say : > The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk. So are they lying ? Why would Nightmare-Eclipse not report them if they are not ? It's a very weird situation

>Why would Nightmare-Eclipse not report them if they are not ? Maybe they're a foreign intelligence cutout masquerading as a burned researcher.

>Maybe they're a foreign intelligence cutout masquerading as a burned researcher.

Whoever silently downvoted this, I'd love to hear why you so strongly disagree with my assessment.

Post reply on HN