GitHub bans security researcher who posted zero-day Windows exploits
261–270 of 274 posts
Re: GitHub bans security researcher who posted zero-day Windows exploits
#262Earlier quoted context omitted.
Because you don't agree doesn't make the legitimate callout (i.e., victim-blaming “what were you wearing” vs. calling someone “unhinged” after they've endured repeated abuse/stress) a logical fallacy. Rather it positions you in opposition. Everything you disagree with isn't incorrect.
I don't really see any evidence of abuse in this post, though. It doesn't really say what Microsoft did, other than ban them from github after they said they will "make Microsoft's bones shatter". It reads to me like Microsoft didn't pay him what he thought he earned from the exploits (i have no idea who is in the right on that), and then he published a zero day with no notification and threatened the company. Doesn'…
You are unsure of the details, so you instinctively choose to align with the $3T corporation. Further you assert the responsible discloser is "unhinged" for having a reaction to sustained abusive behavior by that $3T corporation.
Who exactly is unhinged here: the person who had a human reaction to abuse, or the person who thinks they are social in-group status with Microsoft? My vote is on the latter.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#263I'm mostly joking here, but Microsoft is one of few companies that handle cyber security in a way that really incentive people to not report them.
it's either by downplaying impact and not paying or paying very little or doing other researcher hostile activities.
especially that someone here mentioned some time ago that black market pays about 3x for the same class of vulnerability, so you need fairly high moral standards to go direct way
Re: GitHub bans security researcher who posted zero-day Windows exploits
#264Earlier quoted context omitted.
Ever considered these aren't the full set of exploits the researcher discovered? Or that he can find more since he found these? If I found a bunch, I'd certainly withhold a few as insurance.
Sure, but GitHub and Gitlab aren’t the only two ways to share code on the Internet. The conspiracy theories about two unrelated companies shutting down his git accounts to prevent him from releasing these supposed exploits are reaching pretty deep into conspiracy theory nonsense. The conspiracy theories can’t even agree if he was banned for posting them or because he hadn’t posted them but might post them.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#265Earlier quoted context omitted.
> They seem to have a personal vendetta against Microsoft Probably because they were forced to use MS-DOS when so many better options were killed off by Microsoft's monopolistic and anti-consumer underhanded business tactics... I might be projecting.
What were the "so many better options" during that period? Have we found the only remaining CP/M fan?
CP/M was great on Z80 systems. But a 386 was capable of so much more.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#266Earlier quoted context omitted.
a bit later, but not much: OS/2
The fizzling of OS/2 was as much IBM's fault as anything. If they'd paid more attention to it sooner, MS might never have shipped Windows; they'd just have made their office applications OS/2 GUI programs. But IBM was too fixated on its mainframes to realize that they were giving away the PC market to MS (again--they did it the first time by licensing DOS to MS).
Re: GitHub bans security researcher who posted zero-day Windows exploits
#267No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…
The bug this guy brings up is very obviously a Bitlocker backdoor and raises very serious questions about what Microsoft is doing with the encryption. Pretty certainly they're able to decode the volumes without the user's key, which is extremely concerning. Looks like they're trying to make it disappear, but it's in the wild now.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#268Earlier quoted context omitted.
The fizzling of OS/2 was as much IBM's fault as anything. If they'd paid more attention to it sooner, MS might never have shipped Windows; they'd just have made their office applications OS/2 GUI programs. But IBM was too fixated on its mainframes to realize that they were giving away the PC market to MS (again--they did it the first time by licensing DOS to MS).
Wait, did IBM license DOS to Microsoft? I thought IBM was looking for an operating system for the PC and approached Kildall about CP/M. That deal fell through, so they approached Microsoft. Gates didn't have anything, so he licensed QDOS for a song and licensed it to IBM.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#269Re: GitHub bans security researcher who posted zero-day Windows exploits
#270Earlier quoted context omitted.
If you have so little trust in your government (maybe you're American?) it might be time for change!
No shit. Mind telling us how? Because elections sure aren’t going to do it. edit: sorry, there is so much of this sentiment, and the system is proven to be rigged. We know that things have gotten bad. Really bad. And there’s little hope of it self-correcting. The corruption is too deep and now seems unabashed. I seriously do want advice on how to change things, but three out of the four boxes meant to preserve libert…
I believe that all systems which promote and enforce radical patriotism "no matter what" are bound to end up there.
It's also getting more and more difficult for your country to keep allies, what with bombing and assaulting every single possible place for maximum profit extraction. Lots of people in the world have a hatred for the USA (as an entity) that is only paralleled by e.g. Nazi Germany.
The only way to make a change is to get up and make a change, and if you can't because you're that deep in the hole, as you said, violent upheaval.
I really wish that the USA would just wake up one morning and decide to make a change, without violence and bloodshed, to look at other Western countries for inspiration and create a more human society.