Live data from Hacker News

Windows 10 RCE: The exploit is in the link

positive.security

41–50 of 58 posts

Re: Windows 10 RCE: The exploit is in the link

#41
post #28

Earlier quoted context omitted.

https://zerodium.com/ , the going rate for a full exploit there (and I assume, one that works quickly & leaves little trace, i.e. a high quality exploit, never dealt with them before) is 80k. Under the old rules that's already 4x as much as MS, but the warm fuzzies made up for that I suppose. Under the new rules, 40x as much, and no warm fuzzies are worth that imo.

Selling to Zerodium is not equivalent to getting a bounty from MSFT. Selling exploit code hurts people. Microsoft will patch the vuln to protect its customers. Selling exploits to Zerodium is very bad. Be a force for good in this world.

Windows is not a force for good.

> Selling exploit code hurts people.

As providing backdoors for state agents like Microsoft and other companies do.

I'm ignorant on the matter but is Zerodium a black market? As far as I know they might be selling any exploits to the affected companies.

Re: Windows 10 RCE: The exploit is in the link

#42
post #19

People with technical knowledge who prefer to use Windows should have their brains examined.

Except for when you want to play certain games or use Microsoft Office to view proprietary .DOCX documents. I would say don't connect Windows to the Internet, but some games need Internet access to run, so you would be at a loss there. Messing with Office documents can be done offline however :)

With very few exceptions nowadays if a game doesn't run on Linux it's multiplayer based and due to developer choice as both EAC and Battleye supports Linux.

Re: Windows 10 RCE: The exploit is in the link

#43

People with technical knowledge who prefer to use Windows should have their brains examined.

What other options are there? Linux - dismal desktop experience. MacOS - No support for pro engineering programs.

Personally I prefer Gnome UX over Windows at any time. Is it due to bugs and lack of support for things?

Re: Windows 10 RCE: The exploit is in the link

#44

Earlier quoted context omitted.

Selling to Zerodium is not equivalent to getting a bounty from MSFT. Selling exploit code hurts people. Microsoft will patch the vuln to protect its customers. Selling exploits to Zerodium is very bad. Be a force for good in this world.

Windows is not a force for good. > Selling exploit code hurts people. As providing backdoors for state agents like Microsoft and other companies do. I'm ignorant on the matter but is Zerodium a black market? As far as I know they might be selling any exploits to the affected companies.

The logic of business would imply that a vendor of exploit code is going to make significantly more money reselling the exploit than the author of the exploit code. 100k for an exploit to the author? The exploit vendor will sell it for millions. Who has deep pockets enough that they are willing to buy exploit code for millions? A software vendor can engineers for many years for this cost.

Yeah, I don't like windows either, but its not the point. Billions rely on the security of Windows today, our entire global economy is dependent on reliability of our information systems.

One either helps maintain the security of our systems globally, or they seek to disrupt it for a pay day. I get quite upset when people enter with the mindset of 'the actual vendor wont pay me enough, ill sell it to shady exploit market'. It is not a simple pay day.

Re: Windows 10 RCE: The exploit is in the link

#45
post #28

Earlier quoted context omitted.

https://zerodium.com/ , the going rate for a full exploit there (and I assume, one that works quickly & leaves little trace, i.e. a high quality exploit, never dealt with them before) is 80k. Under the old rules that's already 4x as much as MS, but the warm fuzzies made up for that I suppose. Under the new rules, 40x as much, and no warm fuzzies are worth that imo.

Selling to Zerodium is not equivalent to getting a bounty from MSFT. Selling exploit code hurts people. Microsoft will patch the vuln to protect its customers. Selling exploits to Zerodium is very bad. Be a force for good in this world.

If Microsoft doesn't care, why should he?

Re: Windows 10 RCE: The exploit is in the link

#46
post #45

Earlier quoted context omitted.

Selling to Zerodium is not equivalent to getting a bounty from MSFT. Selling exploit code hurts people. Microsoft will patch the vuln to protect its customers. Selling exploits to Zerodium is very bad. Be a force for good in this world.

If Microsoft doesn't care, why should he?

This way of thinking really reflects poorly on security professionals. They should care out of a sense of professional ethics or personal morals. Selling a bug to be fixed by a vendor or to be weaponized by one of Zerodium’s customers are not equivalent morally or ethically. They also aren’t the only two options: he could just sit on the bug. Someone else will likely discover it but he at least wouldn’t be complicit in the erosion of the security of the software ecosystem.

Re: Windows 10 RCE: The exploit is in the link

#47

To see how it works on your machine, simply paste ms-officecmd: into your browser and then see what happens. In MS Edge you _might_ see a popup window This site is trying to open LocalBridge. A website wants to open this application. Other forms of URI in Windows 10 taken from https://www.tenforums.com/tutorials/78214-settings-pages-lis... So paste the below into your Browser ms-settings:nightlight In MS Edge you wil…

A lot of people have purposefully mangled windows to stop Windows Update which stopped the automatic upgrade from EdgeHTML edge to Chrome-based, and a lot of people do just use whatever browser comes with Windows.

These people would not have gotten the patch anyway.

Re: Windows 10 RCE: The exploit is in the link

#48
post #45

Earlier quoted context omitted.

If Microsoft doesn't care, why should he?

This way of thinking really reflects poorly on security professionals. They should care out of a sense of professional ethics or personal morals. Selling a bug to be fixed by a vendor or to be weaponized by one of Zerodium’s customers are not equivalent morally or ethically. They also aren’t the only two options: he could just sit on the bug. Someone else will likely discover it but he at least wouldn’t be complicit…

The security of Microsoft products is Microsoft's responsibility.

Microsoft seems uninterested in fulfilling that responsibility, therefore the responsible thing to do is to "motivate" Microsoft.

Re: Windows 10 RCE: The exploit is in the link

#49
post #28

Earlier quoted context omitted.

https://zerodium.com/ , the going rate for a full exploit there (and I assume, one that works quickly & leaves little trace, i.e. a high quality exploit, never dealt with them before) is 80k. Under the old rules that's already 4x as much as MS, but the warm fuzzies made up for that I suppose. Under the new rules, 40x as much, and no warm fuzzies are worth that imo.

Selling to Zerodium is not equivalent to getting a bounty from MSFT. Selling exploit code hurts people. Microsoft will patch the vuln to protect its customers. Selling exploits to Zerodium is very bad. Be a force for good in this world.

> Access to Zerodium Zero-Day Research Feed is highly restricted and is only available to a very limited number of eligible government institutions.

Sounds like they sell it to the NSA/CIA/FBI so it's used for "national security" and not ransomware worms.

Re: Windows 10 RCE: The exploit is in the link

#50
post #48

Earlier quoted context omitted.

This way of thinking really reflects poorly on security professionals. They should care out of a sense of professional ethics or personal morals. Selling a bug to be fixed by a vendor or to be weaponized by one of Zerodium’s customers are not equivalent morally or ethically. They also aren’t the only two options: he could just sit on the bug. Someone else will likely discover it but he at least wouldn’t be complicit…

The security of Microsoft products is Microsoft's responsibility. Microsoft seems uninterested in fulfilling that responsibility, therefore the responsible thing to do is to "motivate" Microsoft.

Let’s not pretend selling to private buyers is anything other than financially motivated. I don’t think security researchers who sell their vulnerabilities to private buyers are not acting to “motivate” Microsoft in a roundabout way. Even if we assume that is their motivation, such an arrangement is obviously unethical because vulnerabilities sold in this way are weaponized to do harm against others.
Post reply on HN