Live data from Hacker News

Windows 10 RCE: The exploit is in the link

positive.security

51–58 of 58 posts

Re: Windows 10 RCE: The exploit is in the link

#51

Earlier quoted context omitted.

Selling to Zerodium is not equivalent to getting a bounty from MSFT. Selling exploit code hurts people. Microsoft will patch the vuln to protect its customers. Selling exploits to Zerodium is very bad. Be a force for good in this world.

> Access to Zerodium Zero-Day Research Feed is highly restricted and is only available to a very limited number of eligible government institutions. Sounds like they sell it to the NSA/CIA/FBI so it's used for "national security" and not ransomware worms.

Basically saving then the trouble.

Re: Windows 10 RCE: The exploit is in the link

#52
post #48

Earlier quoted context omitted.

The security of Microsoft products is Microsoft's responsibility. Microsoft seems uninterested in fulfilling that responsibility, therefore the responsible thing to do is to "motivate" Microsoft.

Let’s not pretend selling to private buyers is anything other than financially motivated. I don’t think security researchers who sell their vulnerabilities to private buyers are not acting to “motivate” Microsoft in a roundabout way. Even if we assume that is their motivation, such an arrangement is obviously unethical because vulnerabilities sold in this way are weaponized to do harm against others.

The motivational effect is independent of their intent.

Unless you work for free, you don't get to criticize others for getting paid for their work.

Re: Windows 10 RCE: The exploit is in the link

#53
post #48

Earlier quoted context omitted.

The security of Microsoft products is Microsoft's responsibility. Microsoft seems uninterested in fulfilling that responsibility, therefore the responsible thing to do is to "motivate" Microsoft.

Let’s not pretend selling to private buyers is anything other than financially motivated. I don’t think security researchers who sell their vulnerabilities to private buyers are not acting to “motivate” Microsoft in a roundabout way. Even if we assume that is their motivation, such an arrangement is obviously unethical because vulnerabilities sold in this way are weaponized to do harm against others.

Microsoft is not a financially struggling company. I don't think management cares about security.

Re: Windows 10 RCE: The exploit is in the link

#54
post #28

Earlier quoted context omitted.

https://zerodium.com/ , the going rate for a full exploit there (and I assume, one that works quickly & leaves little trace, i.e. a high quality exploit, never dealt with them before) is 80k. Under the old rules that's already 4x as much as MS, but the warm fuzzies made up for that I suppose. Under the new rules, 40x as much, and no warm fuzzies are worth that imo.

Selling to Zerodium is not equivalent to getting a bounty from MSFT. Selling exploit code hurts people. Microsoft will patch the vuln to protect its customers. Selling exploits to Zerodium is very bad. Be a force for good in this world.

It's Microsoft, the Steve Ballmer (also Teams) Company, they hurt people more than Zerodium can even think of.

Re: Windows 10 RCE: The exploit is in the link

#55

People with technical knowledge who prefer to use Windows should have their brains examined.

It's me, I have technical knowledge and prefer to use Windows. I've shipped production apps that are used by millions of people every day (including probably you) on every desktop operating system. Ask Me Anything about my Brain

How long have you been unemployed and how are you derelict?

Re: Windows 10 RCE: The exploit is in the link

#56
post #52

Earlier quoted context omitted.

Let’s not pretend selling to private buyers is anything other than financially motivated. I don’t think security researchers who sell their vulnerabilities to private buyers are not acting to “motivate” Microsoft in a roundabout way. Even if we assume that is their motivation, such an arrangement is obviously unethical because vulnerabilities sold in this way are weaponized to do harm against others.

The motivational effect is independent of their intent. Unless you work for free, you don't get to criticize others for getting paid for their work.

> Unless you work for free, you don't get to criticize others for getting paid for their work.

This is completely ridiculous. By this reasoning we shouldn’t criticize corrupt politicians or anyone whose chosen profession means they get paid to make the world a worse place to live. I don’t think we’ll see eye to eye on any of this, I simply can’t understand any of the arguments you’ve presented to justify getting paid to make the world a more dangerous place.

Re: Windows 10 RCE: The exploit is in the link

#57
post #52

Earlier quoted context omitted.

The motivational effect is independent of their intent. Unless you work for free, you don't get to criticize others for getting paid for their work.

> Unless you work for free, you don't get to criticize others for getting paid for their work. This is completely ridiculous. By this reasoning we shouldn’t criticize corrupt politicians or anyone whose chosen profession means they get paid to make the world a worse place to live. I don’t think we’ll see eye to eye on any of this, I simply can’t understand any of the arguments you’ve presented to justify getting paid…

We're not going to see eye-to-eye because you think that other folks should work for free to make Microsoft products more secure.

I think that when security problems in Microsoft products are Microsoft's responsibility and no one else's. By insisting that other people work for free to improve that security, you're arguing that other people are responsible for said security problems.

That's a curious position. You think that someone who isn't paid is responsible, but not Microsoft, who is paid.

I understand why Microsoft would like that arrangement, but why do think that anything else is wrong?

Re: Windows 10 RCE: The exploit is in the link

#58

Earlier quoted context omitted.

It's me, I have technical knowledge and prefer to use Windows. I've shipped production apps that are used by millions of people every day (including probably you) on every desktop operating system. Ask Me Anything about my Brain

How long have you been unemployed and how are you derelict?

-7 days so far.
Post reply on HN