Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

51–60 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#51

Is there any public word from Microsoft about what is going on here? Why would both Microsoft and Gitlab ban the user? I thought both platforms allowed hosting exploits and security research as long as everything is clearly marked up-front, I'm guessing some rules were broken?

Well if it’s a full disk encryption exploit that still requires hardware access I imagine it would have been made for a 3-letter govt org or something

The fde encryption exploit is only for volumes that auto decrypt anyway. So it's a know (accepted) that the model doesn't really try to avoid.

You guys need to stop reaching for conspiracy

Re: GitHub bans security researcher who posted zero-day Windows exploits

#52
post #43

What's the backstory on this researcher? They seem to have a personal vendetta against Microsoft and thus releasing zero days that he found with the help of AI? Seems like the gold rush period is over for bounty hunters and its more about who has access to hardware/token capital.

It sounds like they're pissed because they produced a large number of high-value exploits, sent them to MS, were treated like crap, and then MS refused to honor their own published bounties: > But to save money, Microsoft fired the skilled people, leaving flowchart followers. I wouldn't be surprised if Microsoft closed the case after the reporter refused to submit a video of the exploit, since that's apparently an MS…

> If this researcher actually had a vendetta, I'd expect them to just sell the remaining zero-days to the highest bidder.

selling to the highest bidder doesn’t generate headlines though.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#54

Lol, they ban a security researcher from Github for embarassing them, but massgrave's Microsoft Activation Scripts isn't just still on Github but verified ? Make it make sense, Microsoft.

Microsoft hasn’t particuarly cared about consumers pirating Windows for more than a decade. I’m pretty sure they make close to 0 money off Windows licensing to consumers.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#55
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

It all started because the bureaucracy refused to even consider Bluehammer when they couldn't cajole the reporter into providing video footage. And then to double down and ban accounts because you'd rather not fix the bureaucracy is really just a bad look. I'm not quite sure why MS is getting the benefit of the doubt from you.

They're not. These programs make decisions I wouldn't make all the time (though for reasons more complicated than message board discussions capture). I'm making a much narrower claim than you think I am.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#56

Earlier quoted context omitted.

I disagree with policing someone elses language like this in the first place, but it's only one insult and it's just "Microslop".

I don't think you should insert any number of insults into summaries of what other people said. It serves no purpose other than degrading the quality of discussion. If someone posted this comment: > Satya Nadella says as much as 30% of Microsoft code is written by AI. More like Microslop, haha! we'd all recognize that the last sentence is pointless name-calling (and thus violates the HN guidelines). But by interleavi…

It isn't name calling its a fact. Their software was and now increasingly F grade quality. Microslop.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#57
post #43

What's the backstory on this researcher? They seem to have a personal vendetta against Microsoft and thus releasing zero days that he found with the help of AI? Seems like the gold rush period is over for bounty hunters and its more about who has access to hardware/token capital.

It sounds like they're pissed because they produced a large number of high-value exploits, sent them to MS, were treated like crap, and then MS refused to honor their own published bounties: > But to save money, Microsoft fired the skilled people, leaving flowchart followers. I wouldn't be surprised if Microsoft closed the case after the reporter refused to submit a video of the exploit, since that's apparently an MS…

> and the response was flow chart tech support with a "buy a webcam" cherry on top

I feel safe in saying that they don't want a video of you at your keyboard typing stuff. An exploit video is a recording of your screen, not of you.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#58

Earlier quoted context omitted.

Well if it’s a full disk encryption exploit that still requires hardware access I imagine it would have been made for a 3-letter govt org or something

The fde encryption exploit is only for volumes that auto decrypt anyway. So it's a know (accepted) that the model doesn't really try to avoid. You guys need to stop reaching for conspiracy

Which is all of them that don't require a pin (rare).

Re: GitHub bans security researcher who posted zero-day Windows exploits

#59
post #22
post #18

Earlier quoted context omitted.

I don’t like the idea Microsoft can bully other websites into blocking content they don’t like.

Do we have any evidence they did that other than the comment you replied to speculating?

Yes they definitely did that. Find evidence to the contrary.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#60
A perfect storm of GitHub's own self-destruction and downfall all done by themselves.

Microsoft is playing with fire against a researcher that has a track record of finding 0 days out of thin air. Quite a dumb thing to do.

This researcher should instead pivot to crypto smart contract bounties instead. A much larger payout there instead of compaines like Microsoft.

Post reply on HN