Live data from Hacker News

Microsoft 0-day feud escalates as researcher threatens another exploit dump

theregister.com

51–60 of 103 posts

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#51

I know this is a crazy take. But I go feel so down trodden by many many tech corps these days I find it hard not to have a smidge of satisfaction for this guy pointing out the colossal favour research developers do for them by responsible disclosure. That said, I feel bad for the inevitable victims of exploitation and also I am certain he will end up criminalized or as per usual the law will enforce a large corps wil…

Naw totally agree, we need way more robust protections for security researchers and way harsher penalties for corpos doing bullshit, it should be a percentage of revenue.

We have way too much fuck around these days and not nearly enough find out.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#52

I guess I'll play devil's advocate here, don't shoot me. Over the course of my career I've had to deal with multiple hacks, DDOSes, and even situations working with the FBI. It's a mess, and extremely frustrating and unfair to those of us who are just trying to do a good job and make a living. Those of you who are throwing stones at Microsoft's coding, how confident are you that your code is safe from this new AI age…

I don't think it's their fault for not making code without exploits. I do think they should try and close them in a timely fashion when the exploit is pointed out though - the longer they wait the more chance bad actors find it in addition to the security researchers. Ultimately they need to cooperate here for users to be safe.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#53
post #46

Responding to bug bounty reports is a thankless job. Especially these days it's a flood of AI spam, language barriers, "pay me first", incomplete reports, huge egos, and people who think every find should be treated as a critical vulnerability. The people who handle these reports often do so after-hours or on holidays. In smaller companies they're also often the ones who manage the triage, patching, testing, and secu…

> The people who handle these reports often do so after-hours or on holidays.

If that's the case at Microsoft, something is absurdly wrong.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#54

It is not all about money, but microsoft had a net income of 101 billion last year, and a 36% profit margin. I am not saying humans or AI can create "perfect" software, but NASA has shown there is a HUGE gap between what can be achieved and what commercial software has generally done. We have given software a pass on the liability for the damage it can caused when it is defective for too long, that's the only way to…

Is NASA software accessible over the public internet?

Not all, but wouldn't that make a case for more rigorous standards? Economically things must be prioritized, but there is a very big gap between NASA standards and typical commercial software.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#55
post #30

Earlier quoted context omitted.

TPM-only saves you against someone pulling your drive. Probably more than enough for a USB drive. Enable startup PIN if you’re worried about someone grabbing the whole laptop.

I think it does not make much sense to protect the USB drive, as you won't be able to access it from another computer which is what USB drives are for. It makes sense to protect interval drives, but it is unlikely that someone would remove the drives and leave an expensive laptop to the owner.

I think of TPM-only more like a privacy lock than a deadbolt.

An encrypted external drive though works like a safe. Put things in there you want to keep safe but don’t need every day. Air gapped while not in use makes it even more safe.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#56
Attacking the messenger is an age-old trend in the bug reporting arena.

Microsoft has the backing of many governments, and has access to the best legal teams possible, leaving this guy in a world of hurt.

Microsoft seems to have brought this on themselves by creating a complex and user-hostile bug reporting system. It seems to me that they could have offered this person a job or a contract, because Eclipse has been amazingly effective at uncovering high-severity exploits.

Also, Eclipse could have approached various governments offering the exploits for sale, because a lucrative market exists for such things, assuming they aren't already in the NSA portfolio. Lots of above-board companies do the same thing.

Quotes in this article blame Eclipse for the damage, but the blame should really rest with Microsoft. Eclipse is apparently just one person using an AI framework. Microsoft has vastly more resources to discover and fix problems with their products, but they never seem to do it themselves.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#57
post #19

The best interests of the customers of Microsoft is an immediate apology, a payment of at least $100,000, and a signed agreement pledging that no (further) legal action will be taken. The denial of Microsoft is just as harmful as the exploits of these flaws.

or everyone just dump all their exploits on Saturday morning 2AM, then buy puts.

You don't want to go short on a company when that happens, you want to go long.

Amazon stock goes up when AWS bugs take down the entire internet, because everyone realizes that more of the internet depends on Amazon than they thought.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#58

I know this is a crazy take. But I go feel so down trodden by many many tech corps these days I find it hard not to have a smidge of satisfaction for this guy pointing out the colossal favour research developers do for them by responsible disclosure. That said, I feel bad for the inevitable victims of exploitation and also I am certain he will end up criminalized or as per usual the law will enforce a large corps wil…

Nothing crazy about it. Crazy is feeling sorry for the trillion dollar corporation. Don't let anyone tell you otherwise.

The right thing is immediate publication of all exploits, zero liability for the researcher who's just doing a public service and maximum liability for the corporation whose criminal negligence enabled the exploits to begin with.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#59

Attacking the messenger is an age-old trend in the bug reporting arena. Microsoft has the backing of many governments, and has access to the best legal teams possible, leaving this guy in a world of hurt. Microsoft seems to have brought this on themselves by creating a complex and user-hostile bug reporting system. It seems to me that they could have offered this person a job or a contract, because Eclipse has been a…

I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#60
Did Microsoft ever explain why Bitlocker could be deliberately circumvented?

Part of me thinks they are welcoming this drama because if the other 0-days are genuine bugs then it muddies the water and shifts the focus away from a the fact that they shipped an intentionally backdoored security product.

Post reply on HN