Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

61–70 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#61
User also got themselves banned from Gitlab, an unrelated company. Their quotes in the article are threatening violence and destruction toward Microsoft.

I don’t know what’s going on, but given that they’re getting banned from multiple unrelated organizations and threatening to “crush their bones” and such, I suspect this is probably just a regular old case of someone being abusive and unhinged, getting banned because of it, and then claiming conspiracy.

What, exactly, did this person post to GitHub and/or Gitlab that got them banned? We should all know by now that any exploits posted to GitHub are cloned and forked everywhere immediately. Why are these articles so vague about what was posted?

Also, these conspiracy theories that the NSA or other .gov is forcing this are quite ridiculous, as it would be infinitely easier for them to just hand the guy a pile of money than to Streisand effect it with a visibly unhinged guy talking about dead man’s switches and crushing bones.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#62

I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.

But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title.

He also got banned from Gitlab, which isn’t related to Microsoft at all.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#63
post #30

Surely, the public string of exploits means he can find gainful employment from any of the various spooks?

I know quite a few extremely skilled people who aren't employed in a technical field. Usually it's some combination of not working well with others, lack of formal credentials and the means to acquire them, or a criminal record. Government work also means you have to be morally okay with what the government does (or willfully ignorant), able to pass a background check, and be willing to go through the security cleara…

People with skills/means don't want to live in the cheap city/suburb where they have offices. Work from home obviously isn't a thing.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#64

Lol, they ban a security researcher from Github for embarassing them, but massgrave's Microsoft Activation Scripts isn't just still on Github but verified ? Make it make sense, Microsoft.

Pirating windows keeps you in the ecosystem so they can sell ads/games/365/cloud etc.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#65
post #15

The optics don't look good for Microsoft, but we don't know their side of the story.

It doesnt really matter. Banning someone GitHub account change literally nothing and its another proof Microsoft is not to be trusted as steward of open source platform.

Worse, cant be trusted to have secure products.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#67

Earlier quoted context omitted.

I don't think you should insert any number of insults into summaries of what other people said. It serves no purpose other than degrading the quality of discussion. If someone posted this comment: > Satya Nadella says as much as 30% of Microsoft code is written by AI. More like Microslop, haha! we'd all recognize that the last sentence is pointless name-calling (and thus violates the HN guidelines). But by interleavi…

It isn't name calling its a fact. Their software was and now increasingly F grade quality. Microslop.

[deleted]

Re: GitHub bans security researcher who posted zero-day Windows exploits

#68

Is there any public word from Microsoft about what is going on here? Why would both Microsoft and Gitlab ban the user? I thought both platforms allowed hosting exploits and security research as long as everything is clearly marked up-front, I'm guessing some rules were broken?

[flagged]

If a government agency wanted to sweep this under the rug, don’t you think they’d just pay the bounties for the guy instead of giving him more ammunition for his crusade?

I think it’s more likely that the guy is just being as abusive to these services as the quotes in the article where he’s talking about crushing their bones

Re: GitHub bans security researcher who posted zero-day Windows exploits

#69
post #30

Surely, the public string of exploits means he can find gainful employment from any of the various spooks?

I know quite a few extremely skilled people who aren't employed in a technical field. Usually it's some combination of not working well with others, lack of formal credentials and the means to acquire them, or a criminal record. Government work also means you have to be morally okay with what the government does (or willfully ignorant), able to pass a background check, and be willing to go through the security cleara…

"People with skills" just don't care for corporate or government bullshit. You may know them as "not being employed in a technical field", but it's just because you got filtered out.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#70

> forcing them to pack up and move shop to GitLab instead. https://gitlab.com/nightmare-eclipse Blocked user @nightmare-eclipse Looks like they’re banned on GitLab as as well?

Are there any copies of what he supposedly posted? I have a hard time believing someone posted groundbreaking exploits to two separate Git websites and not a single person cloned them.

I also think it’s funny that people are alleging .gov conspiracies that end in a publicly hosted “blocked user” page instead of just 404-ing or something.

Post reply on HN