Earlier quoted context omitted.
Is NASA software accessible over the public internet?
Not all, but wouldn't that make a case for more rigorous standards? Economically things must be prioritized, but there is a very big gap between NASA standards and typical commercial software.
Microsoft 0-day feud escalates as researcher threatens another exploit dump
61–70 of 103 posts
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#62Earlier quoted context omitted.
Not all, but wouldn't that make a case for more rigorous standards? Economically things must be prioritized, but there is a very big gap between NASA standards and typical commercial software.
To be fair NASA doesn't have to turn a profit.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#63It is not all about money, but microsoft had a net income of 101 billion last year, and a 36% profit margin. I am not saying humans or AI can create "perfect" software, but NASA has shown there is a HUGE gap between what can be achieved and what commercial software has generally done. We have given software a pass on the liability for the damage it can caused when it is defective for too long, that's the only way to…
Is NASA software accessible over the public internet?
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#64this is from 2010 but says that microsoft was not going to pay bug bounties https://www.computerworld.com/article/1510124/microsoft-no-m... did they start to do that at some point, or is this a pressure (blackmail?) campaign to get the to do that? I have no love for, but rather hate for, Microsoft, so I'm not suggesting blackmail in the sense of defending them, but it's something they could claim. this is on Microsof…
Instead they have a reputation for telling researchers that their disclosure isn’t actually a vulnerability and doesn’t qualify for a bounty or recognition, then quietly patching said non-vulnerability with a suspicious degree of urgency.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#65I know this is a crazy take. But I go feel so down trodden by many many tech corps these days I find it hard not to have a smidge of satisfaction for this guy pointing out the colossal favour research developers do for them by responsible disclosure. That said, I feel bad for the inevitable victims of exploitation and also I am certain he will end up criminalized or as per usual the law will enforce a large corps wil…
DMCA has exemptions for "good faith" security research, whatever that means when interpreted by a judge. Outside of copyright law, not sure what Microsoft could pursue legally. The researcher is just disclosing information. CFAA doesn't apply because it's an operating system, running on their own machine there's no unauthorized access there.
They could drag Eclipse through civil lawsuits though.
But yeah, zero sympathy for Microsoft here from me. They deserve it and what's coming for them, whatever that may be. Consider it karma for their past abuses.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#66They spent billions trying to build this open source and developer friendly image to just burn it all over $200,000 of unpaid security bounties.
Microsoft is a dumpster fire.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#67Attacking the messenger is an age-old trend in the bug reporting arena. Microsoft has the backing of many governments, and has access to the best legal teams possible, leaving this guy in a world of hurt. Microsoft seems to have brought this on themselves by creating a complex and user-hostile bug reporting system. It seems to me that they could have offered this person a job or a contract, because Eclipse has been a…
I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#68I guess I'll play devil's advocate here, don't shoot me. Over the course of my career I've had to deal with multiple hacks, DDOSes, and even situations working with the FBI. It's a mess, and extremely frustrating and unfair to those of us who are just trying to do a good job and make a living. Those of you who are throwing stones at Microsoft's coding, how confident are you that your code is safe from this new AI age…
I don't think it's their fault for not making code without exploits. I do think they should try and close them in a timely fashion when the exploit is pointed out though - the longer they wait the more chance bad actors find it in addition to the security researchers. Ultimately they need to cooperate here for users to be safe.
That Microsoft releases vulnerable software isn't the issue (that's a known quality at this point), it's their lack of transparency and refusal to hold themselves accountable.
Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump
#69Earlier quoted context omitted.
I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.
Now iOS 0-day is worth up to $2,000,000 on gray market so Apple kind a take it seriously.