Live data from Hacker News

Microsoft 0-day feud escalates as researcher threatens another exploit dump

theregister.com

61–70 of 103 posts

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#61

Earlier quoted context omitted.

Is NASA software accessible over the public internet?

Not all, but wouldn't that make a case for more rigorous standards? Economically things must be prioritized, but there is a very big gap between NASA standards and typical commercial software.

To be fair NASA doesn't have to turn a profit.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#62

Earlier quoted context omitted.

Not all, but wouldn't that make a case for more rigorous standards? Economically things must be prioritized, but there is a very big gap between NASA standards and typical commercial software.

To be fair NASA doesn't have to turn a profit.

There are economic realities, but there is a huge gap between not turning a profit and a 36% margin on billions.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#63

It is not all about money, but microsoft had a net income of 101 billion last year, and a 36% profit margin. I am not saying humans or AI can create "perfect" software, but NASA has shown there is a HUGE gap between what can be achieved and what commercial software has generally done. We have given software a pass on the liability for the damage it can caused when it is defective for too long, that's the only way to…

Is NASA software accessible over the public internet?

All the things up there can be contacted with radio. Some downstream data is easly readable. Sending is another thing, but satelites are in public communication space.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#64
post #44

this is from 2010 but says that microsoft was not going to pay bug bounties https://www.computerworld.com/article/1510124/microsoft-no-m... did they start to do that at some point, or is this a pressure (blackmail?) campaign to get the to do that? I have no love for, but rather hate for, Microsoft, so I'm not suggesting blackmail in the sense of defending them, but it's something they could claim. this is on Microsof…

They’re supposed to.

Instead they have a reputation for telling researchers that their disclosure isn’t actually a vulnerability and doesn’t qualify for a bounty or recognition, then quietly patching said non-vulnerability with a suspicious degree of urgency.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#65

I know this is a crazy take. But I go feel so down trodden by many many tech corps these days I find it hard not to have a smidge of satisfaction for this guy pointing out the colossal favour research developers do for them by responsible disclosure. That said, I feel bad for the inevitable victims of exploitation and also I am certain he will end up criminalized or as per usual the law will enforce a large corps wil…

> I am certain he will end up criminalized

DMCA has exemptions for "good faith" security research, whatever that means when interpreted by a judge. Outside of copyright law, not sure what Microsoft could pursue legally. The researcher is just disclosing information. CFAA doesn't apply because it's an operating system, running on their own machine there's no unauthorized access there.

They could drag Eclipse through civil lawsuits though.

But yeah, zero sympathy for Microsoft here from me. They deserve it and what's coming for them, whatever that may be. Consider it karma for their past abuses.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#66
What is Microslop management and PR department doing? How come this can go for a week?

They spent billions trying to build this open source and developer friendly image to just burn it all over $200,000 of unpaid security bounties.

Microsoft is a dumpster fire.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#67
post #59

Attacking the messenger is an age-old trend in the bug reporting arena. Microsoft has the backing of many governments, and has access to the best legal teams possible, leaving this guy in a world of hurt. Microsoft seems to have brought this on themselves by creating a complex and user-hostile bug reporting system. It seems to me that they could have offered this person a job or a contract, because Eclipse has been a…

I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.

Now iOS 0-day is worth up to $2,000,000 on gray market so Apple kind a take it seriously.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#68

I guess I'll play devil's advocate here, don't shoot me. Over the course of my career I've had to deal with multiple hacks, DDOSes, and even situations working with the FBI. It's a mess, and extremely frustrating and unfair to those of us who are just trying to do a good job and make a living. Those of you who are throwing stones at Microsoft's coding, how confident are you that your code is safe from this new AI age…

I don't think it's their fault for not making code without exploits. I do think they should try and close them in a timely fashion when the exploit is pointed out though - the longer they wait the more chance bad actors find it in addition to the security researchers. Ultimately they need to cooperate here for users to be safe.

They should also be fully transparent and not silently patch, and only issue a CVE weeks later after being called out like they did with RedSun, from this same researcher.

That Microsoft releases vulnerable software isn't the issue (that's a known quality at this point), it's their lack of transparency and refusal to hold themselves accountable.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#69
post #67
post #59

Earlier quoted context omitted.

I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.

Now iOS 0-day is worth up to $2,000,000 on gray market so Apple kind a take it seriously.

If you find a real iOS zero day that you think has a market value of 2 million, how do you (a) find a legit buyer for it, and (b) ensure you get paid, presumably in your own choice of cryptocurrency?
Post reply on HN