Live data from Hacker News

Microsoft 0-day feud escalates as researcher threatens another exploit dump

theregister.com

71–80 of 103 posts

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#71
post #67

Earlier quoted context omitted.

Now iOS 0-day is worth up to $2,000,000 on gray market so Apple kind a take it seriously.

If you find a real iOS zero day that you think has a market value of 2 million, how do you (a) find a legit buyer for it, and (b) ensure you get paid, presumably in your own choice of cryptocurrency?

https://en.wikipedia.org/wiki/Market_for_zero-day_exploits

https://en.wikipedia.org/wiki/Cyber-arms_industry

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#72

I know this is a crazy take. But I go feel so down trodden by many many tech corps these days I find it hard not to have a smidge of satisfaction for this guy pointing out the colossal favour research developers do for them by responsible disclosure. That said, I feel bad for the inevitable victims of exploitation and also I am certain he will end up criminalized or as per usual the law will enforce a large corps wil…

Microsoft chose to run a shoddy bounty program. The researcher tried to do the right thing. Microsoft could have prevented this. They were warned. It's their own fault. The exploit exists whether or not the researcher reports it. They didn't make the exploit.

> They didn't make the exploit

This is important to remember, in this situation and all other 0-day disclosures. There's also no guarantee that the uses of said 0 day after disclosure are the only time its been actively exploited. The exploit was already existing, and there are plenty of three letter agencies and Israeli companies that could very well have already been aware of them.

The only place blame belongs here is on Microsoft, no where else.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#73

I know this is a crazy take. But I go feel so down trodden by many many tech corps these days I find it hard not to have a smidge of satisfaction for this guy pointing out the colossal favour research developers do for them by responsible disclosure. That said, I feel bad for the inevitable victims of exploitation and also I am certain he will end up criminalized or as per usual the law will enforce a large corps wil…

> I am certain he will end up criminalized DMCA has exemptions for "good faith" security research, whatever that means when interpreted by a judge. Outside of copyright law, not sure what Microsoft could pursue legally. The researcher is just disclosing information. CFAA doesn't apply because it's an operating system, running on their own machine there's no unauthorized access there. They could drag Eclipse through c…

Sadly CFAA always applies, just read the letter if the law and multiply by the wide net cast by the microsoft TOS.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#74
post #59

Attacking the messenger is an age-old trend in the bug reporting arena. Microsoft has the backing of many governments, and has access to the best legal teams possible, leaving this guy in a world of hurt. Microsoft seems to have brought this on themselves by creating a complex and user-hostile bug reporting system. It seems to me that they could have offered this person a job or a contract, because Eclipse has been a…

I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.

You don't even need to find a whole 0day, you can find step 3 of 14.

Just dump it anon or sell it, don't even try to claim a bounty or get a cve. Without elaborating, they will make sure you regret it

Same goes for games. If you find RCE, report it and move on. If it remains unfixed let a journalist know. Do NOT accept their invite to the studio, they want to have you arrested. Would have happened to me were it not for one dude with a conscience at the company warning me not to go

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#75
post #67

Earlier quoted context omitted.

Now iOS 0-day is worth up to $2,000,000 on gray market so Apple kind a take it seriously.

If you find a real iOS zero day that you think has a market value of 2 million, how do you (a) find a legit buyer for it, and (b) ensure you get paid, presumably in your own choice of cryptocurrency?

Are you asking for step by step instructions?

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#76
post #16

> “CVD is a two-way street,” he said. “The vendor has some responsibility as well, so to go out publicly stating this person violated CVD without showing any of the correspondence seems bold.” > “It confusingly claims their program ‘ensures researchers are compensated and publicly acknowledged’ in a statement answering a researcher who says he got neither,” Well said.

I would argue that this form of disclosure is ethical in the face of Microsoft misbehaving. It's like mutually assured destruction - and in this case (it sounds like) Microsoft tried to cheat and thought they would get away with it. Feeling consequences are how they are kept in line. Maybe next time they will think twice before (allegedly) treating a person like they did here, as well as the creative reasoning I reca…

> the creative reasoning I recall them using in the past to reduce payouts.

It's a wonder anyone even reports things to Microsoft anymore because of this. They have a long habit of declaring things as intentional, then silently patching it after.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#77
post #67

Earlier quoted context omitted.

Now iOS 0-day is worth up to $2,000,000 on gray market so Apple kind a take it seriously.

If you find a real iOS zero day that you think has a market value of 2 million, how do you (a) find a legit buyer for it, and (b) ensure you get paid, presumably in your own choice of cryptocurrency?

Even if you dont count obvious dark markets there is plenty of well known companies mostly from Israel buying exploits.

You can even reach them via Linkedin and even demonstrate and sell in person with all paperwork. No risk here because they will re-sell them for much more.

Having it both fully anonymous, safe and in crypto will be harder. You need to have a trusted friend with right connections in industry not to get scammed.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#78
post #75

Earlier quoted context omitted.

If you find a real iOS zero day that you think has a market value of 2 million, how do you (a) find a legit buyer for it, and (b) ensure you get paid, presumably in your own choice of cryptocurrency?

Are you asking for step by step instructions?

no, I'm making the rhetorical point that the sort of persons that might have 2 million laying around to pay for an iOS zero day for blackhat type purposes might not be the most honorable or likely to actually pay you. And what recourse would you have?

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#79
post #75

Earlier quoted context omitted.

Are you asking for step by step instructions?

no, I'm making the rhetorical point that the sort of persons that might have 2 million laying around to pay for an iOS zero day for blackhat type purposes might not be the most honorable or likely to actually pay you. And what recourse would you have?

This depends on what you consider black hat. Israeli company that sells surveillance malware to dictatorships around the globe isnt exactly moral, but its legal business.

Unlike Apple or Microsoft buying and selling exploits is their only source of income so they have no motivation not to pay. Reputation is much more important. Also legal system does work in Israel.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#80

I guess I'll play devil's advocate here, don't shoot me. Over the course of my career I've had to deal with multiple hacks, DDOSes, and even situations working with the FBI. It's a mess, and extremely frustrating and unfair to those of us who are just trying to do a good job and make a living. Those of you who are throwing stones at Microsoft's coding, how confident are you that your code is safe from this new AI age…

I don't think it's their fault for not making code without exploits. I do think they should try and close them in a timely fashion when the exploit is pointed out though - the longer they wait the more chance bad actors find it in addition to the security researchers. Ultimately they need to cooperate here for users to be safe.

> I do think they should try and close them in a timely fashion when the exploit is pointed out though - the longer they wait the more chance bad actors find it in addition to the security researchers.

You are assuming it is not already being actively exploited and there will be a timely response to fix it, which is why we have these ticking clocks.

Post reply on HN