Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

91–100 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#91
post #84

Earlier quoted context omitted.

Why would taking this action have any implication for responsibility to take future actions against other accounts?

Legally? I don’t know. More loosely, the fact that they deem this to be an appropriate action when it comes to their own interests would seem to condemn them if they refuse to take it when it comes to others’ interests, particularly those with whom it has a relationship of trust in any capacity.

Outside of legally, I’m not aware of any framework where “creates an editorial responsibly” makes sense.

Even beyond that… most business relationships wouldn’t involve an expectation that Microsoft does things for other entities that it does for itself.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#92
post #36

No idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small compa…

It all started because the bureaucracy refused to even consider Bluehammer when they couldn't cajole the reporter into providing video footage. And then to double down and ban accounts because you'd rather not fix the bureaucracy is really just a bad look. I'm not quite sure why MS is getting the benefit of the doubt from you.

They also silently patched RedSun, didn't issue a CVE until much later.

There's something fishy going on with these vulnerabilities. I'm not one for conspiracies but it's not a good look for Microsoft, they are obviously trying to cover something up.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#93
post #74

Earlier quoted context omitted.

ahh, the "what was she wearing" comment.

ahh, the false analogy comment.

“False analogy” isn’t a counterpoint, it's a deflection. What part of the mapping breaks for you?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#94
post #15

Earlier quoted context omitted.

It doesnt really matter. Banning someone GitHub account change literally nothing and its another proof Microsoft is not to be trusted as steward of open source platform.

Worse, cant be trusted to have secure products.

They lost the trust of having secure products a long time ago. Windows is directly responsible for the rash of varying quality EDR & other "security software" for endpoints.

I mean it took them until Windows 10 to move font rendering out of Ring 0, you could run malicious code in kernel space from a freaking font on a web page at one point.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#95
post #91

Earlier quoted context omitted.

Legally? I don’t know. More loosely, the fact that they deem this to be an appropriate action when it comes to their own interests would seem to condemn them if they refuse to take it when it comes to others’ interests, particularly those with whom it has a relationship of trust in any capacity.

Outside of legally, I’m not aware of any framework where “creates an editorial responsibly” makes sense. Even beyond that… most business relationships wouldn’t involve an expectation that Microsoft does things for other entities that it does for itself.

I’m thinking of § 230 of the CDA [1], where the line between publisher/speaker and not can come down to editorial discretion.

[1] https://en.wikipedia.org/wiki/Section_230

Re: GitHub bans security researcher who posted zero-day Windows exploits

#96
post #83
post #37

Earlier quoted context omitted.

I was forced to use ms basic on my c64. Never forgive, never forget.

I always found it weird to ship a BASIC interpreter that didn't have specialised commands (unless you count POKE) to access the graphics and sound capabilities of a computer like the C64. Some computers of the same era had vastly superior BASICs (such as Sinclair BASIC).

I agree, it seems very low-effort on Commodore's part to license this lowest-common-denominator BASIC with no support for graphics and sound other than POKE. Super lame, but they got away with it.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#97

Earlier quoted context omitted.

But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.

Ever considered these aren't the full set of exploits the researcher discovered? Or that he can find more since he found these? If I found a bunch, I'd certainly withhold a few as insurance.

Sure, but GitHub and Gitlab aren’t the only two ways to share code on the Internet. The conspiracy theories about two unrelated companies shutting down his git accounts to prevent him from releasing these supposed exploits are reaching pretty deep into conspiracy theory nonsense. The conspiracy theories can’t even agree if he was banned for posting them or because he hadn’t posted them but might post them.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#98
post #69
post #30

Earlier quoted context omitted.

I know quite a few extremely skilled people who aren't employed in a technical field. Usually it's some combination of not working well with others, lack of formal credentials and the means to acquire them, or a criminal record. Government work also means you have to be morally okay with what the government does (or willfully ignorant), able to pass a background check, and be willing to go through the security cleara…

"People with skills" just don't care for corporate or government bullshit. You may know them as "not being employed in a technical field", but it's just because you got filtered out.

[deleted]

Re: GitHub bans security researcher who posted zero-day Windows exploits

#99
post #93

Earlier quoted context omitted.

ahh, the false analogy comment.

“False analogy” isn’t a counterpoint, it's a deflection. What part of the mapping breaks for you?

False analogy isn’t a deflection, it’s a logical fallacy.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#100
post #91

Earlier quoted context omitted.

Outside of legally, I’m not aware of any framework where “creates an editorial responsibly” makes sense. Even beyond that… most business relationships wouldn’t involve an expectation that Microsoft does things for other entities that it does for itself.

I’m thinking of § 230 of the CDA [1], where the line between publisher/speaker and not can come down to editorial discretion. [1] https://en.wikipedia.org/wiki/Section_230

It can’t, and it doesn’t.

Section 230 has no concern with publishers making editorial decisions. GitHub can moderate user content on its site however it wants.

Post reply on HN