Live data from Hacker News

Microsoft 0-day feud escalates as researcher threatens another exploit dump

theregister.com

91–100 of 103 posts

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#91
post #9

Earlier quoted context omitted.

> so far as i can tell yellowkey is problematic, as the exploit takes advantage of a backdoor that ms needs, to "manage" your computer. It does look like an intentional backdoor. The way ms is responding to it is even more suspicious. Pretty funny since this defeats security on most corporate laptops, so impact is huge. You'd expect them to treat the reporter better and fix the issue fast... I'm curious why they put…

The backdoor could be a bug, but I don't really understand how it happened. The attack works by having an NTFS log get replayed against another partition than the one the log is stored on. Sending the right signals to unlock Bitlocker in TPM-only mode is a necessity for recovery operations. Managing to replace the executable launched post verification is a plausible attack vector. The weird thing is why it's possible…

> The attack works by having an NTFS log get replayed against another partition than the one the log is stored on.

Obfuscated enough to pass internal reviews, sloppy enough to make it look like a bug.

Other reply makes it even more suspicious... change is new in a subsystem that hasnt been updated in a long tine and it's only present in recovery mode files.

Microsoft handle of this also screams it's not a regular bug and they're likely investigating or someone is trying to cover their ass.

What's even more troubling is that the fix would be a very simple/quick rollback of the change that introduced this... and that they haven't done that is interesting.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#93

I know this is a crazy take. But I go feel so down trodden by many many tech corps these days I find it hard not to have a smidge of satisfaction for this guy pointing out the colossal favour research developers do for them by responsible disclosure. That said, I feel bad for the inevitable victims of exploitation and also I am certain he will end up criminalized or as per usual the law will enforce a large corps wil…

> I am certain he will end up criminalized DMCA has exemptions for "good faith" security research, whatever that means when interpreted by a judge. Outside of copyright law, not sure what Microsoft could pursue legally. The researcher is just disclosing information. CFAA doesn't apply because it's an operating system, running on their own machine there's no unauthorized access there. They could drag Eclipse through c…

Unfortunately I think “good faith” goes away quick in the face of “bone shattering”

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#95
post #27

Earlier quoted context omitted.

yes sniffing is possible, for now im waiting for some pluton variant to start making its way into the chip and die stream. the concept is to shield the TPM its bus, and any keys whith the CPU chip.

Current TPMs already have the ability to encrypted the comms to the CPU. Motherboard manufacturers just don't bother implementing it.

Pluton is about physically placing the TPM behind the CPU die, its more than a SoC it eliminates the possibility of getting to the TPM at all, you wont be able to drill into the chip to access bus lines without mangleing the whole thing.

no sniffing would be possible after Pluton chips, even if you could decrypt.

but as i said, for now you can still sniff.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#96
It's kind of fascinating how large corporations can end up acting like petulant children against their own interests and stated goals. We don't know who said or did what in this situation, but as TFA says, even if the researcher was a maximally bad actor, MSFT's public response hurts their interests. Sometimes individuals behave like petulant children but for a well-run corporation it's a failure mode.

In my experience, corps sometimes behave this way not because it's the 'corporate intent' but simply due to internal politics and ass-covering by individual middle managers. MSFT's response is puzzling because it doesn't clear up anything nor does it try to de-escalate. It's also not the sort of completely neutral statement made when you need to respond but have nothing to say yet. This statement implies the researcher is a bad actor while also being vaguely threatening. I can't imagine any way this benefits MSFT.

It appears more like a junior exec trying to manage the optics so it looks like their department isn't in the wrong. This ass-covering accomplishes nothing for MSFT. Even if the researcher was demanding payment for a vuln and wasn't producing sufficient justification for their demand or wasn't following the process, this isn't a productive response. It sounds more like a manager is worried what their boss thinks. The manager acting this way is bad but the root cause is often the manager's upline creating a context where managers feel they need to ass-cover and stage manage optics.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#97

Attacking the messenger is an age-old trend in the bug reporting arena. Microsoft has the backing of many governments, and has access to the best legal teams possible, leaving this guy in a world of hurt. Microsoft seems to have brought this on themselves by creating a complex and user-hostile bug reporting system. It seems to me that they could have offered this person a job or a contract, because Eclipse has been a…

Assuming he wasn't trying to extort them -- which seems absurd, this is a real self-own by Microsoft. We'll see what July 14th brings.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#98
post #59

Earlier quoted context omitted.

I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.

You don't even need to find a whole 0day, you can find step 3 of 14. Just dump it anon or sell it, don't even try to claim a bounty or get a cve. Without elaborating, they will make sure you regret it Same goes for games. If you find RCE, report it and move on. If it remains unfixed let a journalist know. Do NOT accept their invite to the studio, they want to have you arrested. Would have happened to me were it not f…

Do you have any evidence this is actually happening to good faith security researchers?

There are many examples of Microsoft and other large corporations treating security researchers well. Microsoft hosts BlueHat, where they invite external parties to talk about their findings. They thank researchers monthly who do contribute reports to MSRC. As I recall, they treated bunnie well, and I think they also treated “hoodie” (the original Xbox 360 hacker) well as well.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#99
post #95

Earlier quoted context omitted.

Current TPMs already have the ability to encrypted the comms to the CPU. Motherboard manufacturers just don't bother implementing it.

Pluton is about physically placing the TPM behind the CPU die, its more than a SoC it eliminates the possibility of getting to the TPM at all, you wont be able to drill into the chip to access bus lines without mangleing the whole thing. no sniffing would be possible after Pluton chips, even if you could decrypt. but as i said, for now you can still sniff.

Oh yes but you shouldn't have to be able to do that. If the TPM2 spec were properly implemented.

Physical hardening and protocol hardening are complementary features, not alternatives. It's better to have both in case one of them has a flaw.

Ps I'm not very sold on having this stuff in the CPU, there's so much industry focus on giving up control to big tech. I don't want to get to the situation we already have on mobile where having root on my own system is considered a bad thing. I trust myself one hell of a lot more than Google or Microsoft.

Re: Microsoft 0-day feud escalates as researcher threatens another exploit dump

#100
post #79

Earlier quoted context omitted.

no, I'm making the rhetorical point that the sort of persons that might have 2 million laying around to pay for an iOS zero day for blackhat type purposes might not be the most honorable or likely to actually pay you. And what recourse would you have?

This depends on what you consider black hat. Israeli company that sells surveillance malware to dictatorships around the globe isnt exactly moral, but its legal business. Unlike Apple or Microsoft buying and selling exploits is their only source of income so they have no motivation not to pay. Reputation is much more important. Also legal system does work in Israel.

dictatorships are not there main customers. There are many, also western, governments and their agencies customers of such services.
Post reply on HN