Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
66 Indlæg 46 Posters 67 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • notavi10@critter.cafeN notavi10@critter.cafe

    @GossiTheDog nah the finder was acting rationally cause ms didn't fucking pay them for the zero days like they was supposed to

    briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchange
    wrote sidst redigeret af
    #33

    @notavi10 @GossiTheDog is there anything to support this claim? thanks.

    notavi10@critter.cafeN 1 Reply Last reply
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      @GossiTheDog yeah that reads as pretty hostile to researchers in general and labels as "threat actors" those who don't choose to play by Microsoft's rules.

      johncc@corteximplant.comJ This user is from outside of this forum
      johncc@corteximplant.comJ This user is from outside of this forum
      johncc@corteximplant.com
      wrote sidst redigeret af
      #34

      @briankrebs @GossiTheDog I often hear UK politicians use "working around the clock", "working tirelessly", or "striving relentlessly" when defending themselves. It has become meaningless (which is the point) but to me it serves as a bullshit flag. I'm impressed they managed to get two in one press release!

      1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

        It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

        https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

        cxj@phpc.socialC This user is from outside of this forum
        cxj@phpc.socialC This user is from outside of this forum
        cxj@phpc.social
        wrote sidst redigeret af
        #35

        @GossiTheDog Well that’s rather horrifying.

        1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

          It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

          https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

          snickerbockers@freeradical.zoneS This user is from outside of this forum
          snickerbockers@freeradical.zoneS This user is from outside of this forum
          snickerbockers@freeradical.zone
          wrote sidst redigeret af
          #36

          @GossiTheDog bold threats coming from a company founded by a frequent visitor to epstein island.

          1 Reply Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

            It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

            https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

            interpipes@thx.ggI This user is from outside of this forum
            interpipes@thx.ggI This user is from outside of this forum
            interpipes@thx.gg
            wrote sidst redigeret af
            #37

            @GossiTheDog Microsoft continuing to work hard to prove to everyone else that they are the bad faith actor in infosec I have been criticising them for

            1 Reply Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              @GossiTheDog yeah that reads as pretty hostile to researchers in general and labels as "threat actors" those who don't choose to play by Microsoft's rules.

              sly_vi@lgbtqia.spaceS This user is from outside of this forum
              sly_vi@lgbtqia.spaceS This user is from outside of this forum
              sly_vi@lgbtqia.space
              wrote sidst redigeret af
              #38

              @briankrebs @GossiTheDog not to defend M$, but isn't the responsible disclosure stuff an etiquette in the whole infosec domain? My friends working in a SOC told me so, and I can understand the point of "please think about the workers"
              Still, M$ wanting people to think about the workers leaves a bitter taste int mouth, and nothing justifies sending legal threats against individuals like that

              bertdriehuis@infosec.exchangeB 1 Reply Last reply
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                Do I think the finder was acting rationally? No. Do I think Microsoft gets to decide what is criminal activity around proof of concept exploits? No.

                cdubbs@infosec.exchangeC This user is from outside of this forum
                cdubbs@infosec.exchangeC This user is from outside of this forum
                cdubbs@infosec.exchange
                wrote sidst redigeret af
                #39

                @GossiTheDog That response playbook looks like a villain arc generator.

                1 Reply Last reply
                0
                • ralph@hear-me.socialR ralph@hear-me.social

                  @GossiTheDog

                  #alttext

                  The vulnerabilities known as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma were not responsibly disclosed. In response to the unnecessary risk created by these disclosures, our security teams have been working around the clock to understand the impact, protect our customers, and develop security updates.
                  We remain firmly opposed to these actions, and any disclosure outside proper coordination that could harm our customers and the digital ecosystem. Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences. Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these to attack Microsoft and our customers. Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity -coordinating as needed with law enforcement around the world.

                  rndanger@infosec.exchangeR This user is from outside of this forum
                  rndanger@infosec.exchangeR This user is from outside of this forum
                  rndanger@infosec.exchange
                  wrote sidst redigeret af
                  #40

                  @Ralph @GossiTheDog
                  Thank you, i really didn't want to look at the picture of text

                  ralph@hear-me.socialR 1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                    It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                    https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                    kitsunevixi@sakurajima.socialK This user is from outside of this forum
                    kitsunevixi@sakurajima.socialK This user is from outside of this forum
                    kitsunevixi@sakurajima.social
                    wrote sidst redigeret af
                    #41

                    @GossiTheDog@cyberplace.social So they complain about irresponsible disclosure but kick them off the MSRC so they can't disclose responsibly?

                    1 Reply Last reply
                    0
                    • will@www.librepunk.clubW This user is from outside of this forum
                      will@www.librepunk.clubW This user is from outside of this forum
                      will@www.librepunk.club
                      wrote sidst redigeret af
                      #42

                      @GossiTheDog I really hope that somebody at Microsoft acknowledges that this screenshot looks like it could be lifted straight from Cyberpunk 2077.

                      ciclistarubio@norden.socialC 1 Reply Last reply
                      0
                      • will@www.librepunk.clubW will@www.librepunk.club

                        @GossiTheDog I really hope that somebody at Microsoft acknowledges that this screenshot looks like it could be lifted straight from Cyberpunk 2077.

                        ciclistarubio@norden.socialC This user is from outside of this forum
                        ciclistarubio@norden.socialC This user is from outside of this forum
                        ciclistarubio@norden.social
                        wrote sidst redigeret af
                        #43

                        @will @GossiTheDog A statement straight out of the Arasaka Tower.

                        1 Reply Last reply
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          GitHub has long been a source for zero days exploits in competitor products - it still is. While I worked there GitHub had a policy saying they wouldn’t remove them.

                          By continually removing just exploits for their own products from Github and declaring “criminal activity”, it’s a rubicon.

                          skysailor@social.scribblers.clubS This user is from outside of this forum
                          skysailor@social.scribblers.clubS This user is from outside of this forum
                          skysailor@social.scribblers.club
                          wrote sidst redigeret af
                          #44

                          @GossiTheDog To add, according to Low Level's video on the subject, Microsoft marked previous zero days the person reported as ineligible for its bug bounty program (saying administrator to kernel/system access is not a security boundary).

                          1 Reply Last reply
                          0
                          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                            @notavi10 @GossiTheDog is there anything to support this claim? thanks.

                            notavi10@critter.cafeN This user is from outside of this forum
                            notavi10@critter.cafeN This user is from outside of this forum
                            notavi10@critter.cafe
                            wrote sidst redigeret af
                            #45

                            @briankrebs @GossiTheDog from the person who didn't release the zero days: https://deadeclipse666.blogspot.com/2026/05/july-14th.html

                            1 Reply Last reply
                            0
                            • resister@infosec.exchangeR resister@infosec.exchange

                              @notavi10 @GossiTheDog
                              Is this for real? They submitted for bug bounty and got rejected?

                              notavi10@critter.cafeN This user is from outside of this forum
                              notavi10@critter.cafeN This user is from outside of this forum
                              notavi10@critter.cafe
                              wrote sidst redigeret af
                              #46

                              @resister @GossiTheDog https://deadeclipse666.blogspot.com/2026/05/july-14th.html

                              resister@infosec.exchangeR 1 Reply Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                                It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                                https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                                eestileib@tech.lgbtE This user is from outside of this forum
                                eestileib@tech.lgbtE This user is from outside of this forum
                                eestileib@tech.lgbt
                                wrote sidst redigeret af
                                #47

                                @GossiTheDog

                                The merger of law enforcement and big tech gains pace.

                                1 Reply Last reply
                                0
                                • smilingdemon@mastodon.artS smilingdemon@mastodon.art

                                  @GossiTheDog which stage of dystopian hellscape is it when mega-corporations have turned law enforcement into their own private police force?

                                  theorangetheme@en.osm.townT This user is from outside of this forum
                                  theorangetheme@en.osm.townT This user is from outside of this forum
                                  theorangetheme@en.osm.town
                                  wrote sidst redigeret af
                                  #48

                                  @smilingdemon @GossiTheDog The Pinkertons have been around for a century.

                                  drwho@masto.hackers.townD C 2 Replies Last reply
                                  0
                                  • rndanger@infosec.exchangeR rndanger@infosec.exchange

                                    @Ralph @GossiTheDog
                                    Thank you, i really didn't want to look at the picture of text

                                    ralph@hear-me.socialR This user is from outside of this forum
                                    ralph@hear-me.socialR This user is from outside of this forum
                                    ralph@hear-me.social
                                    wrote sidst redigeret af
                                    #49

                                    @RnDanger @GossiTheDog

                                    You're welcome! I'm not sure why creating and then posting an image of the text is considered easier?, more authentic?, or whatever; than just cutting and pasting the same text. I suppose it eliminates the need for quotation marks.

                                    1 Reply Last reply
                                    0
                                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                      Do I think the finder was acting rationally? No. Do I think Microsoft gets to decide what is criminal activity around proof of concept exploits? No.

                                      theogrin@chaosfem.twT This user is from outside of this forum
                                      theogrin@chaosfem.twT This user is from outside of this forum
                                      theogrin@chaosfem.tw
                                      wrote sidst redigeret af
                                      #50

                                      @GossiTheDog

                                      From the standpoint of the actor and their own future career in bounty hunting, I'm certain that this is irrational -- I have few doubts they'll be blackballed across the board, though it sounds like this may have already occurred.

                                      From a community perspective, a great many malicious actions have recently been taken by the Big Three, raising an unignorable amount of rancor in the bug-hunting community. These actions are irrational in and of themselves, eroding and eliminating trust in the corporations while crippling one of the biggest incentives bounty hunters have to continue their work.

                                      Standing up and making it clear that these bounty programs operate on an understanding of trust -- and that said trust, if broken, will lead to Bad Things like This happening -- is, from a community standpoint, rational, logical and sane. It's possibly the only way to counter a unilateral corporate decision to break the social contract holding things together.

                                      1 Reply Last reply
                                      0
                                      • ralph@hear-me.socialR ralph@hear-me.social

                                        @GossiTheDog

                                        #alttext

                                        The vulnerabilities known as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma were not responsibly disclosed. In response to the unnecessary risk created by these disclosures, our security teams have been working around the clock to understand the impact, protect our customers, and develop security updates.
                                        We remain firmly opposed to these actions, and any disclosure outside proper coordination that could harm our customers and the digital ecosystem. Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences. Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these to attack Microsoft and our customers. Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity -coordinating as needed with law enforcement around the world.

                                        theothersimo@mastodon.socialT This user is from outside of this forum
                                        theothersimo@mastodon.socialT This user is from outside of this forum
                                        theothersimo@mastodon.social
                                        wrote sidst redigeret af
                                        #51

                                        @Ralph @GossiTheDog Big “whistleblowers must go through the chain of command” energy

                                        1 Reply Last reply
                                        0
                                        • notavi10@critter.cafeN notavi10@critter.cafe

                                          @resister @GossiTheDog https://deadeclipse666.blogspot.com/2026/05/july-14th.html

                                          resister@infosec.exchangeR This user is from outside of this forum
                                          resister@infosec.exchangeR This user is from outside of this forum
                                          resister@infosec.exchange
                                          wrote sidst redigeret af
                                          #52

                                          @notavi10 @GossiTheDog
                                          Thank you @notavi10

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper