Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
66 Indlæg 46 Posters 67 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    Do I think the finder was acting rationally? No. Do I think Microsoft gets to decide what is criminal activity around proof of concept exploits? No.

    wowsuchcyber@cyberplace.socialW This user is from outside of this forum
    wowsuchcyber@cyberplace.socialW This user is from outside of this forum
    wowsuchcyber@cyberplace.social
    wrote sidst redigeret af
    #12

    @GossiTheDog the criminal activity was issuing the bugs in the first place.

    1 Reply Last reply
    0
    • mhkohne@mastodon.socialM This user is from outside of this forum
      mhkohne@mastodon.socialM This user is from outside of this forum
      mhkohne@mastodon.social
      wrote sidst redigeret af
      #13

      @sharkfie @GossiTheDog One presumes management? I don't follow MS execs, but one assumes that there's more third-party thinkers in charge than there used to be.

      1 Reply Last reply
      0
      • mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
        mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
        mrmasterkeyboard@mastodon.social
        wrote sidst redigeret af
        #14

        @kkarhan @GossiTheDog i have a backup of all of it

        all recent as of May 16th

        i thought they'd be useful and i KNEW that something like this would happen so i came prepared

        mrmasterkeyboard@mastodon.socialM 1 Reply Last reply
        0
        • lykso@tiny.tilde.websiteL lykso@tiny.tilde.website

          @GossiTheDog Shit, Microsoft was basically *built* on the other side of the Rubicon, to torture the analogy. Never have they ever been accused of being ethical.

          rndanger@infosec.exchangeR This user is from outside of this forum
          rndanger@infosec.exchangeR This user is from outside of this forum
          rndanger@infosec.exchange
          wrote sidst redigeret af
          #15

          @lykso @GossiTheDog
          Microsoft attained market dominance in the eighties by scaring people with fake error messages, so yeah. People should remember better

          resister@infosec.exchangeR 1 Reply Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

            It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

            https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

            piepants@famichiki.jpP This user is from outside of this forum
            piepants@famichiki.jpP This user is from outside of this forum
            piepants@famichiki.jp
            wrote sidst redigeret af
            #16

            @GossiTheDog

            1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

              It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

              https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

              fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
              fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
              fuzzyfuzzyfungus@cyberplace.social
              wrote sidst redigeret af
              #17

              @GossiTheDog "We invite diverse perspectives that help the security community work together to protect everyone. We realize that we will not always agree on everything, but we are committed to transparency and continue to create opportunities for dialogue. "

              Also we'll blatantly conflate researchers of our bugs and attackers and threaten to send the cops after both; unless you are a respectable nerd-merc like NSO, of course.

              Fuck whoever wrote this.

              1 Reply Last reply
              0
              • mrmasterkeyboard@mastodon.socialM mrmasterkeyboard@mastodon.social

                @kkarhan @GossiTheDog i have a backup of all of it

                all recent as of May 16th

                i thought they'd be useful and i KNEW that something like this would happen so i came prepared

                mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                mrmasterkeyboard@mastodon.social
                wrote sidst redigeret af
                #18

                @kkarhan @GossiTheDog also, this story goes way deeper...

                turns out Nightmare Eclipse has their own blog too which has been talking about all of this.

                deadeclipse666 dot blogspot dot com

                interesting url for a blog but i wont question it

                mrmasterkeyboard@mastodon.socialM 1 Reply Last reply
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                  It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                  https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                  themadhatter@mastodon.socialT This user is from outside of this forum
                  themadhatter@mastodon.socialT This user is from outside of this forum
                  themadhatter@mastodon.social
                  wrote sidst redigeret af
                  #19

                  @GossiTheDog this one needs to be said in German:

                  #BigTechMussWeg

                  1 Reply Last reply
                  0
                  • mrmasterkeyboard@mastodon.socialM mrmasterkeyboard@mastodon.social

                    @kkarhan @GossiTheDog also, this story goes way deeper...

                    turns out Nightmare Eclipse has their own blog too which has been talking about all of this.

                    deadeclipse666 dot blogspot dot com

                    interesting url for a blog but i wont question it

                    mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                    mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                    mrmasterkeyboard@mastodon.social
                    wrote sidst redigeret af
                    #20

                    @kkarhan @GossiTheDog @anomr Edit: It was instantly taken down. I had only been away for 5 minutes. What rule does this even violate?

                    Malware archives are allowed on archive.org but this isn't?

                    anomr@mastodon.socialA 1 Reply Last reply
                    0
                    • mrmasterkeyboard@mastodon.socialM mrmasterkeyboard@mastodon.social

                      @kkarhan @GossiTheDog @anomr Edit: It was instantly taken down. I had only been away for 5 minutes. What rule does this even violate?

                      Malware archives are allowed on archive.org but this isn't?

                      anomr@mastodon.socialA This user is from outside of this forum
                      anomr@mastodon.socialA This user is from outside of this forum
                      anomr@mastodon.social
                      wrote sidst redigeret af
                      #21

                      @mrmasterkeyboard @kkarhan @GossiTheDog you also included the .git, amazing!

                      mrmasterkeyboard@mastodon.socialM 1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                        It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                        https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                        sycophantic@infosec.exchangeS This user is from outside of this forum
                        sycophantic@infosec.exchangeS This user is from outside of this forum
                        sycophantic@infosec.exchange
                        wrote sidst redigeret af
                        #22

                        @GossiTheDog if I find a 0day I'm dropping it the same way. I'm done with responsible disclosure.

                        drwho@masto.hackers.townD 1 Reply Last reply
                        0
                        • anomr@mastodon.socialA anomr@mastodon.social

                          @mrmasterkeyboard @kkarhan @GossiTheDog you also included the .git, amazing!

                          mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                          mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                          mrmasterkeyboard@mastodon.social
                          wrote sidst redigeret af
                          #23

                          @anomr @kkarhan @GossiTheDog yup, i believe that the history is important too!

                          mrmasterkeyboard@mastodon.socialM 1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                            It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                            https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                            goingforbrooke@hachyderm.ioG This user is from outside of this forum
                            goingforbrooke@hachyderm.ioG This user is from outside of this forum
                            goingforbrooke@hachyderm.io
                            wrote sidst redigeret af
                            #24

                            @GossiTheDog 9 out of 10 doctore agree that sell-to-APT incentives are going up

                            drwho@masto.hackers.townD 1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              GitHub has long been a source for zero days exploits in competitor products - it still is. While I worked there GitHub had a policy saying they wouldn’t remove them.

                              By continually removing just exploits for their own products from Github and declaring “criminal activity”, it’s a rubicon.

                              zaicurity@infosec.exchangeZ This user is from outside of this forum
                              zaicurity@infosec.exchangeZ This user is from outside of this forum
                              zaicurity@infosec.exchange
                              wrote sidst redigeret af
                              #25

                              @GossiTheDog I was actually surprised that the repos weren’t taken down sooner given Microsoft’s track record with similar cases affecting their products.

                              1 Reply Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                Do I think the finder was acting rationally? No. Do I think Microsoft gets to decide what is criminal activity around proof of concept exploits? No.

                                rairii@labyrinth.zoneR This user is from outside of this forum
                                rairii@labyrinth.zoneR This user is from outside of this forum
                                rairii@labyrinth.zone
                                wrote sidst redigeret af
                                #26
                                @GossiTheDog i mean, i can totally understand why it was done

                                if the coordinated disclosure process breaks down, full disclosure seems to be the obvious result. this isn't the first time this has happened and won't be the last.

                                MS seems to be acting more irrationally than the researcher here, banning them from MSRC seems to guarantee any future discoveries from them will be fully disclosed, and there are enough git forges that MS don't lean on.

                                and if MS's leaning on law enforcement does end up with something happening on that front, it seems that would increase the streisand effect exponentially?
                                1 Reply Last reply
                                0
                                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                  I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                                  It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                                  https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                                  ralph@hear-me.socialR This user is from outside of this forum
                                  ralph@hear-me.socialR This user is from outside of this forum
                                  ralph@hear-me.social
                                  wrote sidst redigeret af
                                  #27

                                  @GossiTheDog

                                  #alttext

                                  The vulnerabilities known as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma were not responsibly disclosed. In response to the unnecessary risk created by these disclosures, our security teams have been working around the clock to understand the impact, protect our customers, and develop security updates.
                                  We remain firmly opposed to these actions, and any disclosure outside proper coordination that could harm our customers and the digital ecosystem. Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences. Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these to attack Microsoft and our customers. Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity -coordinating as needed with law enforcement around the world.

                                  rndanger@infosec.exchangeR theothersimo@mastodon.socialT 2 Replies Last reply
                                  0
                                  • rndanger@infosec.exchangeR rndanger@infosec.exchange

                                    @lykso @GossiTheDog
                                    Microsoft attained market dominance in the eighties by scaring people with fake error messages, so yeah. People should remember better

                                    resister@infosec.exchangeR This user is from outside of this forum
                                    resister@infosec.exchangeR This user is from outside of this forum
                                    resister@infosec.exchange
                                    wrote sidst redigeret af
                                    #28

                                    @RnDanger @lykso @GossiTheDog remember "different"

                                    1 Reply Last reply
                                    0
                                    • notavi10@critter.cafeN notavi10@critter.cafe

                                      @GossiTheDog nah the finder was acting rationally cause ms didn't fucking pay them for the zero days like they was supposed to

                                      resister@infosec.exchangeR This user is from outside of this forum
                                      resister@infosec.exchangeR This user is from outside of this forum
                                      resister@infosec.exchange
                                      wrote sidst redigeret af
                                      #29

                                      @notavi10 @GossiTheDog
                                      Is this for real? They submitted for bug bounty and got rejected?

                                      notavi10@critter.cafeN 1 Reply Last reply
                                      0
                                      • mrmasterkeyboard@mastodon.socialM mrmasterkeyboard@mastodon.social

                                        @anomr @kkarhan @GossiTheDog yup, i believe that the history is important too!

                                        mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                                        mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                                        mrmasterkeyboard@mastodon.social
                                        wrote sidst redigeret af
                                        #30

                                        @anomr @kkarhan @GossiTheDog well I dunno where to rereupload it now.

                                        mrmasterkeyboard@mastodon.socialM 1 Reply Last reply
                                        0
                                        • mrmasterkeyboard@mastodon.socialM mrmasterkeyboard@mastodon.social

                                          @anomr @kkarhan @GossiTheDog well I dunno where to rereupload it now.

                                          mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                                          mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                                          mrmasterkeyboard@mastodon.social
                                          wrote sidst redigeret af
                                          #31

                                          @anomr @kkarhan @GossiTheDog fuck it, I give up.

                                          I'm not uploading my copy again elsewhere, turns out it's here anyway.

                                          https://archive.softwareheritage.org/browse/search/?q=nightmare-eclipse&with_visit=true&with_content=true

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper