Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
66 Indlæg 46 Posters 67 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • sly_vi@lgbtqia.spaceS sly_vi@lgbtqia.space

    @briankrebs @GossiTheDog not to defend M$, but isn't the responsible disclosure stuff an etiquette in the whole infosec domain? My friends working in a SOC told me so, and I can understand the point of "please think about the workers"
    Still, M$ wanting people to think about the workers leaves a bitter taste int mouth, and nothing justifies sending legal threats against individuals like that

    bertdriehuis@infosec.exchangeB This user is from outside of this forum
    bertdriehuis@infosec.exchangeB This user is from outside of this forum
    bertdriehuis@infosec.exchange
    wrote sidst redigeret af
    #57

    @sly_vi @briankrebs @GossiTheDog I'm not privy to the situation that made this guy do what he did, but MS have quite a history of responding to notifications with "works a designed" or other ways of shifting the blame to the user. In some cases, they fixed issues silently after sending the researcher into the weeds.

    Mind you, I feel their pain. I would hate to do triage on their product line"s CVD, and that's even without considering all the crap reports everyone gets these days from folks whose expertise consists of reading chapter one from "ethical hacking for dummies" (now with free reporting templates).

    1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

      It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

      https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

      drwho@masto.hackers.townD This user is from outside of this forum
      drwho@masto.hackers.townD This user is from outside of this forum
      drwho@masto.hackers.town
      wrote sidst redigeret af
      #58

      @GossiTheDog It's like the 90's all over again.

      1 Reply Last reply
      0
      • smilingdemon@mastodon.artS smilingdemon@mastodon.art

        @GossiTheDog which stage of dystopian hellscape is it when mega-corporations have turned law enforcement into their own private police force?

        drwho@masto.hackers.townD This user is from outside of this forum
        drwho@masto.hackers.townD This user is from outside of this forum
        drwho@masto.hackers.town
        wrote sidst redigeret af
        #59

        @smilingdemon @GossiTheDog Apple's counter-intelligence department comes immediately to mind.

        1 Reply Last reply
        0
        • theorangetheme@en.osm.townT theorangetheme@en.osm.town

          @smilingdemon @GossiTheDog The Pinkertons have been around for a century.

          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.town
          wrote sidst redigeret af
          #60

          @theorangetheme @smilingdemon @GossiTheDog And still take those contracts.

          1 Reply Last reply
          0
          • rtificial@infosec.exchangeR rtificial@infosec.exchange

            @GossiTheDog looks like we are going back to combative Microsoft of the late 90’s early 2000’s.

            drwho@masto.hackers.townD This user is from outside of this forum
            drwho@masto.hackers.townD This user is from outside of this forum
            drwho@masto.hackers.town
            wrote sidst redigeret af
            #61

            @rtificial @GossiTheDog Yep.

            1 Reply Last reply
            0
            • sycophantic@infosec.exchangeS sycophantic@infosec.exchange

              @GossiTheDog if I find a 0day I'm dropping it the same way. I'm done with responsible disclosure.

              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.town
              wrote sidst redigeret af
              #62

              @sycophantic @GossiTheDog If you do, just sell it. Probably safer.

              1 Reply Last reply
              0
              • goingforbrooke@hachyderm.ioG goingforbrooke@hachyderm.io

                @GossiTheDog 9 out of 10 doctore agree that sell-to-APT incentives are going up

                drwho@masto.hackers.townD This user is from outside of this forum
                drwho@masto.hackers.townD This user is from outside of this forum
                drwho@masto.hackers.town
                wrote sidst redigeret af
                #63

                @goingforbrooke @GossiTheDog Yep.

                1 Reply Last reply
                0
                • sigi714@ruhr.socialS sigi714@ruhr.social

                  @GossiTheDog No more help from the good guys then, M$ ¯\_(ツ)_/¯

                  drwho@masto.hackers.townD This user is from outside of this forum
                  drwho@masto.hackers.townD This user is from outside of this forum
                  drwho@masto.hackers.town
                  wrote sidst redigeret af
                  #64

                  @sigi714 @GossiTheDog Hear, hear.

                  1 Reply Last reply
                  0
                  • theorangetheme@en.osm.townT theorangetheme@en.osm.town

                    @smilingdemon @GossiTheDog The Pinkertons have been around for a century.

                    C This user is from outside of this forum
                    C This user is from outside of this forum
                    clickymcticker@hachyderm.io
                    wrote sidst redigeret af
                    #65

                    @theorangetheme @smilingdemon @GossiTheDog Two centuries. Rounded up from 175-180ish.

                    1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                      It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                      https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                      huntingdon@mstdn.socialH This user is from outside of this forum
                      huntingdon@mstdn.socialH This user is from outside of this forum
                      huntingdon@mstdn.social
                      wrote sidst redigeret af
                      #66

                      @GossiTheDog

                      When it comes to finding serious errors in it software, how does MS define "responsibly disclosed?" Does it mean "Never!"

                      1 Reply Last reply
                      0
                      • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                      Svar
                      • Svar som emne
                      Login for at svare
                      • Ældste til nyeste
                      • Nyeste til ældste
                      • Most Votes


                      • Log ind

                      • Har du ikke en konto? Tilmeld

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      Graciously hosted by data.coop
                      • First post
                        Last post
                      0
                      • Hjem
                      • Seneste
                      • Etiketter
                      • Populære
                      • Verden
                      • Bruger
                      • Grupper