4 ms·
I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.
by bitbasher 4mo ago
I can’t help but feel Microsoft will regret this.
Guy finds zero days and gets no compensation. Instead gets banned.
Guy sells zero days elsewhere.
- akkartik 4mo agoNot to mention all the other people who find 0-days. Reputation matters a lot.
- mapontosevenths 4mo agoYep, and its a really small world out there. If researchers stop believing MS will treat them fairly it's bad news for the entire security industry.
- SXX 4mo agoWell. Its a bad news for society as whole. Security industry going to be okay - someone will always pay for 0-days. If vendors wont pay its just gonna be US agencies, Israel resellers, China or Russia. If you don't feed your army, you will soon feed someone's else's.
- rurban 4mo agoIt's had bad news only for Windows buerocrats. Good orgs don't use Windows.
- mapontosevenths 4mo agoI have now worked for/with a significant percentage of the fortune 500. All used Windows in some capacity. Is this just your way of saying that only tiny, weird, companies are "good"?
- hparadiz 4mo agoThese days corporate security treats these workstations like a dummy terminal. No secrets live on the workstation. You have to re-auth with sso constantly with biometrics and are basically editing data that is in a cloud. So the risk to a corp is minimal where even in the worst case they are insured. Zero days like this are being disclosed regularly so the idea of securing a windows workstation is tantalizing but you'll never feel satiated trying to drink that water so don't even try. So yea there's plenty of windows users but we're certainly not hosting anything important on those boxes and would frankly be aghast at the suggestion.
- thewebguyd 4mo ago> These days corporate security treats these workstations like a dummy terminal Correct, "zero trust" is the buzzword but this is how Microsoft even recommends you set up your endpoint infra. Assume breach, treat every endpoint as if it is currently compromised or could be at any time. Laptops are basically ephemeral, when set up right, and can be wiped and re-imaged within an hour or less. That's not unique to Windows either, that's how all employee/user endpoints should be managed.
- rurban 4mo agoIt's saying that those with Windows could be 100x more effective and secure. Wasting billions of money and a lot of time
- hedora 4mo agoNot to mention all the startups being founded right now. Sure, github's still the default, and maybe you can still monetize stars or something, but it's also a clown show from an availability, feature roadmap and company policy perspective. Is it really fiscally responsible to tie your company's future to that? I wonder if anyone tracks metrics for this stuff. Percentage of stuff with a repo there is probably still high, but what's happening with stuff like github actions, and are devs directly pushing to github, or are they just mirroring an internal / other provider's git repo to it?
- Aurornis 4mo agoBut the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.
- linkregister 4mo agoI'm not sure if this is an unintentional mistake. Gitlab did not perform a ban. Github performed the ban. Github is fully-owned by Microsoft.
- gchamonlive 4mo agoEver considered these aren't the full set of exploits the researcher discovered? Or that he can find more since he found these? If I found a bunch, I'd certainly withhold a few as insurance.
- thewebguyd 4mo ago
- themafia 4mo ago> Guy sells zero days elsewhere. No problem. The CIA will give it's high level officers millions of dollars in gold bars simply for the asking. I'm sure purchasing exploits doesn't even require a purchase order.
- nullbio 4mo agoWhy would they regret it? According to the person who found them, they put those vulnerabilities there for a reason.