Post B6lFLpNmJjaJkfoASG by GossiTheDog@cyberplace.social
(DIR) More posts by GossiTheDog@cyberplace.social
(DIR) Post #B6kzTdTGtAxjrL4wJk by GossiTheDog@cyberplace.social
1 likes, 2 repeats
I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled. https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure
(DIR) Post #B6kzTdvdBjeDHILaWO by GossiTheDog@cyberplace.social
1 likes, 0 repeats
Do I think the finder was acting rationally? No. Do I think Microsoft gets to decide what is criminal activity around proof of concept exploits? No.
(DIR) Post #B6kzTeZKo7PHGQvIPI by GossiTheDog@cyberplace.social
2 likes, 0 repeats
GitHub has long been a source for zero days exploits in competitor products - it still is. While I worked there GitHub had a policy saying they wouldn’t remove them. By continually removing just exploits for their own products from Github and declaring “criminal activity”, it’s a rubicon.
(DIR) Post #B6l0yn838Dz8k9ZY9I by Rairii@labyrinth.zone
0 likes, 0 repeats
@GossiTheDog i mean, i can totally understand why it was doneif the coordinated disclosure process breaks down, full disclosure seems to be the obvious result. this isn't the first time this has happened and won't be the last.MS seems to be acting more irrationally than the researcher here, banning them from MSRC seems to guarantee any future discoveries from them will be fully disclosed, and there are enough git forges that MS don't lean on.and if MS's leaning on law enforcement does end up with something happening on that front, it seems that would increase the streisand effect exponentially?
(DIR) Post #B6lFLoa9IFszGkaX68 by briankrebs@infosec.exchange
0 likes, 0 repeats
@GossiTheDog yeah that reads as pretty hostile to researchers in general and labels as "threat actors" those who don't choose to play by Microsoft's rules.
(DIR) Post #B6lFLorAGzUs7WY7cW by sly_vi@lgbtqia.space
0 likes, 0 repeats
@briankrebs @GossiTheDog not to defend M$, but isn't the responsible disclosure stuff an etiquette in the whole infosec domain? My friends working in a SOC told me so, and I can understand the point of "please think about the workers"Still, M$ wanting people to think about the workers leaves a bitter taste int mouth, and nothing justifies sending legal threats against individuals like that
(DIR) Post #B6lFLpNmJjaJkfoASG by GossiTheDog@cyberplace.social
1 likes, 0 repeats
@sly_vi @briankrebs one of the problems is everybody defines “responsible disclosure” differently - quite often companies use it to defend themselves from vulns being disclosed and from researchers, rather than protecting customers.In this case Microsoft have banned the researcher from their disclosure portal.. so how are they supposed to follow Microsoft’s process?Microsoft aren’t law enforcement, law enforcement would be wise to distance themselves from this.