‼️ After the MSRC blog post about Nightmare-Eclipse, researchers are coming forward with their own MSRC horror stories.
The response from the security community isn't going Microsoft's way. As they’re not backing Microsoft.
Gabriel Landau, a well-known Windows security researcher, says he reported a Device Guard bypass with a 90-day window. MSRC told him it met their bar and they'd fix it, then asked him to hold disclosure for extra months. He agreed on the condition they issue a CVE. They patched it silently, decided after the fact it "didn't meet the bar," and never issued the CVE. In his words: "MSRC strung me along for a few extra months to keep me quiet, then broke their word."
Another researcher, rootsecdev, says he responsibly disclosed a legacy-auth flaw that allowed password spraying while avoiding smart lockout. Five months later, MSRC replied that it "doesn't meet the bar for servicing," silently fixed it, and closed the case.
Microsoft's post was meant to defend their coordinated disclosure policy. Instead it became a thread of researchers explaining why they've stopped trusting their process.
@NoLimits057@riotgames Its a paperweight, because the cheating method with this hardware has been blocked. The ahrdware itself is still fine and nothing is bricked.
To help protect Signal users from phishing and social engineering attacks, we’ve introduced additional confirmations and educational messaging in the app to help people better detect fraudulent profiles, especially message requests from scammers posing as Signal.
More changes are on the way.
@gergokevok@RiotK3o Really a dumb idea to answer this bullcrap of lersonal feelings without any thought. Riot is not dumb. They want to have many players playing their game. Every ban is one less potential future customer, why would they want to hand out false bans in masses?
Mitbekommen?
Ein Autohändler, FDP-Politiker, stellvertretender Landrat, Träger des Bundesverdienstkreuzes muss sich vor dem Landgericht Mönchengladbach verantworten.
Der Vorwurf: Steuerhinterziehung, Umfang fast 38 Millionen Euro.
Zum Prozessbeginn gestand er.