publicly complain about how you where mistreated without prior government approval. Reporting the vulnerability after discovery to government or the organisation is mandatory and any further disclosure requires a rather frustrating process of government approval.
It's good to see people sharing stories about being mistreated after reporting vulnerabilities and deciding to limit the coordination before disclosure to avoid further mistreatment. This is why I got upset about the situation in Belgium where it is criminal to even
@huibmodderkolk '"Evidently, Western special services resolved that it would be cheaper and simpler for them to hack cellular phones than recruit costly informants with access to state secrets," the FSB officer said.' Klinkt redelijk.
@msftsecresponse That is not how I read the press release, but many apparently did. It is a weird choice that the above follow up statement does not explicitly clarify the specific language that has upset many people. Is that a consious choice by Microsoft?
@msftsecresponse A large part of the controversy, as I understood it, came from the suggestive/ambigious language by Microsoft that some people read as Microsoft implaying that publishing vulnerabilities before patches are available might be considdered as a criminal action by Microsoft.
@robertgraham@k8em0 It's weird. I didn't read their original statement like that untill people pointed it out to me. I can see it's suggestively worded. Chosing not to clarify it in this follow-up statement is a weird choice.
@RonnyTNL@GossiTheDog I read that "those actors" as refering to actors who look for weaknesses to attack Microsoft and customers (the scentence before it). Not actors who look for vulnerabilities and disclose them in a way MS feels uncomfortable with.
@caseyjohnellis I once asked someone doing ethical assesments for governments how the fact that the example he was explaining was clearly unlawful affected the ethical assesement. It didn't. That was a valuable lesson in ehtics for me.
NIEUW: Hoe een organisatieadviseur (57) en een concertpianist (39) uit Nederland pro-Russische cybercriminelen hielpen
Onderzoek met de geweldige Deense onderzoeksjournalist @moltke
https://t.co/cuGch1eFYk
The cognitive disconnect between what AI can do in blog posts, and what it fails to do in reality, is wide for me.
It can do marvels, but it can also mess up so much easy stuff. Is the capability getting even spikier?
@klaasm67 Toen ik nog in Den Haag woonde had de gemeente bovendien de handhaving uitbesteed aan de verhuurbedrijven die zelf direct of indirect de overlast veroorzaken. #innovatief
Helaas met ongeveer evenveel bewijs als degenen die zeggen dat ShinyHunters wel alle gestolen data netjes hebben gewist. Toch goed dat er meer weerstand is tegen oncontroleerbare en slecht onderbouwde claims dat de criminelen wel te vertrouwen zijn.
@elonmusk When viewing ad information I consistently see "the reason you are seeing this as is not available". It used to be visible for most ads I saw.