European Cyber Defense League | als Stein sozialisierter Birnbaum | ☚ ☛ | ♁ | ⚉
expert for cryptographic distributed social blockchain in hybrid clouds
@IntCyberDigest Discussion will die down, nightmare eclipse will be a pariah and nothing will change unless people use this momentum to publicly share their exploits they've been sitting on. Not hacked = doesnt matter to me.
‼️ After the MSRC blog post about Nightmare-Eclipse, researchers are coming forward with their own MSRC horror stories.
The response from the security community isn't going Microsoft's way. As they’re not backing Microsoft.
Gabriel Landau, a well-known Windows security researcher, says he reported a Device Guard bypass with a 90-day window. MSRC told him it met their bar and they'd fix it, then asked him to hold disclosure for extra months. He agreed on the condition they issue a CVE. They patched it silently, decided after the fact it "didn't meet the bar," and never issued the CVE. In his words: "MSRC strung me along for a few extra months to keep me quiet, then broke their word."
Another researcher, rootsecdev, says he responsibly disclosed a legacy-auth flaw that allowed password spraying while avoiding smart lockout. Five months later, MSRC replied that it "doesn't meet the bar for servicing," silently fixed it, and closed the case.
Microsoft's post was meant to defend their coordinated disclosure policy. Instead it became a thread of researchers explaining why they've stopped trusting their process.
so, fun fact about digital scales: most have fairly wide margins of error, like +/- 1-2%, which is 2-4 lbs on a 200 lbs person,
BUT they mask this by storing your weight in memory for a certain period of time - usually about 15 minutes - if you step off and step right back on, the scale will recognize this and serve you the old weight to mask the measurement error.
so it is likely this person spent just long enough in the shower for the memory to dump, and she got an honest re-read within the scale’s MoE.
My last submission to MSRC was for a Device Guard bypass. I learned my lesson from prior drawn-out submissions, so I included a 90 day window this time. MSRC responded saying that it met their bar and they would fix it, but asked me to withhold disclosure well past 90 days because they needed a few extra months to fix it. I agreed on the condition that they issue a CVE, to which they agreed.
After the agreed-upon Patch Tuesday a few months later, I couldn’t find any mention in the CVE list, so I reached out to MSRC to inquire. It turns out - they changed their minds, deciding it did not meet their bar for servicing, yet they patched it anyway. Since it didn’t meet the bar, they didn’t issue a CVE. MSRC strung me along for a few extra months to keep me quiet, then broke their word.
They could have at least bought me dinner first.
The interaction left such a bad taste in my mouth that I don’t really feel like interacting with them again. That’s why I didn’t publish any exploits/tools last year. #MeTooMSRC
Microsoft Security Response Center put out a blog post today about Eclipse Nightmare guy
Basically they think he's super mean and totally not cool he's dropping zero days. They say you're a jerk if you do this stuff because it's dangerous and stuff
https://t.co/Bg5iFxI3lc
Die StA Wien hat das Handy der ORF-Mitarbeiterin beschlagnahmt, deren Vorwürfe zum Rücktritt Roland Weißmanns geführt haben. Am Wohnsitz von Pius Strobl.
https://t.co/VGhkS7S6jA
@der_ackerl Leider besteuert die Bonzen-#SPÖ lieber die Pakete der normalen Leute und die Elektroautos von Normalverdienern um das Vermögen der Reichen zu schützen.
@AndiBabler sagt, Reiche bestreuen und meint die Vertriebsmitarbeiterin mit 4000€ brutto und Elektro Fiat-500 Firmenwagen.
@ancrth@mardehaym No, because measuring output will show that more AI doesn't improve output and risk the job of the C levels which decided to go all in on AI.
@E_Boeminghaus Im Umkreis von 500m um Dominos in der Neubaugasse gibt es min. 15 Pizzerien die gute Pizza machen und keinen räudigen Ami-Fraß.
Das ist nur ein Warnsignal, dass es wenige Menschen mit schlechtem Geschmack gibt.
#österreich#realtalk#pizza#aislop#hashtag
Diese Regierung ist komplett außer Kontrolle. Das einzige was ihnen einfällt sind Abgaben, Steuern und noch mehr Steuern.
Alles werden die Bürger tragen. Und alles wird teurer. Trump-sche Politik. Komplett dumm und irre.
Neos was is mit euch?
@Nick_Davidov@TapeTrickster That's bullshit. If you want to live in a corporate hellscape, just move to Delaware.
You can't enjoy the benefits of living in a proper society without also fulfilling your obligations.
We're in a weird era where a guy gets publicly shamed for running his sprinklers on a Tuesday, while a data center the size of a Costco quietly drains a reservoir so AI can generate a picture of your cat as a medieval knight. And the data center gets a tax incentive for it.
they want us to believe it’s a national security emergency to fall behind china on Ai but falling behind china on high speed rail, renewable energy and childhood nutrition is a-OK.
Incredible video by randomly sacked Atlassian engineer telling all about the entire company
Love this genre, like LinkedIn green banner with zero fcks given