Microsoft is threatening legal action for disclosing exploits


Microsoft is facing criticism for its handling of zero-day exploits. Someone going by the name Nightmare Eclipse has been publicly feuding with the company, posting proof-of-concept exploit code. Some of their posts suggest that they’re a disgruntled former employee. But what caught cyber security researcher Kevin Beaumont’s eye was how Microsoft has responded.

Microsoft suggests it plans to bring a criminal case against Nightmare Eclipse for failing to follow “proper coordination” in disclosing vulnerabilities. They also disabled Nightmare Eclipse’s GitHub, GitLab, and Microsoft Security Response Center accounts disabled. As Beaumont points out, “It’s quite difficult to ‘responsibly’ report future vulnerabilities when you have been banned.”

What troubles Beaumont is that Microsoft has hired people who have done many of the exact same things. They’ve employed people who have publicly posted zero-day exploits, some with criminal hacking convictions on their record. Microsoft has also purchased exploits from brokers.

If Microsoft’s tactic is to try to criminalise not following often arbitrary “responsible disclosure” frameworks, good luck defending that in court — because there’s a whole clown car of prior decision making within Microsoft and facts which would emerge in that process.



Source link

  • Related Posts

    Quilts Are Better Than Sleeping Bags

    I used to say that all my best days started with waking up in a sleeping bag. Waking up in a sleeping bag usually means you’re out there somewhere, doing…

    Snap alums unveil Ghost Angels fund

    A group of 20 Snap alumni has come together to launch a fund called Ghost Angels to back the next generation of social media. The fund declined to disclose how…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Farewell: Pilot Of Spirit Airlines’ Last Las Vegas Jet Performs Final “Wing Wave”

    Farewell: Pilot Of Spirit Airlines’ Last Las Vegas Jet Performs Final “Wing Wave”

    These 15 Levi’s New Arrivals Are So Worth It For Summer

    These 15 Levi’s New Arrivals Are So Worth It For Summer

    Colombia’s Elections Are a Crucial Test for the Left in Latin America

    Colombia’s Elections Are a Crucial Test for the Left in Latin America

    Minister Joly to meet with Yulia Navalnaya in Ottawa

    Minister Joly to meet with Yulia Navalnaya in Ottawa

    ‘So much love’: Montreal Victoire celebrate Walter Cup win with downtown parade – Montreal

    ‘So much love’: Montreal Victoire celebrate Walter Cup win with downtown parade – Montreal

    Microsoft is threatening legal action for disclosing exploits

    Microsoft is threatening legal action for disclosing exploits