https://twitter.com/SandboxEscaper/status/103411618937352192...
https://twitter.com/SandboxEscaper/status/103411292604562227...
EDIT as @dixie_land points out, it appears the author is open to selling indiscriminately.
https://twitter.com/SandboxEscaper/status/103411618937352192...
https://twitter.com/SandboxEscaper/status/103411292604562227...
EDIT as @dixie_land points out, it appears the author is open to selling indiscriminately.
From her website - http://sandboxescaper.blogspot.com:
> I'm also transgender. But my transition so far has been really difficult (social isolation, lack of support.. etc), my voice is still really manly and I don't really pass at all (which probably weirds people out.. so I would rather say it upfront so I don't need to have anxiety about it, I have alot of anxiety issues). I also have not been able to change my name yet, legally its still "Thomas".
- - -
w.r.t. the 0-day release: Well that's some seriously irresponsible stuff right there.
I think she has a tough time (she's transgender and doesn't have support from her peers). It's sad that she hasn't found a way to live a happy life although she clearly has serious skills. I hope she'll be fine.
It's just annoying that a lot of users are now at risk, I hope the patches will be installed ASAP.
Is selling an exploit to a foreign government even 100% legal? (Serious question; that seems like the sort of thing that could get one in trouble.)
Exploit development security research is something that there's a surprisingly small market for... unless you're selling vulns. And buyers are usually either government intelligence services or organized crime (skipping right past "what's the difference hyuk hyuk hyuk").
Doing the work first and selling it later is always inherently risky, be it writing a novel or bug hunting.
It sometimes can be perhaps slightly less lucrative than you might expect, with your average pen tester paid significantly less than your average SWE. And often somewhat different than the kind of specialty skills someone focused on (say) Windows Internals might have. Compare with selling exploits, where a month's worth of highly enjoyable work might turn into mid-five-figures. Or higher.
You're absolutely right. Penetration testing and code auditing are ways to make money. It's possible that there may be some relevant differences in both subject and compensation is all.
Companies, such as companies that sell surveillance software to governments, do hire people to just find exploits, but judging by leaked emails that can be a stressful job as you are expected to regularly deliver new exploits.
> I think she has a tough time (she's transgender and doesn't have support from her peers)
This is from her website, I don't like armchair-psychoanalysis, either:
> I'm also transgender. But my transition so far has been really difficult (social isolation, lack of support.. etc), my voice is still really manly and I don't really pass at all (which probably weirds people out.. so I would rather say it upfront so I don't need to have anxiety about it, I have alot of anxiety issues). I also have not been able to change my name yet, legally its still "Thomas".
from http://sandboxescaper.blogspot.com
Seems I was the only one who clicked on her website. The first question I've had in my mind: "What does this person feel? It's weird to publish 0-days on Twitter with a little bit of rant"
For the downvoters: Would love to know why you downvoted me. Maybe I can clarify some aspects.
Many people I've talked are in favor of full-disclosure and think that coordinated disclosure is long term dangerous as large companies with the resources to actually develop secure software are not sufficiently incentivized to do so under coordinated disclosure.
Edit: I've also noticed on HN that sometimes I will get downvoted really hard for no clear reason and then two weeks later HN will magically transform my downvotes into upvotes. Not really sure why that happens, maybe a wave of bot banning?
Yup, I've seen this more recently but now the cycle is faster. My comments regularly get downvotes but then later in the evening they turned into upvotes.
Also back in Dec 2017, there was a huge wave of people shilling on reddit for ICOs and subreddits would regularly post what "HN users think" and "how to correct them".
I'd like to also point out that there is a very real cabal of HN nicks that is actively doing drive by downvotes on specific topics centring around LGBTQ+, immigration and ICOs.
I started seeing this back in 2014 and it correlated with the rise of r/the_donald. There are even amino groups that specifically coordinates such attacks. For instance, the Damore threads were really interesting. Within the first few hours of posting there were a lot of comments seemed off for HN userbase, defending trump and Damore's manifesto. Counter comments were flagged and downvoted.
We know reddit is under the influence of shills and HN is not exempt.
1st link -> http://archive.is/8xh4z
2nd link -> http://archive.is/KGyCf
If this is the case, which I can see how it could be, then this is the bigger story for those outside of Tech circles to understand.