Guy finds zero days and gets no compensation. Instead gets banned.
Guy sells zero days elsewhere.
Guy finds zero days and gets no compensation. Instead gets banned.
Guy sells zero days elsewhere.
He also got banned from Gitlab, which isn’t related to Microsoft at all.
and that censorship at all would compromise the point of IPFS
although I disagree with both of those takes. Nodes always had discretion in IPFS, just pick a different node or pin something yourself which has pretty much always been required. Everyone can route to your pinned files while pinned.
That git account was posted on their blogspot...
I understand Microsoft's being petty, but why would GitLab do this?
If researchers stop believing MS will treat them fairly it's bad news for the entire security industry.
Security industry going to be okay - someone will always pay for 0-days. If vendors wont pay its just gonna be US agencies, Israel resellers, China or Russia.
If you don't feed your army, you will soon feed someone's else's.
Is this just your way of saying that only tiny, weird, companies are "good"?
Zero days like this are being disclosed regularly so the idea of securing a windows workstation is tantalizing but you'll never feel satiated trying to drink that water so don't even try.
So yea there's plenty of windows users but we're certainly not hosting anything important on those boxes and would frankly be aghast at the suggestion.
Correct, "zero trust" is the buzzword but this is how Microsoft even recommends you set up your endpoint infra. Assume breach, treat every endpoint as if it is currently compromised or could be at any time. Laptops are basically ephemeral, when set up right, and can be wiped and re-imaged within an hour or less.
That's not unique to Windows either, that's how all employee/user endpoints should be managed.
Is it really fiscally responsible to tie your company's future to that?
I wonder if anyone tracks metrics for this stuff. Percentage of stuff with a repo there is probably still high, but what's happening with stuff like github actions, and are devs directly pushing to github, or are they just mirroring an internal / other provider's git repo to it?
No problem. The CIA will give it's high level officers millions of dollars in gold bars simply for the asking. I'm sure purchasing exploits doesn't even require a purchase order.