this post was submitted on 27 May 2026
918 points (99.2% liked)

Technology

85168 readers
3978 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
(page 2) 50 comments
sorted by: hot top controversial new old
[–] stickyprimer@lemmy.world 15 points 1 week ago

Eclipse implies that Microsoft ignored or refused their zero-day reports and/or did not pay out bounties as requested, somehow causing financial harm in the process.

“Somehow?”

Were the bounties not earned? Because simply not paying as a promised for services rendered is a very clear financial harm.

[–] bss03@infosec.pub 15 points 1 week ago (1 children)

Responsible disclosure is a kindness; it is not required--especially if/when the vendor doesn't act in good faith.

MS shouldn't be able to silence researchers, but that's what the industry gets by voluntarily clustering around a single, proprietary service.

I don't think either party should be compelled to take (or reverse) any action.

[–] motruck@lemmy.zip 7 points 1 week ago

Exactly. Thank you Microsoft do more of this so we end up in a federated world.

[–] apftwb@lemmy.world 12 points 1 week ago* (last edited 1 week ago) (1 children)

Too bad there aren't any GitHub alternatives for them to post future exploits on.

[–] Jhestyr@lemmy.world 7 points 1 week ago (1 children)

I have to assume being sarcastic. But if not a locally hosted gitea is trivial to set up.

[–] DanceMomsSavedMe@lemmy.zip 4 points 1 week ago (1 children)

Everyone keeps mentioning this but what about Codeberg or one of the other ones I see mentioned here a lot?

Are those not viable alternatives that you don't have to self host?

Codeberg would be sympathetic to the cause but does not have the €€ or legal power to deal with being bullied by microSLOP. :( Corporate law in Europe (and everywhere) is written to favour & protect big corps and corruption & bribery.

[–] someone@lemmy.today 11 points 1 week ago (5 children)

If she's going for maximum damage, I am surprised this person doesn't just announce when she's found a big exploit, and then just sell it to up to 10 people, and then announce in very vague terms what the exploits are. (Like, "just sold exploit for windows defender" or "just sold way to hack into bitlocker").

It seems like the vagueness of such things would make corporations more worried about being hacked and Microsoft could only guess as to what specific code was hacked, costing them greater resources.

Yes, it would be illegal, and therefore I hope she doesn't do that and recommend against it. But I am just surprised, given the level of anger, that she has been approaching things in a way that is so easy to patch.

Is her approach more damaging the way she's actually doing it?

load more comments (5 replies)
[–] Reygle@lemmy.world 9 points 1 week ago

HACK THE PLANET's windows

[–] tobebannedbygaymods@lemmy.zip 7 points 1 week ago

friendly reminder there is a github replacement for opensource made by framasoft I think

[–] GnuLinuxDude@lemmy.ml 7 points 1 week ago

Best of luck to him on his crusade. Full support!

[–] sturmblast@lemmy.world 6 points 1 week ago

Microsofts been spitting at the rain for decades

load more comments
view more: ‹ prev next ›