12 ms·
Does it? Now that I see their name again in this context they're blacklisted for life.
by jasonmp85 5mo ago
Does it? Now that I see their name again in this context they're blacklisted for life.
- CSSer 5mo agoYes, exactly. Name and shame.
- true_religion 5mo agoSame. I did not know who they were, but now they have been named and shamed. Not every publicity is good.
- Scharkenberg 5mo agoIt is the opposite for me. I did not know who they are and now I have a positive opinion of them.
- selectively 5mo agoResearchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.
- lambda 5mo agoIf they want to be seen as responsible rather than opportunistic, then yeah, they should do a proper coordinated disclosure. Sure, they have no legal obligation to disclose, but we all also have no legal obligation to buy their services. Blacklisting bad actors like this is the right move to discourage this kind of behavior.
- selectively 5mo agoWho cares about how you are seen when you are selling 0day for big bucks? The bad actor makes more money than the 'legitimate' one without breaking any law. Punishing someone who didn't alert distros despite a patch being available encourages the company to simply find flaws and sell them for profit - it pays more to begin with.
- _yttw 5mo agoIf they want to take advantage of disclosure for marketing, they're either going to need to accept the norms around responsible disclosure, or they're going to need to accept how shirking those norms will come off. That's life in society. Sometimes it's annoying and sometimes it doesn't feel rational, but these norms have been negotiated throughout the history of our industry and are the way they are for reasons good and bad. I just don't see the point in complaining about how shirking the norms of your industry will make you look irresponsible. I don't really care that they could have decided to sell the vulnerability instead. It isn't material.
- selectively 5mo agoThose norms do not exist. Those are people asking companies to do stuff to benefit the person complaining for free, and many companies will not do that.
- _yttw 5mo agoIt seems to me you're unaware of them, but there are strong norms around disclosure. They've been discussed for decades. It is the expectation that vendors would be notified in a scenario like this.
- selectively 5mo agoNo, there are users who want those to be norms. Qualified researchers happily sell substantive vulns to people who pay (Governments/Cellebrite and companies like that) enough to quell any complaint.
- _yttw 5mo agoWhich is again, irrelevant to the question of how disclosure works and what expectations there are around it because that is not disclosure and is not what was being discussed.
- 5mo ago
- john_strinlai 5mo ago>they should do a proper coordinated disclosure. they did a proper coordinated disclosure, following the industry standard 90+30 process. that is why the exploit dropped 30 days after the patch landed. the kernel team should have communicated with their downstream about the importance of the patch. that is the kernel security team's responsibility -- and they are much better positioned to do that than crossing your fingers and hoping every reporter will contact every distro every single time there is a vulnerability. there are very good reasons disclosure works this way, backed by a couple of decades of debate about it.
- lstodd 5mo agohow many times it has to be said that it is impossible for linux kernel to communicate with anything but a minuscule portion of its downstream and _that_ has been done?
- eschaton 5mo agoThey should have a legal obligation to engage in coordinated/responsible disclosure, and it should be a crime to sell or disclose a 0day to anyone other than a state-designated security organization or the vendor/provider. If it won’t be handled through criminal law then it’ll be handled through civil litigation: Anyone who was exploited as a result of this disclosure should sue the discloser for contributing to the damage they’ve suffered.
- kelnos 5mo agoI'm pretty sure they have a legal obligation in most jurisdictions not to sell 0days for profit. And they absolutely have a moral obligation to do things in a way to minimize damage and impact to other people's systems. (I'm not saying "responsible disclosure" is the correct way to do that, but hoarding vulnerabilities and exploits and selling them to the highest bidder certainly isn't.) This is how society needs to work.
- mschuster91 5mo ago> I'm pretty sure they have a legal obligation in most jurisdictions not to sell 0days for profit. it wasn't sold for profit, it was openly disclosed. > And they absolutely have a moral obligation to do things in a way to minimize damage and impact to other people's systems. All that "responsible disclosure" does is keep people from demanding better.
- lrvick 5mo agoLet me make you aware of zerodium. A broker anyone can sell vulns to, that sells to unspecified buyers you do not need to know about.
- selectively 5mo ago(The buyers are the NSA, the IDF, Cellebrite, NSO and its successor corporation and that kind of thing. Depends on what you are offering) You'll learn who the buyers are if you routinely have the really good stuff to sell! If you are offering iOS zero click on a semi-regular basis, the buyer is going to want to try to deal with you directly and preferably offer you a more regular form of employment, if you are interested. Some national governments may offer certain benefits to you, depending on your situation. All depends on what you have to offer. If you were able to offer this https://arstechnica.com/security/2025/09/microsofts-entra-id-vulnerabilities-could-have-been-catastrophic/ https://arstechnica.com/security/2025/09/microsofts-entra-id... or something of that magnitude, a lot of problems in your life would just go away. The buyers would all be Five Eyes and the intelligence gain of having that kind of access even briefly is priceless. In a more Western-centric context, imagine if you had a flaw like that, same 'no logs are generated' and 'every single customer account is accessible' but the impacted vendor was Alibaba Cloud. The researcher would get to name their price. That's the real world, that's the world we share. We shouldn't be blind to that.
- grayhatter 5mo ago> Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Uh... no? If you mean legally, some people might, depending on jurisdiction. But also, ethically? yes, researchers are ethically obligated to disclose responsibly. > Just fyi. ... > Be glad it was disclosed at all. Be glad a patch was available prior to release. I am glad that a patch was available. Equally I can be glad that the linux community is strong enough to respond quickly, while also being angry that this person behaves unethically. Likewise, when people in my industry behave poorly, or unethically; I'm now the person ethically obligated to both point it out, and condemn it. Not to become an apologist demanding I should be happy watching bad things happen, when much of the fallout could have been prevented with a bit less incompetence and ignorance.
- jojomodding 5mo ago> are free to sell 0day for profit. This is not true in many jurisdictions.
- lrvick 5mo agoAnyone can sell a vuln in any jurisdiction and never be caught. Lets not pretend the law is actually worth a damn here. We need an anonymous bounty system.
- selectively 5mo agoAre you claiming that if I sell 0day through a broker to the national Government of a given jurisdictions that the national Government of that jurisdiction is going to criminally penalize me? If so, that's a bit naive. In the actual world, that buyer wants to buy more stuff from me, not penalize me.
- deleted 5mo ago[deleted]
- deleted 5mo ago[deleted]
- estimator7292 5mo ago[flagged]
- ux266478 5mo agommmmmm, no it would seem like they are absolutely under a social obligation to not do that.
- lrvick 5mo agoUnfortunately this is correct. As a security researcher I set millions in profit on fire for reporting vulns to projects that offer no bounties vs selling to highest bidder. I keep doing it because it is the right thing to do, but I would not blame someone that needs to feed their family making a different choice. We must get public funds to reward ethical disclosure of big impact vulns like this.
- selectively 5mo agoHarder and harder to get good policy like what you describe when tech-adjacent people loudly argue for criminal penalties for anything other than coordinated disclosure :(
- robocat 5mo ago> criminal penalties Mostly cover citizens within a very limited set of jurisdictions. Otherwise there's a chance at extradition.
- bigbadfeline 5mo ago> Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. I'm so glad these so called "researchers" aren't totally evil, I'm so grateful they're only half evil, give them a lollipop. Whatever, the way they disclosed it isn't much different from no disclosure at all - the exploit would have been identified in the wild and fixed soon thereafter. "Researchers"...
- john_strinlai 5mo agothe way the disclosed it is the industry standard. think of the biggest security research teams you know (e.g. google), and they follow the same process. non-security people always seem to get up in arms about it, but there is very good reasons why the industry has landed on the process it has, which has been hashed out over a few decades.
- selectively 5mo agoThere are two options: 1. Status quo. Researchers are free to disclose to a vendor, free to sell vulns to legitimate companies, free to do full disclosure if they want. This situation benefits security. Researchers are able to pay their bills while also doing meaningful research into OSS projects that are unable to fund the kind of security audit they need. Harm reduction, of sorts. 2. Everyone is a bad actor. No one is going to do this work for free/for a bounty. Horrible flaws will be found and shared with ransomware gangs and the like. 0day will sell for a percentage of the ransom winnings. Researchers will live like kings, everyone else will suffer. Which do you prefer?
- eaf7e281 5mo agoSame. They do become famous, but not in a wholly positive way.
- esseph 5mo agoI used to think the context of the fame mattered. At least in the US, it does not. Hell, Crowdstrike is still purchased.
- john_strinlai 5mo agohope you are also blacklisting google's project zero, and practically every other major player in the vulnerability reporting space, as all use roughly the same bog standard 90+30 policy. this was a failure of the kernel security team, and their stance on communicating security issues with their downstreams.
- bathtub365 5mo agoWhat are they blacklisted from exactly? The benefit you get from them forcing vendors to make their software more secure?