this post was submitted on 29 May 2026
86 points (98.9% liked)

Technology

84980 readers
3357 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

Researchers normally submit such findings to the Microsoft Security Response Center (MSRC) for patching to prevent hackers from exploiting them. But Nightmare Eclipse has deliberately ignored the responsible disclosure route, citing claims that Microsoft mistreated them.

“They mopped the floor with me and pulled every childish game they could,” the researcher wrote last month, without elaborating. “It was soo bad at some point I was wondering if I was dealing with a massive corporation or someone who is just having fun seeing me suffer but it seems to be a collective decision.”

you are viewing a single comment's thread
view the rest of the comments
[–] disorderly@lemmy.world 23 points 1 hour ago (1 children)

Every place I've ever worked has tried to play cute with security researchers. I've never understood it. I've always called it out. But I keep fucking running into it!

[–] crunchy@lemmy.dbzer0.com 10 points 59 minutes ago

They know that most security researchers won't risk legal action by releasing through other means, so they'll do whatever saves them a few dollars in paying them.

But what can we do about it? A nonprofit legal fund that barely stands a chance against Microsoft's legal team? There must be something meaningful.