Microsoft Backs Down from Legal Threats Against Security Researchers After Backlash
Executive Briefing
- Researcher 'Nightmare-Eclipse' published YellowKey zero-day exploit enabling BitLocker bypass via USB on Windows 11
- Microsoft initially threatened legal action over uncoordinated disclosure, citing risk to customers from public proof-of-concept code
- Community backlash was swift, with experts warning Microsoft was destroying a decade of goodwill with the security research community
- Microsoft reversed course, clarifying it has no intention to pursue action against individuals conducting legitimate security research
- Concerns remain about chilling effects on future vulnerability disclosures despite Microsoft's reassurances
Sponsored