Switch hacking/homebrew scene explodes when a team excommunicates one of their members for disclosing an exploit another person found without permission. Accused claims they did nothing of the sort and makes a side remark accusing the original accuser of transphobia.
18 2018-07-13 by roothorick
ReSwitched Team Twitter (Discord server link pinned there)
ktemkin Twitter is the apparent unauthorized reporter that was excommunicated. What becomes relevant far later is she is a transwoman that downplays that in her public persona.
SciresM Twitter originally discovered the exploit in question (details have been withheld and probably aren't all that important anyway),
Sci openly discourages brigading, which is interesting with comments that come later:
[6:02 PM] SciresM: @everyone There'll be some slight turbulence while we adjust the server to account for this. Hang in there.
Please note: any and all attempts to use this ban as justification to be a shithead in the server (especially in transphobic ways) will be met with a strict zero tolerance policy.
[6:52 PM] SciresM: I would like to repeat: do not harass ktemkin here or elsewhere.
Anyway, relevant comments from the remaining RS members in their Discord, with the occasional contextualizing comment from others:
[6:02 PM] SciresM: .ban @ktemkin Submitted a bootrom bug she did not originally discover (without finder consent) to bug bounty (for up to $200k), as well as other questionable behaviors towards multiple community members.
(The channel was locked for a while as people started understandably losing their shit)
[6:32 PM] SciresM: It was not f-g, she found that.
[6:41 PM] TuxSH: this is not déjà-vu, this is another exploit
[6:42 PM] SciresM: It was not sent to Nintendo.
[6:49 PM] nicolás: @azza900 like many others hedge is affected because she was friends with kate and feels betrayed
(Hedge Twitter is genderfluid and the prefers pronouns she/her, as noted on her twitter description. Hedgeberg made some tweets confirming this situation is the primary reason for her recent funk and that she feels betrayed. Her Twitter account has since been locked, hiding the tweets.)
[6:49 PM] nicolás: it wasn't hedge's bug either
[6:50 PM] Plailect 🌹: @iBlackSunday the exploit in question has not yet been released
[6:50 PM] Shúbshúb [5.x.x]: @Plailect 🌹 is said exploit on the same level as b9s?
[6:52 PM] Plailect 🌹: @Shúbshúb [5.x.x] I'm not gonna give details on sciresm's exploit, that's for him to do
[6:53 PM] Plailect 🌹: @parrotgeek1 afaik said bug is not patched in the wild
[7:06 PM] nicolás: for all we know she didn't get paid at all (but having submitted is the problem already)
[7:20 PM] n.: getting information on vulndisco from an nvidia employee is probably as unethical as pirating videogames
[7:21 PM] SciresM: @n. I won't comment further except to say that that's not what happened
Two and a half hours later, Kate strikes back on Twitter:
I haven’t sold out any Switch bugs to Nintendo; though it’s possible I exercised bad judgement in submitting some Pixel C bugs, possibly. I don’t know what the actual accusations are, as @SciresM has not been willing to communicate them to me. To date, I have not made a dime. =\
I’m really not pleased with the way that @SciresM has “come forward” with accusations— he’s provided very little info about what he believes happened, and refused to communicate with me. I won’t lie: this hurts— and given the lack of comms, I don’t even know what I deserve.
I did use a bootrom bug that @SciresM found to illustrate why a security policy decision made on the Pixel C was a bad one— but I only used this as I was under the impression (and had evidence) that NVIDIA and their subordinate OEMs already knew about that bug.
Sci counters:
We spoke more than enough in DMs. I can post more logs if you'd like, but I think that would be a major breach of privacy. [With screenshot of DMs](https://twitter.com/SciresM/status/1017608556441288706)
Around the same time, he also commented in Discord:
[10:10 PM] SciresM: We discussed this at length, examined a ton of evidence, and came to the only conclusion that there was to come to: She violated trust by reporting a bug that wasn't her discovery, and was subsequently banned.
[10:10 PM] SciresM: I've talked to ktemkin.
Kate counter-counters:
That DM is well after you made your accusations to the public, and contains only me apologizing “just in case”, while you still haven’t actually talked to me at all about what’s going on. I’m okay with you not wanting to talk about this, but not with the public accusations. :/
Then elaborates:
The vuln I reported was a config issue that was already fixed on the Switch and had been before I submitted to Google. The vul needed to be patched on th Pixel C as well, so I let them know via their bug system. I didn’t explicitly submit it to any “bounty”-targeted programs.
I... didn’t pass myself off as the author of the exploit. I found evidence that the exploit was known well before @SciresM independently discovered it, and then referenced that in my own reports to substantiate that the config bug is serious.
And now it gets personal:
Given how many times @SciresM and I have argued over his disregard for LGBT and trans rights, I don’t think any of this is actually a major concern of Scire’s. I’ve given up on expecting decency from him. Instead, he’s lied to the public repeatedly— so good riddance, I guess.
Let's return to Discord!
RS makes some dubious claims about what was discussed in the screencapped DMs:
[11:18 PM] Plailect 🌹: Ktemkin was clearly contacted by @SciresM (proof: https://twitter.com/SciresM/status/1017608556441288706) in direct contradiction to her claim that no attempt at communication has been made. She has admitted to including, without permission, a bug she did not find in a bug report to Google (proof: https://twitter.com/ktemkin/status/1017608653493305344). Regardless of whether or not Google already knew about said bug (and I have serious reason to doubt that they did), she did not have the right to share the information given to her in confidence. Without even getting into the financial incentive for her actions, this breach of trust is a violation of the ethical standards set by this community and warranted a public ban.(edited)
[11:26 PM] Plailect 🌹: As @SciresM said earlier, all that needed to be said has been said. Please be aware that any further discussion which contributes nothing but pointless bickering may result in moderator action.
The most recent development:
[11:56 PM] SciresM: fwiw: the issue was discussed internally with the team.
[11:56 PM] SciresM: (Or at least, with several relevant parties)
I like that "several relevant parties" note. The hell does that even mean?
12 comments
1 SnapshillBot 2018-07-13
You're not shit next to me. My genes are just light years superior to yours and I don't even need to look at you.
Snapshots:
This Post - archive.org, megalodon.jp*, removeddit.com, archive.is
ReSwitched Team Twitter (Discord se... - archive.org, megalodon.jp*, archive.is
Twitter - archive.org, megalodon.jp*, archive.is
Twitter - archive.org, megalodon.jp*, archive.is
Twitter - archive.org, megalodon.jp*, archive.is
https://twitter.com/SciresM/status/... - archive.org, megalodon.jp*, archive.is
https://twitter.com/ktemkin/status/... - archive.org, megalodon.jp*, archive.is
I am a bot. (Info / Contact)
1 Mary-Celeste 2018-07-13
skrrt skrrt my dicc hurt
1 le_epic_xd 2018-07-13
zoom zoom my balls sting
1 Tricitiesdrama 2018-07-13
*zing zing
1 ShizukaHiratsuka 2018-07-13
i remember using homebrew a while ago for my old wii and ripping mario kart. good times
1 PurpleIcy 2018-07-13
That's Kafkatrap if I've ever seen one. :OmegaThonk:
1 roothorick 2018-07-13
This just happened:
(same message spammed over and over again by two different users)
1 roothorick 2018-07-13
I missed some hot action over on Twitter. Kate's getting more aggressive! Now she's accusing wololo.net of spreading bad information.
Probably easier to just post a link for this. Thread between Kate and wololo https://twitter.com/frwololo/status/1017571147414528000
Thread branched a little, scroll up from here for a little more https://twitter.com/ktemkin/status/1017678934228398081
Moving on, rumors travel fast:
She retweeted a full resolution screenshot of Qyriad's rant: https://twitter.com/ktemkin/status/1017673205014618112
For context: The Pixel C uses the same SoC as the Switch, and as a result much of what RS has discovered also applied to the phone. Thus responsible disclosure becomes a consideration.
1 Ed_ButteredToast 2018-07-13
https://i.imgur.com/zWEv5Gp.jpg
1 ticktockwarrior 2018-07-13
lmao, neither /r/switchhaxing or /r/switchhacks have any threads up about this. despite the fact that it's incredibly relevant to the switch scene and will affect development heavily.
nice job posting all the relevant info, but /r/drama never appreciates or puts effort into understanding this kind of stuff.
1 roothorick 2018-07-13
Not for not trying.
1 aef823 2018-07-13
The nintendo scene was always a fucking weird part tbh.
Doesn't surprise me that it went #MeToo inb4 big gay tho.
In my experience with retards using the "disagreements betwen LGBT and trans rights" to hide behind.
The problem was less disagreements and more the dumbass using said hiding spot as a stick up their ass.
1 wtfuxlolwut 2018-07-13
Fucking kids today following responsible disclosure practices, this generation of hackers are weak source. Never disclose always exploit ruin all the things.
1 PopeCumstainIIX 2018-07-13
The programming scene in general has gone awry lately with the CoC drama, I don't really get why these smart people get sucked into a stupid authoritarian mindset, a.k.a. /r/gitinaction
1 OddSandwich 2018-07-13
ktemkin is a shit head tranny who kept using the discord server to blog about her own personal shit. Of course she's a fucking trouble maker.
1 roothorick 2018-07-13
I totally missed that there's a gbatemp thread that's up to 48 pages right now: https://gbatemp.net/threads/ktemkin-drama.511193/
One person there insinuated that Kate might be defecting to the much-reviled Team Xecuter 🤣
And now fail0verflow has been dragged into it: https://twitter.com/marcan42/status/1017760860696203265
Over in Discord, RS is doubling down:
(EdTheNerd is a purple "HoP" user class. Whatever that means. Apparently they're not all that in the loop.)
Also defending deleting Qyriad's comments and kicking her:
Deleting the comment doesn't make a lot of sense, as the ping still goes through despite the comment being deleted.
Why was the first message deleted though? Again, you didn't undo the ping.
cough
Most of the reposts I saw removed the @everyone...
💡
People keep asking why it was deleted and they keep responding it was the ping, even now. Censorship is SERIOUS BUSINESS guys.
Oh, that went over well.
Someone screenshotted a post on gbatemp: https://cdn.discordapp.com/attachments/420029476634886144/467386728022278165/unknown.png
CTCaer is an active dev in the Switch hacking scene. He's not affiliated with RS, f0f, or TX. Far as I know, he's independent.
Guys, you probably should pick a new face at this point.
We getting personal again? Where's my popcorn...
Despite a member being opposed to such an extent that they spoke out publicly and stepped down. Hmm.
Somehow missed their original declaration... maybe it wasn't really made public.
What I want to know is, did he discuss those "questionable behaviors" with Kate? And why the cocktease?
What happened to privacy?
Ah, hiding behind the "Only with her permission but I'm not going to ask and she has no idea because she's banned from the server" excuse.
Oh, so it's fine if someone else violates privacy?
What's this? A mutiny?
Hm, guess not.
That's all I see for right now.