You can criminalize the messenger. The bug doesn't care.
June 23, 2026 · Paul Graham, Hackers & Painters~5 min read
In May 2026, someone calling themselves Nightmare Eclipse dropped six Windows zero-days online — working exploit code included, no warning to Microsoft. Microsoft's answer wasn't only a patch. It was a threat of criminal prosecution. And here is the thing both sides keep walking past: the prosecution decides who gets punished. It does not decide whether the holes are still there. They are.
What actually happened, with the ugly parts left in
Let's not flatten this into a hero story. Nightmare Eclipse published flaws in core Windows products — including Defender, Microsoft's own antivirus engine, and the disk-encryption tool BitLocker — and named them BlueHammer, RedSun, UnDefend, and YellowKey. The disclosure was uncoordinated: no quiet window for Microsoft to ship a fix first. By Microsoft's account, three of those bugs were already being used in real attacks before any patch existed. That is a real cost, paid by real people, and pretending otherwise would be dishonest.
The researcher tells a different origin story: they say they tried to work with Microsoft first, got mistreated, had their MSRC reporting account revoked, and were stiffed on a bounty. Both things can be true at once — that the channel failed them, and that dumping live exploits on the open web put users in front of a moving car. The interesting question isn't who's the angel. It's what Microsoft reached for when it got angry.
Microsoft reached for the prosecutor
On May 28, Microsoft's Digital Crimes Unit threatened the researcher with criminal investigation. The next day it published a blog post scolding them for "irresponsible disclosure" and endangering users. The security world did not nod along. Katie Moussouris — the person who built Microsoft's own bug-bounty program — said plainly that the predictable result is fewer people reporting bugs, which makes all of us less safe. Within days Microsoft walked it back: it had "no intention to pursue action against individuals conducting or publishing their security research." The threat was withdrawn. But the chilling signal had already been sent, and you can't fully un-send a signal like that.
A bug is a true thing about the world
Paul Graham, in Hackers & Painters, has an essay called "What You Can't Say." His point is that every era has heresies — statements that are true but get you punished for saying them — and that the punishment is aimed at the speaker, never at the truth. A vulnerability is exactly this kind of statement. BlueHammer isn't an opinion Nightmare Eclipse holds about Windows. It's a fact about Windows: under these conditions, the system can be made to do something it shouldn't. The exploit is just the sentence that says it out loud.
So watch what a prosecution can and can't touch. You can revoke an account. You can name a person in a blog post, sic a Digital Crimes Unit on them, make an example. What you cannot do, with any of that, is reach into the binary and close the hole. The truth the researcher uttered stays true after they're silenced. The attackers who were already using three of those bugs do not need the researcher's permission, or yours, to keep using them. Punish the messenger all you want; the message was about the world, and the world didn't change.
A vulnerability is a true fact about a system, and prosecuting the researcher who discloses it (as Microsoft threatened over the Nightmare Eclipse Windows zero-days, May 2026, before walking it back) changes who gets punished, not whether the bug exists. The incentive runs one way: punish reporting, get fewer reports and a less-safe system. Framework: Paul Graham, Hackers & Painters, "What You Can't Say." Popular-science interpretation.
Why this optimizes for silence, not safety
Graham's other half — the one that keeps this from being a free pass for recklessness — is that knowing a forbidden truth and broadcasting it to a mob are different acts. He's almost paranoid about how you say a dangerous thing: to whom, in what room, with what timing. That's coordinated disclosure in a nutshell. Tell the vendor, give them a window, then go loud. Nightmare Eclipse skipped the careful part and handed live ammunition to whoever was watching. Graham would not applaud that. The friction is real on both sides.
But here's the asymmetry that should decide it. When a vendor punishes the careless reporter, the next ten careful reporters watch and learn — and the lesson they take isn't "disclose more carefully." It's "don't pick up the phone at all." Moussouris's warning is just incentive design said out loud: the move you most reward is the move you get more of, and the move you most punish is the move you get less of. Criminalize the act of telling, and you don't get safer disclosure. You get a researcher who finds the next BlueHammer, thinks about a Digital Crimes Unit, and quietly closes the tab. The bug stays. Now nobody's looking at it but the attackers.
What this means for you
You don't run MSRC, but you run the same play in miniature every week. The intern who flags that the deploy script has been silently corrupting data for a month. The teammate who says the architecture everyone praised has a hole in it. The tester whose bug report makes the demo look bad two days before launch. Every one of them is a Nightmare Eclipse on your team — a person handing you a true, unwelcome fact about something you own. And the cheapest reflex in the world is to shoot them: kill the message by making the messenger regret it. Graham's hacker ethic cuts the other way. Care whether a thing is right, not whether saying so is welcome. The person who tells you where you're broken is the single contributor you can least afford to teach to stay quiet — because the brokenness, like the bug, was never in their report. It was already in you. They just said it out loud.
Punishing the report doesn't fix what it found
Silence the messenger and the vulnerability stays exactly where it was — only now nobody's pointing at it but the people exploiting it.
Framework drawn from Paul Graham's Hackers & Painters, especially the essay "What You Can't Say." Reporting from TechCrunch (May 29, 2026), The Record, Microsoft's own MSRC blog, and the wider security-community response (including Katie Moussouris). A popular-science interpretation — not security or legal advice; intellectual property belongs to the original author.
保罗·格雷厄姆在《黑客与画家》里有一篇《你不能说的话》。他的意思是:每个时代都有自己的异端——那些为真、说出来却会惹祸的陈述——而惩罚永远冲着说话的人,从不冲着那个真相。一个漏洞,恰恰是这种陈述。BlueHammer 不是 Nightmare Eclipse 对 Windows 持有的某个观点,它是关于 Windows 的一个事实:在这些条件下,系统能被逼着做它本不该做的事。利用代码,不过是把这句话大声说出来的那个句子。
バグはシステムについての真実であり、開示した研究者を訴追しても(Nightmare Eclipse の Windows ゼロデイをめぐりマイクロソフトが脅し、2026年5月、のちに撤回)、変わるのは誰が罰せられるかであって、バグが在るかどうかではない。誘因は一方向に働く——報告を罰すれば、報告は減り、システムはより危険になる。枠組:ポール・グレアム『ハッカーと画家』「言ってはいけないこと」。科学解説。