Live data from Hacker News

Hackers exploited Word flaw for months while Microsoft investigated

reuters.com

11–20 of 105 posts

Re: Hackers exploited Word flaw for months while Microsoft investigated

#11
post #8

Earlier quoted context omitted.

Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…

> to establish a de-facto standard on the home desktop market... Doesn't this have a lot more to do with pre-installs, and the marketing power that comes with it? Dell's XPS Linux line and the Asus EEE PC were/are both pretty popular with the average person, so far as I'm aware.

Indeed. No one wanted Windows until it came preinstalled.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#12

Earlier quoted context omitted.

Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…

But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc Just for the record in case someone isn't aware: Modern Linuxes are often easier to install and install software onto (as long as that software isn't written specifically for Windows or Mac OS.)

I find they still fail a lot of the time. Some issue's I've come across recently:

* no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far.

* Can't change login screen resolution (haven't seen a way to do this on any distro I've tried).

* Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no automatic scaling).

* Secondary drives require manual mounting (or doing it yourself at the command line).

Re: Hackers exploited Word flaw for months while Microsoft investigated

#13
Vendors, even ones as large as Microsoft, do not have infinite resources available to evaluate vulnerabilities. There are only so many of the issues you can work on at once. They have to evaluate each issue and prioritize the fix. In this case, they merely did not recognize the potential scope of the problem at hand.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#14
post #4
post #2

https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…

Microsoft was really really bad at security. Then the internet became a popular thing. I think an fresh xp install would, on average survive 15 minutes before getting infected by blaster. Microsoft, to their credit, improved dramatically. I don't know if they're extraordinarily good compared to other software producers. Microsoft gets the mention because it was so very bad, back in the day. It's kind of like when a v…

There were versions of windows, 2000 if not XP, that could and would get infected in-between the time the network stack initialized and the local software firewall initialized a second or two later. This was actually addressed and fixed, because it was not a unique experience. That's how pervasive and wild the exploit network traffic was before MS got their act together.

Edit: My google-fu is failing me, and I can't find the right keywords to find a reference to this, but I distinctly remember it. Back in the days when firewalls weren't quite as pervasive, and especially not for small colo deployments.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#15
post #2

https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…

We will never know the answer to your assertion until more than 1% of the OS market is open source.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#16
post #2

https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…

Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…

"But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc"

For what it's worth (which may be not a great deal): I have installed a lot of Windows and Linux over the years, but my Windows experience has been lackin further and further behind these last few years. A short while ago, I had to a rare chance of setting up two identical machines side by side, one with Windows 10, one with Manjaro, an Arch Linux derivative. The Linux install finished sooner and with less need of interference than the Windows one. It also didn't require preparatory messing round with weird licensing codes and what have you, and of course it didn't require one tenth the amount of postprocessing to reach the desired level of functionality - compare the twenty second operation of setting up a LaTeX which worked to the corresponding twenty Windows minutes of setting up one which didn't.

Your anecdotal mileage may obviously vary.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#17

Vendors, even ones as large as Microsoft, do not have infinite resources available to evaluate vulnerabilities. There are only so many of the issues you can work on at once. They have to evaluate each issue and prioritize the fix. In this case, they merely did not recognize the potential scope of the problem at hand.

That's true, but it doesn't matter. It's still broken.

That's why we have automatic release after a set time. Because it's a problem for the public even if the vendor has zero resources. The ability of the vendor to fix the problem is not related at all to the potential damage the problem can cause.

Worst-case scenario? The software is shutdown and/or withdrawn from the market because the vendor can't fix it. Not that the vulnerability isn't announced.

What we need is a public and open way to do this that doesn't involved walled gardens.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#19
post #12

Earlier quoted context omitted.

But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc Just for the record in case someone isn't aware: Modern Linuxes are often easier to install and install software onto (as long as that software isn't written specifically for Windows or Mac OS.)

I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…

Pure nonsense. Or did you try a distribution from 2002?

Re: Hackers exploited Word flaw for months while Microsoft investigated

#20
I thought that it is the norm for M$ to hand out the zero-days to the 3-letter-agencies for "a while" and patches them ONLY when someone else gets hold and starts using the same vuln.. so it makes PERFECT sense that they would do something like that.

Also who in their right mind allow Word/Excel/Powerpoint to access the internet? (oh yes it's called "365" and it makes software, that is completely unfit for the task, to access the internet)

Post reply on HN