Live data from Hacker News

Hackers exploited Word flaw for months while Microsoft investigated

reuters.com

21–30 of 105 posts

Re: Hackers exploited Word flaw for months while Microsoft investigated

#21
post #6

Earlier quoted context omitted.

Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…

The sentiment of "the better product will win" is understandable, but wrong as you present it. Microsoft managed to gain a monopoly (legally or illegally - doesn't matter) and has used it to illegally keep others out, and network effects now (and for the past 20 years) have been that "goodness" measure - technical mediocrity had been sufficient (although recently they have been doing a lot of excellent technical work…

This is very true, since the idea of meritocracy doesn't do a lot to overcome business inertia of being in a Microsoft Environment.

If there is a Linux solution that in every way exceeds a Microsoft Solution from a technical and price standpoint, you still need to weigh in the transition costs, employee costs, and the long term effect of changing. It's not always as simple as "X is better than Microsoft's Y, people will use it." There are far more things that get considered, and you can get tied down pretty heavily when your entire workflow and operations rely on a single product or vendor.

The longer you've been using a product, the harder it is to get away from it. It's not that Linux isn't good or making a lot of cool progress in all realms, it's that Microsoft does "good enough" and the transition isn't seamless enough for many use cases.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#22

Vendors, even ones as large as Microsoft, do not have infinite resources available to evaluate vulnerabilities. There are only so many of the issues you can work on at once. They have to evaluate each issue and prioritize the fix. In this case, they merely did not recognize the potential scope of the problem at hand.

That's true, but it doesn't matter. It's still broken. That's why we have automatic release after a set time. Because it's a problem for the public even if the vendor has zero resources. The ability of the vendor to fix the problem is not related at all to the potential damage the problem can cause. Worst-case scenario? The software is shutdown and/or withdrawn from the market because the vendor can't fix it. Not tha…

I don't want anyone to be able to shutdown and/or withdraw software that I'm using for any reason. That cure is worse than the disease.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#23
post #19
post #12

Earlier quoted context omitted.

I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…

Pure nonsense. Or did you try a distribution from 2002?

Ubuntu 17.04. Is that recent enough for you?

I've tried antergos, red hat and a couple of others, all with similar issues. Many I didn't get far with because I simply couldn't read the login screen. Antergos doesn't even have user switching working out of the box but it was the only one that supported my graphics card until very recently. I used the gnome variant of each.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#24

Vendors, even ones as large as Microsoft, do not have infinite resources available to evaluate vulnerabilities. There are only so many of the issues you can work on at once. They have to evaluate each issue and prioritize the fix. In this case, they merely did not recognize the potential scope of the problem at hand.

That's true, but it doesn't matter. It's still broken. That's why we have automatic release after a set time. Because it's a problem for the public even if the vendor has zero resources. The ability of the vendor to fix the problem is not related at all to the potential damage the problem can cause. Worst-case scenario? The software is shutdown and/or withdrawn from the market because the vendor can't fix it. Not tha…

There's also an aspect of "capitalist tough-love".

Sometimes companies do have resources for fixes and for general security-quality, but they don't budget or prioritize because there's no strong economic incentive.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#25

And _this_, ladies and gentlemen, is why we have disclosure deadlines for security vulnerabilities. For example, Project Zero expects vendors to fix security vulnerabilities within 90 days of notification. Looking at this story, it's possible that 90 days is almost too long and should be shortened. As time goes on, it's becoming more and more common for multiple parties to become aware of the same vulnerabilities. No…

Next up on HN: extreme outrage after a botched security update breaks hundreds of millions of machines. Not all bugs can be fixed with a simple one-line fix, and the faster patches need to be cranked out, the lower quality they'll be.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#26
post #22

Earlier quoted context omitted.

That's true, but it doesn't matter. It's still broken. That's why we have automatic release after a set time. Because it's a problem for the public even if the vendor has zero resources. The ability of the vendor to fix the problem is not related at all to the potential damage the problem can cause. Worst-case scenario? The software is shutdown and/or withdrawn from the market because the vendor can't fix it. Not tha…

I don't want anyone to be able to shutdown and/or withdraw software that I'm using for any reason. That cure is worse than the disease.

Personally I don't want you to have to. As far as I'm concerned, if you're notified in big, red letters (perhaps every time the software starts)? Works for me. As long as you know -- and are reminded. (That's because different people use the same software. If the notice only appeared once, a new person might start using the software/machine and not be aware of what's going on)

But if you had a piece of software with a terrible vulnerability that was currently being exploited to do some sort of terrible harm? Beats me. Does my right to use the internet without being DDOSed override your right to use unsafe software if you want?

Re: Hackers exploited Word flaw for months while Microsoft investigated

#27

Vendors, even ones as large as Microsoft, do not have infinite resources available to evaluate vulnerabilities. There are only so many of the issues you can work on at once. They have to evaluate each issue and prioritize the fix. In this case, they merely did not recognize the potential scope of the problem at hand.

That's true, but it doesn't matter. It's still broken. That's why we have automatic release after a set time. Because it's a problem for the public even if the vendor has zero resources. The ability of the vendor to fix the problem is not related at all to the potential damage the problem can cause. Worst-case scenario? The software is shutdown and/or withdrawn from the market because the vendor can't fix it. Not tha…

[deleted]

Re: Hackers exploited Word flaw for months while Microsoft investigated

#28
post #25

And _this_, ladies and gentlemen, is why we have disclosure deadlines for security vulnerabilities. For example, Project Zero expects vendors to fix security vulnerabilities within 90 days of notification. Looking at this story, it's possible that 90 days is almost too long and should be shortened. As time goes on, it's becoming more and more common for multiple parties to become aware of the same vulnerabilities. No…

Next up on HN: extreme outrage after a botched security update breaks hundreds of millions of machines. Not all bugs can be fixed with a simple one-line fix, and the faster patches need to be cranked out, the lower quality they'll be.

Well yeah, if a patch for a single application broke machines then the outrage would be deserved.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#29
post #12

Earlier quoted context omitted.

But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc Just for the record in case someone isn't aware: Modern Linuxes are often easier to install and install software onto (as long as that software isn't written specifically for Windows or Mac OS.)

I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…

>> But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc

> Just for the record in case someone isn't aware: Modern Linuxes are often easier to install and install software onto ...

I think my "often" accounts for this.

Also you are now discussing something else (hi res) vs general ease of use.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#30
post #12

Earlier quoted context omitted.

I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…

>> But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc > Just for the record in case someone isn't aware: Modern Linuxes are often easier to install and install software onto ... I think my "often" accounts for this. Also you are now discussing something else (hi res) vs general ease of use.

> Also you are now discussing something else (hi res) vs general ease of use.

I'm discussing the challenges I've run into getting to a working installation, which is a lot more time and effort than running the installer, yet still part of the installation process.

Post reply on HN