Live data from Hacker News

Hackers exploited Word flaw for months while Microsoft investigated

reuters.com

41–50 of 105 posts

Re: Hackers exploited Word flaw for months while Microsoft investigated

#42
post #40

Earlier quoted context omitted.

Not sure why you're down voted. I had the same thought as parent, but this seems like the answer. A standard splash screen on load that pops up for 10 seconds and says "this program has known active vulnerabilities that are unpatched". If people choose to ignore it, that's on them. Cheap and easy, no?

That still requires that a third party is allowed to flash things on my screen without my explicit consent.

Does it?

We already have a solution to this, which I hate: walled gardens. I'm exploring options that preserve the peace while not letting companies effectively own their users.

Maybe there is no answer that makes everybody happy. That's why it's worth asking questions.

Just so I understand this, you're saying that if you have a piece of hardware that's say, taking down the local ISP because you're running compromised software on it, you don't want to even be notified before your box is compromised or that there might be a problem.

Well, dang. Something's going to happen. That much is sure. What's the first notification you'd like that you're destroying the internet experience for others and perhaps ruining a local business? SWAT team at the door?

I hear your complaint. I'm just not able to figure out how it makes sense.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#43
post #34
post #12

Earlier quoted context omitted.

I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…

> Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). Really? You mention in another thread, you used Ubuntu. So you apparently didn't notice this [0] or this [1]? The issue with this and complexity, is that login screen resolution is often handled by GRUB, not Linux. Edit: In future you can drop into a commandline via Ctrl+Alt+F1 > Secondary drives require manual mounting (…

> Really? You mention in another thread, you used Ubuntu. So you apparently didn't notice this [0] or this [1]?

Neither of those solutions are user friendly are they?. You think an average person knows what grub is? I did come across the second one actually, but I have no idea if the solution is still relevant or not. I haven't seen anything to indicate what login manager I'm even running, where is this information displayed?

I'm talking about kdm/gdm or whatever is installed these days.

> If it's an internal drive, try gnome-volume-manager and it's a tickbox away. (Which is on quite a few distros by default).

It's there and configured to mount at startup. I keep most of my steam games on there. But if I log in and start up steam all the games are missing. If I navigate to the drive through the file manager and then start steam then it will find them properly. I have no idea what's going on but it doesn't appear to be mounting the drive at startup.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#44
post #34
post #12

Earlier quoted context omitted.

I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…

> Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). Really? You mention in another thread, you used Ubuntu. So you apparently didn't notice this [0] or this [1]? The issue with this and complexity, is that login screen resolution is often handled by GRUB, not Linux. Edit: In future you can drop into a commandline via Ctrl+Alt+F1 > Secondary drives require manual mounting (…

Ubuntu's support for less-common screen resolutions is atrocious. Aside from its poor support for hi-dpi, if you try to install it when using low-res display hardware (like VirtualBox's emulated GPU) some of the important installer UI extends off the screen and cannot be seen or clicked.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#45

I thought that it is the norm for M$ to hand out the zero-days to the 3-letter-agencies for "a while" and patches them ONLY when someone else gets hold and starts using the same vuln.. so it makes PERFECT sense that they would do something like that. Also who in their right mind allow Word/Excel/Powerpoint to access the internet? (oh yes it's called "365" and it makes software, that is completely unfit for the task,…

Not sure why you're being downvoted. This is literally the company that built in "_NSAKEY" into the kernel, which is still present (just called "_KEY2" now.

Putting some sort of security backdoor or snooping feature into your software (likely by government order) is pretty different from 'M$ gives 0days to spy agencies and delays fixing them'. _NSAKEY, whatever it is, doesn't resemble the situation the original article is describing.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#46
"A quick change in the settings on Word by customers would do the trick, but if Microsoft notified customers about the bug and the recommended changes, it would also be telling hackers about how to break in."

In their monthly update, couldn't Microsoft have released a patch to have this setting to the correct configuration? Of course this would only be the short term solution, rather than waiting for 9 months for the permanent solution.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#47
This is why what McAfee did is ok. It was already being exploited. This got it patched and let Corp IT roll out a settings change to fix it immediately. Google's 90 day policy from its team is also sane. Letting bad bugs live on in the dark after submitting to a vendor is clearly more dangerous for everyone.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#48
post #23
post #19

Earlier quoted context omitted.

Pure nonsense. Or did you try a distribution from 2002?

Ubuntu 17.04. Is that recent enough for you? I've tried antergos, red hat and a couple of others, all with similar issues. Many I didn't get far with because I simply couldn't read the login screen. Antergos doesn't even have user switching working out of the box but it was the only one that supported my graphics card until very recently. I used the gnome variant of each.

Ubuntu 16.04 or Fedora are likely to work better than 17.04. Regardless there is still hardware that does not have the best compatibility. Ubuntu does handle individual high DPI displays well though.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#49

We need civil penalties for failing to patch any serious vulnerability (that can be defined as RCE, priv. escalation, etc) within 30 days of disclosure. If you can't patch it, you must issue a patch that announces the vuln and disables the minimal set of functionality that enables it. Even if that's the whole program.

So, turn a nontrivial set of vulns into successful DoS attacks?

Yes. That, in turn, will give the economic incentive to not have the vulnerabilities in the first place.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#50
post #25

And _this_, ladies and gentlemen, is why we have disclosure deadlines for security vulnerabilities. For example, Project Zero expects vendors to fix security vulnerabilities within 90 days of notification. Looking at this story, it's possible that 90 days is almost too long and should be shortened. As time goes on, it's becoming more and more common for multiple parties to become aware of the same vulnerabilities. No…

Next up on HN: extreme outrage after a botched security update breaks hundreds of millions of machines. Not all bugs can be fixed with a simple one-line fix, and the faster patches need to be cranked out, the lower quality they'll be.

There was a simple settings change for a temp fix on this one too. When there is even a remote chance a bug is being exploited in the wild it needs to be disclosed. Corp IT can work around it almost always. Individuals can as well. This argument that "it's complex to patch" is a non-starter at best. We the users deserve the option to decide how to deal with it. Silent exploitation is how we all lose, even the vendor.
Post reply on HN