Live data from Hacker News

Hackers exploited Word flaw for months while Microsoft investigated

reuters.com

71–80 of 105 posts

Re: Hackers exploited Word flaw for months while Microsoft investigated

#71
post #69

Earlier quoted context omitted.

I need a lot more than twenty minutes to learn about and ascertain the validity of some third party installation robot, which your choco-thing appears to be. I then need some minutes to get it started. And yes, installation proces itself took something on the scale of ten to twenty minutes. Pacman -Syu (or Pamac if you're in a clicky mood) took care of everything in less time than the BibTeX took to download download…

> I need a lot more than twenty minutes to learn about and ascertain the validity of some third party installation robot, which your choco-thing appears to be. > Pacman -Syu So it's basically "I know one system much better than the other". And your ignorance is somehow the fault of the OS now?

If you fail to understand the difference between an integrated package management system overseeing all or most software installation, and a third party bolt-on component like your chocolate robot, we may not really have the basis of a meaningful conversation here.

Anyway, I am not putting anything or anyone at fault. As clearly stated, I was relaying some anecdotal evidence of probably very littly use to the world at large.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#72
post #2

https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…

Only four minutes according to Kevin Mitnick.

https://en.wikipedia.org/wiki/Microsoft_Windows#Third-party_...

Re: Hackers exploited Word flaw for months while Microsoft investigated

#73
post #32
post #12

Earlier quoted context omitted.

I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…

I have all of these problems with Windows. So many apps fail with HiDPi that I just use an external monitor. Having to compress folders by selecting "send to" and digging around the tray for an eject button, is something I can't figure out how to solve so easily.

You don't actually have to eject USB drives. Be default, windows doesn't cache writes to removable media.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#74
post #6

Earlier quoted context omitted.

Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…

The sentiment of "the better product will win" is understandable, but wrong as you present it. Microsoft managed to gain a monopoly (legally or illegally - doesn't matter) and has used it to illegally keep others out, and network effects now (and for the past 20 years) have been that "goodness" measure - technical mediocrity had been sufficient (although recently they have been doing a lot of excellent technical work…

Part of why they succeeded was by being first. Linux was certainly much worse than Windows in the early days when people still used DOS together with Windows. Being first means it was massively better for those people at that time.

Plan9 lost out to Linux, perhaps partly by being too late. Do we blame Linux for being horrible?

Re: Hackers exploited Word flaw for months while Microsoft investigated

#75
What's more interesting than vulnerabilities being found is vulnerabilities being created. I used to think they were progressively eliminated so older software is safer. But is that true? Is MS accidentally creating new ones faster than they're patching old ones? Same goes for any software.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#76

What's more interesting than vulnerabilities being found is vulnerabilities being created. I used to think they were progressively eliminated so older software is safer. But is that true? Is MS accidentally creating new ones faster than they're patching old ones? Same goes for any software.

I'd imagine the rate is more or less constant, with the exception of very new software.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#77

What's more interesting than vulnerabilities being found is vulnerabilities being created. I used to think they were progressively eliminated so older software is safer. But is that true? Is MS accidentally creating new ones faster than they're patching old ones? Same goes for any software.

The answer is yes:

> Despite being Microsoft’s newest and ‘most secure’ operating system, Windows 10 was found to have the highest proportion of vulnerabilities of any OS (395), 46% more than Windows 8 and Windows 8.1 (265 each).

https://www.avecto.com/news-and-events/news/94-of-critical-m...

And if you've used Windows 10, you'd already know that. Windows 10 has added a ton of new features/crap. The Q&A has suffered, too, and Windows 10 has been quite buggy so far, ruining some people's computers, etc.

And since we were talking about Word, here's another tidbit from the same source:

> Microsoft Office products were the subject of 79 vulnerabilities, up from 62 last year. This represents a 295% increase in Office vulnerabilities since 2014.

The amount of bugs likely increases in general, too, because more code = more complexity = more bugs and bigger attack surface, especially if we're talking about "improving" or adding on top of an old codebase, as is the case with Windows and Office, as opposed to writing something from scratch (which may benefit from safer languages sometimes, newer safer architectures, etc).

Re: Hackers exploited Word flaw for months while Microsoft investigated

#78

Earlier quoted context omitted.

Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…

> But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc... You can only say that in comparison to Windows if you haven't tried installing both any time in the past 15 years.

[deleted]

Re: Hackers exploited Word flaw for months while Microsoft investigated

#79

Earlier quoted context omitted.

Nah, that's more false than it is true. I've seen Microsoft sit on cases simply because they can. I'm sure that they were not resource-bound in this case, they simply didn't make it a top priority. Their self-imposed timeline is 180 days by default. Unless it comes from Google of course, because they know Google take the 90 day deadline seriously (or 7 days for active attacks such as this). That alone speaks volumes,…

Not everything is a trivial webservice with zero users, that can be patched overnight with no impact.

I'm not sure how that's relevant.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#80

This is why what McAfee did is ok. It was already being exploited. This got it patched and let Corp IT roll out a settings change to fix it immediately. Google's 90 day policy from its team is also sane. Letting bad bugs live on in the dark after submitting to a vendor is clearly more dangerous for everyone.

Not really, according to the article the sequence of events went * Microsoft warned in March of active attacks * Microsoft schedules patch for April 11th * McAfee sees attacks on April 6th * McAfee publicly explains how to use the exploit on April 7th * April 9th attack-kits are publicly for sale * April 11th Microsoft releases public patch as scheduled McAfee fucked up here.

I don't see why. The whole thing seems wrong. Having privacy and keeping secrets seems to only encourage the bad security practices. If instead every vulnerability discovered was immediately shared, our society as a whole, and especially the IT sub culture, would work quite differently. We would value security far more. Right now, it is easier to justify having less focus on security because when someone does find an exploit they'll help you patch it up before it is out of control.

On a very fundamental level, someone engaging in the free exchange of information, and this information being useful to people wanting to know what is or is not secure, cannot be a fuck up.

Microsoft had a security flaw. That's a fuck up.

People used that flaw for immoral actions. That's a double fuck up.

McAfee shared information letting people know about active security threats. That isn't a fuck up.

Post reply on HN