Live data from Hacker News

Hackers exploited Word flaw for months while Microsoft investigated

reuters.com

81–90 of 105 posts

Re: Hackers exploited Word flaw for months while Microsoft investigated

#81
post #69

Earlier quoted context omitted.

> I need a lot more than twenty minutes to learn about and ascertain the validity of some third party installation robot, which your choco-thing appears to be. > Pacman -Syu So it's basically "I know one system much better than the other". And your ignorance is somehow the fault of the OS now?

If you fail to understand the difference between an integrated package management system overseeing all or most software installation, and a third party bolt-on component like your chocolate robot, we may not really have the basis of a meaningful conversation here. Anyway, I am not putting anything or anyone at fault. As clearly stated, I was relaying some anecdotal evidence of probably very littly use to the world a…

I agree about the lack of a basis. Educate yourself.

https://msdn.microsoft.com/en-us/powershell/reference/5.0/pa...

https://msdn.microsoft.com/en-us/powershell/reference/5.0/pa...

Re: Hackers exploited Word flaw for months while Microsoft investigated

#82
post #25

And _this_, ladies and gentlemen, is why we have disclosure deadlines for security vulnerabilities. For example, Project Zero expects vendors to fix security vulnerabilities within 90 days of notification. Looking at this story, it's possible that 90 days is almost too long and should be shortened. As time goes on, it's becoming more and more common for multiple parties to become aware of the same vulnerabilities. No…

Next up on HN: extreme outrage after a botched security update breaks hundreds of millions of machines. Not all bugs can be fixed with a simple one-line fix, and the faster patches need to be cranked out, the lower quality they'll be.

In which case the users need to be informed of the security risks they are taking by using that software. Hiding risks is not the answer.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#83
post #10
post #2

https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…

I don't support anyone hiding source code from users (and have given conference talks about hard-to-detect ways of backdooring binaries), and so I don't mean this to be an excuse for the secrecy of the source code, but every single person I know who's worked in the security industry agrees that Microsoft made a major qualitative improvement in their security at every level, based on spending a lot of money and giving…

That's a really complete argument. But there's still the elephant in the room of the whole operation being closed source, and the inability to do quantitative analysis into the improving security of a closed source system.

People on the inside can say there have been qualitative improvements, but that's not measurable on the outside and so is no better than hearsay and conjecture. Meanwhile in the GNU/Linux world, you can browse the git repositories and see and audit every step in the development process if needed.

Is it possible that typical open source projects didn't NEED to improve their security over the same timeframe, given that the F/OSS world didn't fuck users over for two decades with unfixed 0days?

Meanwhile, the OP here is talking about Word which is likely a world away from the improving security team working on Windows. Hell, I'm surprised they've got more than a skeleton crew working on the desktop version of Word anymore. People in my community 60+ have been using Google Docs for the last five years already.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#84
post #4
post #2

https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…

Microsoft was really really bad at security. Then the internet became a popular thing. I think an fresh xp install would, on average survive 15 minutes before getting infected by blaster. Microsoft, to their credit, improved dramatically. I don't know if they're extraordinarily good compared to other software producers. Microsoft gets the mention because it was so very bad, back in the day. It's kind of like when a v…

Indeed. But becoming a marathon runner who finishes in 7 hours, after the finish line has closed, and doesn't get a medal because the cut off was 6:30 :)

No, it's a great achievement, but there's still room for improvement.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#85

This is why what McAfee did is ok. It was already being exploited. This got it patched and let Corp IT roll out a settings change to fix it immediately. Google's 90 day policy from its team is also sane. Letting bad bugs live on in the dark after submitting to a vendor is clearly more dangerous for everyone.

FWIW, I'll note that Google has a 7 day policy for issues that are believed to be under active exploitation.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#86
post #6

Earlier quoted context omitted.

The sentiment of "the better product will win" is understandable, but wrong as you present it. Microsoft managed to gain a monopoly (legally or illegally - doesn't matter) and has used it to illegally keep others out, and network effects now (and for the past 20 years) have been that "goodness" measure - technical mediocrity had been sufficient (although recently they have been doing a lot of excellent technical work…

Part of why they succeeded was by being first. Linux was certainly much worse than Windows in the early days when people still used DOS together with Windows. Being first means it was massively better for those people at that time. Plan9 lost out to Linux, perhaps partly by being too late. Do we blame Linux for being horrible?

As a user of both circa 1994 - no, Linux was definitely not worse. It was about a thousand times more stable, though it lacked e.g. A word processor.

When Microsoft produced win 2 and 3, they unfairly (and likely illegally) used their DOS and then Windows monopoly to stop competitors (DR DOS, BeOS, a few lesser known ones); they later used the Windows monopoly to embed IE and kill Netscape. It didn't matter that IE was, in fact, a better browser - everyone wanted Netscape, and it was only with the IE4 merge into the OS that Microsoft took the internet.

I was involved with one of the smaller and less famous Microsoft victims at the time, and I can assure you that regardless of technical merits, MS made very significant progress by playing dirty.

They paid billions in court for it, but economically it was worth it to them.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#87

Earlier quoted context omitted.

Not everything is a trivial webservice with zero users, that can be patched overnight with no impact.

I'm not sure how that's relevant.

That's relevant to the time it takes to fix a vulnerability and deploy the patch.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#88
post #52

Earlier quoted context omitted.

Or for software not to get written in the first place.

>Or for [buggy] software not to get written in the first place. FTFY We place too much trust and rely too much on computer systems these days to have the luxury to write software like we used to.

No don't twist my words. I meant I'm sure as hell not inventing something new if it sets me up for civil liabilities. It would kill innovation.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#89
post #14
post #4

Earlier quoted context omitted.

Microsoft was really really bad at security. Then the internet became a popular thing. I think an fresh xp install would, on average survive 15 minutes before getting infected by blaster. Microsoft, to their credit, improved dramatically. I don't know if they're extraordinarily good compared to other software producers. Microsoft gets the mention because it was so very bad, back in the day. It's kind of like when a v…

There were versions of windows, 2000 if not XP, that could and would get infected in-between the time the network stack initialized and the local software firewall initialized a second or two later. This was actually addressed and fixed, because it was not a unique experience. That's how pervasive and wild the exploit network traffic was before MS got their act together. Edit: My google-fu is failing me, and I can't…

I saw this first-hand when installing Windows 2000 using Parallels circa 2006. I mistakenly believed the configuration I had chosen had the VM behind the Mac's firewall, but it wasn't. The VM was infected before Windows 2000 could install the latest updates... just a matter of minutes.

This is not as extreme as you are describing, but it was also on the corporate network of a large company, not the open internet.

Re: Hackers exploited Word flaw for months while Microsoft investigated

#90

Earlier quoted context omitted.

Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…

> But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc... You can only say that in comparison to Windows if you haven't tried installing both any time in the past 15 years.

I have installed both multiple times recently...

Linus is NOT as easy to install software into, its a different process for different distros... if what you want isnt in the repo of your choice you have to add repos (because politics matter in software apparently)... lets not even talk GPU driver issues...

I work on linux and mac, and I play on windows. Im familiar with all 3 environments (including various distros for linux). I'm not ignorant of any of the processes. And while linus is easier for me for the most part (I find OSX to be the simplest "plug and play" OS out there, honestly) - for the average user, its just not...

Post reply on HN