Live data from Hacker News

Security Update for Microsoft Malware Protection Engine

technet.microsoft.com

11–20 of 85 posts

Re: Security Update for Microsoft Malware Protection Engine

#12
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

Tavis also got some blowback on Twitter simply for announcing that he'd found a vulnerability. It's baffling to me why people think it's a problem.

If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.

Re: Security Update for Microsoft Malware Protection Engine

#13

shame that the instructions for verifying the update don't apply to Windows 10

on my win10 machine, I had to open Windows Defender Security Center, click the cog in the lower left, and then click 'About' in the upper right.

Re: Security Update for Microsoft Malware Protection Engine

#14
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet:

https://twitter.com/taviso/status/860679110728622080

The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind the fact that there's no details in the tweet relating to the actual vulnerability or exploit.

To be clear: I don't know what relationship (if any) Graham Cluley has to the people being jerks to Tavis, and it's possible that this quote was taken out of context. However, given the backlash Tavis's tweet summoned from some Twitter users with inflexible opinions about disclosure ethics, and this alien remark in the article, I'd hedge on the two being related.

Re: Security Update for Microsoft Malware Protection Engine

#15

Details from Microsoft: https://technet.microsoft.com/en-us/library/security/4022344

Hrm. Microsoft article says:

> For more information on how to verify the version number for the Microsoft Malware Protection Engine that your software is currently using, see the section, "Verifying Update Installation", in Microsoft Knowledge Base Article 2510781.

But the link points to https://technet.microsoft.com/en-us/library/security/4022344 which doesn't include Windows 10.

Edit: guessed and found it: Start -> Windows Defender Security Centre -> (cog icon in bottom left) -> About -> Engine Version

Re: Security Update for Microsoft Malware Protection Engine

#16
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

This is going to sound glib but it just sounds like some people in security research are butthurt. And not for any valid reason.

Re: Security Update for Microsoft Malware Protection Engine

#17
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

Anyone confused about what parent's comment is quoting, this HN link was originally pointing to http://www.bbc.co.uk/news/technology-39856391

Re: Security Update for Microsoft Malware Protection Engine

#18

shame that the instructions for verifying the update don't apply to Windows 10

They do? Just check the version: Open Defender, go to Help => About, check "Engine Version". Should be 1.1.13704.0 or higher.

I also find the version under Settings -> Updates & Security -> Windows Defender.

Thant screen gives you the version numbers in the place you're most likely to want to update.

Re: Security Update for Microsoft Malware Protection Engine

#19
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…

Graham's a longtime critic of Tavis. Think he used to work for an AV provider. Here's the history anyway https://www.google.co.uk/search?q=Graham+Cluley&oq=Graham+Cl...

Re: Security Update for Microsoft Malware Protection Engine

#20
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

I tried the proof of concept zip (https://bugs.chromium.org/p/project-zero/issues/detail?id=12...) on my machine this morning. It crashed msmpeng. Had to manually update.

Perhaps they should wait for a few days to allow it to roll out organically before releasing the details?

Post reply on HN