Live data from Hacker News

Security Update for Microsoft Malware Protection Engine

technet.microsoft.com

21–30 of 85 posts

Re: Security Update for Microsoft Malware Protection Engine

#21
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

I know comparatively little about this stuff, so please excuse the question if it's dumb...

If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit?

My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.

Re: Security Update for Microsoft Malware Protection Engine

#22

Earlier quoted context omitted.

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

I know comparatively little about this stuff, so please excuse the question if it's dumb... If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit? My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.

Malicious actors are far more proactive already about watching for security patches and reverse engineering them to work out how to exploit unpatched systems. Once a patch is released the cat is out the bag, and the only solution is to patch as quickly as possible.

Re: Security Update for Microsoft Malware Protection Engine

#23

Earlier quoted context omitted.

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

I know comparatively little about this stuff, so please excuse the question if it's dumb... If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit? My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.

> surely it also allows malicious actors to prepare to exploit?

"There is an RCE in Windows" is not helping anyone.

Re: Security Update for Microsoft Malware Protection Engine

#24
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…

There are many sides to this and you're generalizing it to people not understanding the full value of security disclosure is misleading. I can assure you a lot of those people fully understand the value of security disclosures and they are for it.

What many people have the problem with, is with Tavis' tone and his approach to announcing his findings. No reasonable security researchers find a bug, announce it first to Twitter or other mass public postings and then inform affected vendor(s) with the disclosures. That's not it should be done and it is not a responsible discourse policy, this is what people have problems with Tavis.

Tavis is doing amazing work, work that we need but he has to be careful with how he announce his findings to the public.

Re: Security Update for Microsoft Malware Protection Engine

#25

Earlier quoted context omitted.

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

I know comparatively little about this stuff, so please excuse the question if it's dumb... If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit? My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.

This is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion?

I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions.

In the tech world, this seems unique to security. For example, none of us would feel like we should have a say in how Rust rolls forward unless we're experts in Rust, or at least involved in Rust in some way. Yet there are many who feel they should have a say in whether Project Zero ought to do X or Y even without any experience. I wonder why?

Re: Security Update for Microsoft Malware Protection Engine

#26
post #15

Details from Microsoft: https://technet.microsoft.com/en-us/library/security/4022344

Hrm. Microsoft article says: > For more information on how to verify the version number for the Microsoft Malware Protection Engine that your software is currently using, see the section, "Verifying Update Installation", in Microsoft Knowledge Base Article 2510781. But the link points to https://technet.microsoft.com/en-us/library/security/4022344 which doesn't include Windows 10. Edit: guessed and found it: Start ->…

And if your engine version is equal to or less than 1.1.13701.0, then you still have the vulnerability and need to update ASAP.

Re: Security Update for Microsoft Malware Protection Engine

#27

Earlier quoted context omitted.

A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…

There are many sides to this and you're generalizing it to people not understanding the full value of security disclosure is misleading. I can assure you a lot of those people fully understand the value of security disclosures and they are for it. What many people have the problem with, is with Tavis' tone and his approach to announcing his findings. No reasonable security researchers find a bug, announce it first to…

What's wrong with an announcement like this? With literally no details, it's not helping bad guys (or, for that matter, good guys).

I can see an argument that it's unprofessional to call out a company when you need them on your side. But is anyone making that argument? All the negative replies I saw to that tweet, for example, are along the lines of "omg you ruined my weekend why couldn't you wait until Monday?"

Re: Security Update for Microsoft Malware Protection Engine

#28

Earlier quoted context omitted.

I know comparatively little about this stuff, so please excuse the question if it's dumb... If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit? My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.

This is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion? I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions. In the tech world, this seems unique to security. For example, none of…

I'd guess that security feels pretty personal to a lot of people. They may not be experts in the area, but maybe they run servers,- deal with sensitive data or just don't want their personal machines compromised. A poor approach to vulnerability disclosure for a zero-day could cause them real issues, whereas perhaps a language design decision is less critical.

Re: Security Update for Microsoft Malware Protection Engine

#29

Earlier quoted context omitted.

I know comparatively little about this stuff, so please excuse the question if it's dumb... If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit? My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.

This is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion? I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions. In the tech world, this seems unique to security. For example, none of…

I'm surprised you feel that way. Who here hasn't commented on an aspect of UI design, or UX, or Apple's roadmap or whether product X should be open source or comply with standard Z or whatever?

Re: Security Update for Microsoft Malware Protection Engine

#30
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench.

Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a website" paints a huge target on you.

Although the danger is kind of abstract, there is no security gain from tweeting about this, so I'd say he shouldn't have done it.

Post reply on HN