shame that the instructions for verifying the update don't apply to Windows 10
They do? Just check the version: Open Defender, go to Help => About, check "Engine Version". Should be 1.1.13704.0 or higher.
Security Update for Microsoft Malware Protection Engine
31–40 of 85 posts
Re: Security Update for Microsoft Malware Protection Engine
#32Details from Microsoft: https://technet.microsoft.com/en-us/library/security/4022344
Hrm. Microsoft article says: > For more information on how to verify the version number for the Microsoft Malware Protection Engine that your software is currently using, see the section, "Verifying Update Installation", in Microsoft Knowledge Base Article 2510781. But the link points to https://technet.microsoft.com/en-us/library/security/4022344 which doesn't include Windows 10. Edit: guessed and found it: Start ->…
Re: Security Update for Microsoft Malware Protection Engine
#33Earlier quoted context omitted.
Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…
He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…
Re: Security Update for Microsoft Malware Protection Engine
#34> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…
A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…
I just think the tone rubbed people up the wrong way.
Re: Security Update for Microsoft Malware Protection Engine
#35> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…
A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…
but as a researcher you to have to be careful with details sometimes. i've been able to reverse engineer java exploits from security explorations full disclosure posts in the past but these contained significantly more details than tavis's tweet.
Re: Security Update for Microsoft Malware Protection Engine
#36> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…
Tavis also got some blowback on Twitter simply for announcing that he'd found a vulnerability. It's baffling to me why people think it's a problem. If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.
A remote zero day in Windows is worth millions on the black market, and in skilled hands the amount of damage or money you can make is nearly limitless.
Re: Security Update for Microsoft Malware Protection Engine
#37Earlier quoted context omitted.
Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…
He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…
Re: Security Update for Microsoft Malware Protection Engine
#38Earlier quoted context omitted.
Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…
He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…
Now you could argue that a personal twitter account is not the best medium for this warning (maybe it should come directly from Google Project Zero or Microsoft), but Tavis does have a large sphere of influence, and I invariably hear about these things through him than via other sources so it is an effective medium.
Edit: Note, the argument here is whether his initial tweet (https://twitter.com/taviso/status/860679110728622080) constitutes disclosure - I don't think it does. The actual disclosure was handled according to Google Project Zero's policies.
Re: Security Update for Microsoft Malware Protection Engine
#39Earlier quoted context omitted.
This is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion? I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions. In the tech world, this seems unique to security. For example, none of…
I'm surprised you feel that way. Who here hasn't commented on an aspect of UI design, or UX, or Apple's roadmap or whether product X should be open source or comply with standard Z or whatever?
Re: Security Update for Microsoft Malware Protection Engine
#40Earlier quoted context omitted.
Tavis also got some blowback on Twitter simply for announcing that he'd found a vulnerability. It's baffling to me why people think it's a problem. If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.
It's not that the bad guys will find it now by looking for it in Windows. It's more like they could grab a gun (thugs) or creatively worded court order (government) and pay him a visit... A remote zero day in Windows is worth millions on the black market, and in skilled hands the amount of damage or money you can make is nearly limitless.