Live data from Hacker News

Security Update for Microsoft Malware Protection Engine

technet.microsoft.com

31–40 of 85 posts

Re: Security Update for Microsoft Malware Protection Engine

#31

shame that the instructions for verifying the update don't apply to Windows 10

They do? Just check the version: Open Defender, go to Help => About, check "Engine Version". Should be 1.1.13704.0 or higher.

If you assume the instructions for Windows 8 apply to windows 10, then that is what you find. Also, the security advisory itself links to this page with the statement "For more information on how to verify the engine version number that your software is currently using, see the section, "Verifying Update Installation", in Microsoft Knowledge Base Article 2510781.", but the actual section title is "Verification of the update installation", so when I searched for the stated section name, I did not find it. These are small mistakes, but it is sloppy work. A person might be left wondering if there is some Windows-10 -specific information somewhere in the rabbit-warren of links leading from the security advisory.

Re: Security Update for Microsoft Malware Protection Engine

#32
post #15

Details from Microsoft: https://technet.microsoft.com/en-us/library/security/4022344

Hrm. Microsoft article says: > For more information on how to verify the version number for the Microsoft Malware Protection Engine that your software is currently using, see the section, "Verifying Update Installation", in Microsoft Knowledge Base Article 2510781. But the link points to https://technet.microsoft.com/en-us/library/security/4022344 which doesn't include Windows 10. Edit: guessed and found it: Start ->…

And for Microsoft Security Essentials, Click the down arrow next to the Help link, and select about.

Re: Security Update for Microsoft Malware Protection Engine

#33

Earlier quoted context omitted.

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…

It's not worth millions if it's already been reported to Microsoft.

Re: Security Update for Microsoft Malware Protection Engine

#34
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…

I suppose the issue that I have with that Tweet is - exactly what is its purpose - I don't think it poses a risk, but the tone - excited?, self-important? doesn't sit well with the idea of a professional security bod soberly reporting a serious problem.

I just think the tone rubbed people up the wrong way.

Re: Security Update for Microsoft Malware Protection Engine

#35
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…

i think tavis's tweet is completely fine. even if someone managed to work out the general location of the code from the tweet [tavis has been looking at AV and Natalie does research on scripting VMs -- a big stretch] then its still an enormous effort to find the problem code and further effort to create an exploit. i doubt it would be possible to do by the time microsoft patched it.

but as a researcher you to have to be careful with details sometimes. i've been able to reverse engineer java exploits from security explorations full disclosure posts in the past but these contained significantly more details than tavis's tweet.

Re: Security Update for Microsoft Malware Protection Engine

#36
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

Tavis also got some blowback on Twitter simply for announcing that he'd found a vulnerability. It's baffling to me why people think it's a problem. If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.

It's not that the bad guys will find it now by looking for it in Windows. It's more like they could grab a gun (thugs) or creatively worded court order (government) and pay him a visit...

A remote zero day in Windows is worth millions on the black market, and in skilled hands the amount of damage or money you can make is nearly limitless.

Re: Security Update for Microsoft Malware Protection Engine

#37

Earlier quoted context omitted.

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…

That's nonsense, and nobody would pay millions for this bug. What he did was really of no consequence at all.

Re: Security Update for Microsoft Malware Protection Engine

#38

Earlier quoted context omitted.

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…

I'd maybe disagree that there is "no security gain from tweeting about this". I think there is a security gain from warning people that an urgent security patch is on the way so they should prepare themselves/their organisation to deploy the patch as soon as it lands.

Now you could argue that a personal twitter account is not the best medium for this warning (maybe it should come directly from Google Project Zero or Microsoft), but Tavis does have a large sphere of influence, and I invariably hear about these things through him than via other sources so it is an effective medium.

Edit: Note, the argument here is whether his initial tweet (https://twitter.com/taviso/status/860679110728622080) constitutes disclosure - I don't think it does. The actual disclosure was handled according to Google Project Zero's policies.

Re: Security Update for Microsoft Malware Protection Engine

#39

Earlier quoted context omitted.

This is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion? I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions. In the tech world, this seems unique to security. For example, none of…

I'm surprised you feel that way. Who here hasn't commented on an aspect of UI design, or UX, or Apple's roadmap or whether product X should be open source or comply with standard Z or whatever?

In case anyone here hasn't heard it, this supposed trait of engineers of overconfidence on other topics is sometimes referred to as Engineer "Woo"

http://rationalwiki.org/wiki/Engineers_and_woo

Re: Security Update for Microsoft Malware Protection Engine

#40

Earlier quoted context omitted.

Tavis also got some blowback on Twitter simply for announcing that he'd found a vulnerability. It's baffling to me why people think it's a problem. If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.

It's not that the bad guys will find it now by looking for it in Windows. It's more like they could grab a gun (thugs) or creatively worded court order (government) and pay him a visit... A remote zero day in Windows is worth millions on the black market, and in skilled hands the amount of damage or money you can make is nearly limitless.

Please do not spread baseless FUD. None of this is true.
Post reply on HN