Live data from Hacker News

Security Update for Microsoft Malware Protection Engine

technet.microsoft.com

41–50 of 85 posts

Re: Security Update for Microsoft Malware Protection Engine

#41

Earlier quoted context omitted.

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…

It's more of "I knew how to get into any Windows PC by sending someone to a website, but it's already been patched"

Much less desirable.

Re: Security Update for Microsoft Malware Protection Engine

#42
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

I'm still wondering if the best possible plan (when done over a long time) is immediate and full release of all known information to the public.

The immediate effect is worse. You will have people making use of the vulnerability as soon as the information is out the door. But what about the secondary (and tertiary, etc.) impacts? Will companies be more likely to spend more on security because they will have lost the chance of having 90 days to fix an issue before it goes public? Will consumers who see the damage done in the immediate end up searching for more secure options?

It seems weird (and very very beneficial to the corporations making these security vulnerabilities) that we blame the researcher for releasing the details more than the entity who made the insecure software, sometimes even more than we blame the ones exploiting the vulnerability.

Think of it this way, we already have a given window before we go public. 90 days, which you mention in your post. Why do we have 90 days? Why not 180? If you get to the 90th day with no fix in sight, going public exposes all users to the same damage. If it were 180 days, or something much longer like 10 years, is there a chance that entities behind the software in question will just ignore the bug because patching bugs doesn't generate income like new features? Does the reasoning we have for having a 90 day clock instead of a longer maybe justify a shorter than 90 day clock?

Re: Security Update for Microsoft Malware Protection Engine

#43
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

Tavis also got some blowback on Twitter simply for announcing that he'd found a vulnerability. It's baffling to me why people think it's a problem. If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.

Are we taking twitter as a legitimate medium? 90% of what I see there are contrarians riding the coattails of others. Of course Tavis has all these crazy replies. Its a bit like how the paparazzi get celebs to notice them. They 'neg' the famous person to get the desired response and attention they want.

People not playing these games don't see his tweet as being controversial. It almost had no details, what exactly is there to argue here? Your average copy of Windows probably has tens of thousads of unfound zero days. Its rational that they will be continued to be found.

I think the narrative of "but people on twitter are talking" is fairly bullshitty. Twitter is not reputable, anyone can reply to anyone, and unless you start naming the names of respected security researchers then these replies are from just kids and a trolls looking for attention.

Re: Security Update for Microsoft Malware Protection Engine

#44
post #41

Earlier quoted context omitted.

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…

It's more of "I knew how to get into any Windows PC by sending someone to a website, but it's already been patched" Much less desirable.

4 days ago when he posted about its existence on twitter, it hadn't been patched.

Re: Security Update for Microsoft Malware Protection Engine

#45

Earlier quoted context omitted.

Tavis also got some blowback on Twitter simply for announcing that he'd found a vulnerability. It's baffling to me why people think it's a problem. If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.

It's not that the bad guys will find it now by looking for it in Windows. It's more like they could grab a gun (thugs) or creatively worded court order (government) and pay him a visit... A remote zero day in Windows is worth millions on the black market, and in skilled hands the amount of damage or money you can make is nearly limitless.

Literally nonsense. But, in fact, totally representative of the crazy lengths people go to to justify why Tavis's tweet that he found ~a vulnerability~ is somehow dangerous.

Re: Security Update for Microsoft Malware Protection Engine

#46
"An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take control of the system." Why would software that is written to scan potentially dangerous files be configured to run under the LocalSystem account? Shouldn't it run under a least privilege account?

Re: Security Update for Microsoft Malware Protection Engine

#47
post #44
post #41

Earlier quoted context omitted.

It's more of "I knew how to get into any Windows PC by sending someone to a website, but it's already been patched" Much less desirable.

4 days ago when he posted about its existence on twitter, it hadn't been patched.

But the vendor was aware of the issue, and was already getting their ducks in a row. So it was largely useless to any adversary.

Re: Security Update for Microsoft Malware Protection Engine

#48

Earlier quoted context omitted.

This is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion? I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions. In the tech world, this seems unique to security. For example, none of…

I'm surprised you feel that way. Who here hasn't commented on an aspect of UI design, or UX, or Apple's roadmap or whether product X should be open source or comply with standard Z or whatever?

True, but as engineers, most of us have been at least peripherally involved in an aspect of UI design, or UX, or a product's roadmap, or choosing whether something should be open source or comply with a standard. But it seems like comparatively few of us have been involved with security in any way except perhaps doing our best not to write insecure code.

Re: Security Update for Microsoft Malware Protection Engine

#49

shame that the instructions for verifying the update don't apply to Windows 10

My Windows 10 system showed 1.1.13701.0 but Windows Update indicated everything was up to date. I clicked on the usual Windows Update button Check for Updates anyway and now Defender shows 1.1.13704.0

Re: Security Update for Microsoft Malware Protection Engine

#50

Earlier quoted context omitted.

A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…

There are many sides to this and you're generalizing it to people not understanding the full value of security disclosure is misleading. I can assure you a lot of those people fully understand the value of security disclosures and they are for it. What many people have the problem with, is with Tavis' tone and his approach to announcing his findings. No reasonable security researchers find a bug, announce it first to…

As a supporter of Full Disclosure I believe it is irresponsible to follow the so called "Responsible" disclosure model.

I dont believe it is "responsible" to leave people exposed for 90+ days while the vendor attempts to whitewash and cover up their vulnerabilities as it so often the case.

While some software vendors might respond the vulnerabilities properly, most do not often wanting to blame shit, or even file legal action against anyone discovering vulnerabilities.

Post reply on HN