Live data from Hacker News

Security Update for Microsoft Malware Protection Engine

technet.microsoft.com

51–60 of 85 posts

Re: Security Update for Microsoft Malware Protection Engine

#51
post #33

Earlier quoted context omitted.

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…

It's not worth millions if it's already been reported to Microsoft.

Tell that to the millions of people who won't have the patch before next week.

Re: Security Update for Microsoft Malware Protection Engine

#52

shame that the instructions for verifying the update don't apply to Windows 10

My Windows 10 system showed 1.1.13701.0 but Windows Update indicated everything was up to date. I clicked on the usual Windows Update button Check for Updates anyway and now Defender shows 1.1.13704.0

It'll update on definition update, too, it seems (without going through Windows Update).

Re: Security Update for Microsoft Malware Protection Engine

#53
post #33

Earlier quoted context omitted.

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…

It's not worth millions if it's already been reported to Microsoft.

[deleted]

Re: Security Update for Microsoft Malware Protection Engine

#54
Any suggestions for a good quality virus scanner in which I can have some confidence in regarding a reasonable choice in how it operates.

If I'm understanding correctly Defender runs with high privilege and has a very large security footprint; as such I don't think it's something I want to run.

Re: Security Update for Microsoft Malware Protection Engine

#55

Earlier quoted context omitted.

A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…

I suppose the issue that I have with that Tweet is - exactly what is its purpose - I don't think it poses a risk, but the tone - excited?, self-important? doesn't sit well with the idea of a professional security bod soberly reporting a serious problem. I just think the tone rubbed people up the wrong way.

If people don't know that a vulnerability exists (For example: the Intel Active Management Technology) it can be very easy for the company to just ignore it. (Especially if it is one that reflects badly on the company) However, if people know that a vulnerability exists, it puts the ball in the companies court to do something about it.

However, that is just my personal opinion about the reason for Travis' tweets (which happen every time a large vulnerability is discovered), and I have no security background. I trust that people like Travis, who have done a lot of work to improve security, to know how to minimize the damage from the vulnerabilities.

Re: Security Update for Microsoft Malware Protection Engine

#56
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

The disclosure is irresponsible.

The post published today contains information on how to exploit the bug with a working code for POC, confirmed to work.

The windows patch is published today. It's gonna take weeks to propagate to the windows computers around the world.

Re: Security Update for Microsoft Malware Protection Engine

#57

Earlier quoted context omitted.

Tavis also got some blowback on Twitter simply for announcing that he'd found a vulnerability. It's baffling to me why people think it's a problem. If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.

It's not that the bad guys will find it now by looking for it in Windows. It's more like they could grab a gun (thugs) or creatively worded court order (government) and pay him a visit... A remote zero day in Windows is worth millions on the black market, and in skilled hands the amount of damage or money you can make is nearly limitless.

Oh come on. They're going to tie him up and torture him before he gets a chance to press "Send" on his report email, then?

Re: Security Update for Microsoft Malware Protection Engine

#58
post #50

Earlier quoted context omitted.

There are many sides to this and you're generalizing it to people not understanding the full value of security disclosure is misleading. I can assure you a lot of those people fully understand the value of security disclosures and they are for it. What many people have the problem with, is with Tavis' tone and his approach to announcing his findings. No reasonable security researchers find a bug, announce it first to…

As a supporter of Full Disclosure I believe it is irresponsible to follow the so called "Responsible" disclosure model. I dont believe it is "responsible" to leave people exposed for 90+ days while the vendor attempts to whitewash and cover up their vulnerabilities as it so often the case. While some software vendors might respond the vulnerabilities properly, most do not often wanting to blame shit, or even file leg…

The term "responsible disclosure" is actually a bad term to use, even if you support it: https://adamcaudill.com/2015/11/19/responsible-disclosure-is...

TL;DR "coordinated disclosure" is preferred.

Re: Security Update for Microsoft Malware Protection Engine

#59
post #54

Any suggestions for a good quality virus scanner in which I can have some confidence in regarding a reasonable choice in how it operates. If I'm understanding correctly Defender runs with high privilege and has a very large security footprint; as such I don't think it's something I want to run.

I'd recommend Avira.

Re: Security Update for Microsoft Malware Protection Engine

#60
post #33

Earlier quoted context omitted.

It's not worth millions if it's already been reported to Microsoft.

Tell that to the millions of people who won't have the patch before next week.

Why would they not have it until next week. Per the advisory, the engine update is part of the normal windows defender updates, which happen up to 3 times daily.

I just checked this morning, and I have the updated version already, and took no action.

Those millions would have had to have disabled windows defender updates in order to not get this update before next week.

Post reply on HN