Live data from Hacker News

Security Update for Microsoft Malware Protection Engine

technet.microsoft.com

61–70 of 85 posts

Re: Security Update for Microsoft Malware Protection Engine

#61

Earlier quoted context omitted.

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a web…

He basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench.

It's not a secret worth millions and nobody does any of that stuff for Windows RCE vulnerabilities.

Re: Security Update for Microsoft Malware Protection Engine

#62
post #33

Earlier quoted context omitted.

It's not worth millions if it's already been reported to Microsoft.

Tell that to the millions of people who won't have the patch before next week.

Not sure about millions but many do have update for Windows turned off, due to Microsoft's security-trust-destroying habit of deploying invasive and undesired non-security updates automatically.

Windows 10 especially has a nasty streak with updates, and while security updates are smart, forcing new content updates, advertisements, and spyware into the Tuesday fast track teaches users that the only way to be safe from Microsoft is to not take software from them automatically.

Re: Security Update for Microsoft Malware Protection Engine

#63
post #54

Any suggestions for a good quality virus scanner in which I can have some confidence in regarding a reasonable choice in how it operates. If I'm understanding correctly Defender runs with high privilege and has a very large security footprint; as such I don't think it's something I want to run.

Everything on the market has had something like this bug. I'd stick with Defender simply because Microsoft will put the resources into dragging their coding practices out of the 90s and they're better about general QA testing.

Re: Security Update for Microsoft Malware Protection Engine

#64

Earlier quoted context omitted.

I know comparatively little about this stuff, so please excuse the question if it's dumb... If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit? My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.

This is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion? I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions. In the tech world, this seems unique to security. For example, none of…

I don't think there's a difference in how willing people are to do it (e.g. I've definitely seen people who haven't touched Rust have strong opinions about it). However with security it's very easy to accidentally say something someone can show is clearly and unequivocally wrong, with decades of research in tow. A lot of other technical opinions on HN are ultimately up for debate.

You see the same thing with physics and mathematics here fairly often: every time quantum computing comes up some people ask some good questions, and then a bunch of people give them confident and embarrassingly wrong answers. Finally others (including me sometimes) shout them down. It's just less noticeable because those subjects are rare here compared to information security; tptacek and others are constantly fighting the good fight.

Re: Security Update for Microsoft Malware Protection Engine

#66
post #15

Details from Microsoft: https://technet.microsoft.com/en-us/library/security/4022344

Hrm. Microsoft article says: > For more information on how to verify the version number for the Microsoft Malware Protection Engine that your software is currently using, see the section, "Verifying Update Installation", in Microsoft Knowledge Base Article 2510781. But the link points to https://technet.microsoft.com/en-us/library/security/4022344 which doesn't include Windows 10. Edit: guessed and found it: Start ->…

From powershell (on Windows 10/Server 2016, possibly others):

(Get-MpComputerStatus).AmEngineVersion

Also, from powershell:

Update-MpSignature

to just go ahead and run the update process

Re: Security Update for Microsoft Malware Protection Engine

#67

Earlier quoted context omitted.

A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind th…

I suppose the issue that I have with that Tweet is - exactly what is its purpose - I don't think it poses a risk, but the tone - excited?, self-important? doesn't sit well with the idea of a professional security bod soberly reporting a serious problem. I just think the tone rubbed people up the wrong way.

> I don't think it poses a risk, but the tone - excited?, self-important? doesn't sit well with the idea of a professional security bod soberly reporting a serious problem.

What a surprise! Self-importance in an security industry that relies on reputation for consulting gigs?[1] You might have missed the ominous, grandiose vulnerability names, fancy logos and the PR-blitz now associated with any vulnerability worth a damn.

I'm an outsider, but even I know NetSec twittersphere is that last place to expect 'sober' communication.

1. I don't agree with your assessment that there was self-service in Tavis' tweet. To my knowledge Google Zero doesn't consult for anyone, he was probably excited and very surprised by what he saw and he needed to get it off his chest.

Re: Security Update for Microsoft Malware Protection Engine

#68
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

The disclosure is irresponsible. The post published today contains information on how to exploit the bug with a working code for POC, confirmed to work. The windows patch is published today. It's gonna take weeks to propagate to the windows computers around the world.

The windows patch contains mitigation techniques for the vulnerability, likely enough for an attacker to to reverse engineer. Its better to have the details out in the open so that users can take action to mitigate in the meantime.

Re: Security Update for Microsoft Malware Protection Engine

#69
post #65

Did they only fix the type confusion or did they do something about the unsandboxed JavaScript interpreter running as SYSTEM ?

They got this out incredibly quickly so it's likely that either they just fixed the type confusion or that they already had a sandboxing modification ready which they were saving for a major update but had to rush out. I don't know the age of the defender code, but my money is on the former.

Re: Security Update for Microsoft Malware Protection Engine

#70
post #27

Earlier quoted context omitted.

There are many sides to this and you're generalizing it to people not understanding the full value of security disclosure is misleading. I can assure you a lot of those people fully understand the value of security disclosures and they are for it. What many people have the problem with, is with Tavis' tone and his approach to announcing his findings. No reasonable security researchers find a bug, announce it first to…

What's wrong with an announcement like this? With literally no details, it's not helping bad guys (or, for that matter, good guys). I can see an argument that it's unprofessional to call out a company when you need them on your side. But is anyone making that argument? All the negative replies I saw to that tweet, for example, are along the lines of "omg you ruined my weekend why couldn't you wait until Monday?"

Not this tweet specifically, look at the tweets he did in the past where he did point out the names such as LastPass and 1Password. It caused some folks to contact these vendors for more information where they don't have any yet at the time of the tweets.

Like this one: https://mobile.twitter.com/taviso/status/760231214812844032

Or https://mobile.twitter.com/taviso/status/845717082717114368

Post reply on HN