Earlier quoted context omitted.
From what I've heard, Falun Gong is about making money too. It's basically "hey we'll help you and be real nice to you and help you get back on your feet. Now it's your turn to pay up with donations". Which seems better than scientology, I'd say it's most comparable to mormonism
Sounds like everybody on this list: https://en.wikipedia.org/wiki/Chinese_lists_of_cults As far as I know, among them, Falun Gong and The Church of Almighty God was making false promise about their ability of "getting people back on their feet". I don't know why people here are suddenly on fire when saw me put Falun Gong and cult together. In China, we use word "神棍"[0] to describe someone who fake their supernatural…
Microsoft finds privilege escalation vulnerability in Huawei driver
91–100 of 138 posts
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#92Earlier quoted context omitted.
The problem is that most incentives can be gamed. There are good and bad ways to get customers to buy more or make the stock price go up. People are smarter than metrics. Increase the incentives and you also increase the incentive to cheat. Sometimes the best you can do is insulate people from incentives, so people have the leeway to do the right thing without acting against their own best interest.
Well, that's why there's generally a difference between market incentives and regulatory incentives. In this case, I believe we are referring to market based incentives, where gaming them is of limited use because the market should respond to that gaming. That said, regulatory incentives and punishments have their place too, IMO generally where the market isn't responding well, or information isn't available enough t…
I mean, consider Wall Street, Las Vegas, used car sales - the list goes on and on. It's a rich area of storytelling that goes back to the dawn of recorded history.
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#93Backdoor is such a loaded word to use for a vulnerability. Especially since Huawei is involved. Shame on the person who came up with the title and the reporter who uses the term in the article.
The Epoch Times is a Falun Gong propaganda arm, and Falun Gong is basically Chinese Scientology that the CCP has been trying to stamp out.
Then blame them for the world fearing Huawei security
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#94Weird approach by Huawei. If you want a program to stay up and running, you write a windows service; autostart with restart for recovery in case of crash. The service process can set its own DAC so that only SYSTEM can open its handle, hence the process in inaccessible/unkillable to ordinary users, even administrators. The knowledge needed to do so is far less than what is needed to pull the hack that Huawei did. So…
Considering the physical memory mapping stuff, I wouldn't be surprised if the service doesn't have some roles firmware should have had - for example ensuring the battery charger is stopped when the battery is fully charged to prevent a fire.
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#95Earlier quoted context omitted.
Well, that's why there's generally a difference between market incentives and regulatory incentives. In this case, I believe we are referring to market based incentives, where gaming them is of limited use because the market should respond to that gaming. That said, regulatory incentives and punishments have their place too, IMO generally where the market isn't responding well, or information isn't available enough t…
If gaming the markets is of limited use, I wonder why market participants put so much effort into it? I mean, consider Wall Street, Las Vegas, used car sales - the list goes on and on. It's a rich area of storytelling that goes back to the dawn of recorded history.
There is gaming of markets, but I think generally if it's not based on some regulation, it's because of information asymmetry (which is a market inefficiency).
All I was trying to point out in the prior comment is that there are different kinds of incentives. There are incentives that are constructed, and there are incentives that are natural. Constructed incentives are much easier to game. Natural incentives are emergent. Microsoft is incentivized to have good security for their OS now by the market in general, because it hurts them to not have good security (compared the the bast, where they could get away with lax security until it became a problem). That's emergent from the market and people deciding to use or not use their product. I wouldn't consider that "gaming the system", and if they did game it by talking a lot about security but not actually doing much, eventually the market should note that and respond appropriately.
Alternatively, Microsoft can reduce their tax burden by shifting business entities to different countries and shuffling how it appears their profit is created, so it's registered in a country with very little taxes, leading them to pay fewer taxes (not that they do, I don't know. I believe Apple and Google are reputed to do this). That's based on rules set by people, such as country boundaries and tax rates. Doing this could be considered "gaming the tax system". It requires specific changes to the rules to fix, it won't just shift naturally.
To me it appeared the comment you were responding to originally was using "incentive" in the pure form, meaning "benefit for doing so", and it appeared you were referring to incentive in the regulatory sense, where it's a human construction to influence behavior, but that's only a subset of the meaning.
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#96Weird approach by Huawei. If you want a program to stay up and running, you write a windows service; autostart with restart for recovery in case of crash. The service process can set its own DAC so that only SYSTEM can open its handle, hence the process in inaccessible/unkillable to ordinary users, even administrators. The knowledge needed to do so is far less than what is needed to pull the hack that Huawei did. So…
Perhaps they wanted the service killable, but for it to always restart? Considering the physical memory mapping stuff, I wouldn't be surprised if the service doesn't have some roles firmware should have had - for example ensuring the battery charger is stopped when the battery is fully charged to prevent a fire.
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#97Earlier quoted context omitted.
They’ve done it for previous versions as well. I think that practice goes back to Vista at the very least.
It started in Vista, AFAIK, but it didn't really become reliably useful for _most_ of the drivers on even relatively common hardware configurations until 7, and even now it's still not complete (I installed a Coffee Lake-era Intel desktop with Win10, and I still got to play Hunt the Unknown Device Driver even after the endless reboots for updating had installed every driver Windows Update offered, and that's for onbo…
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#98Earlier quoted context omitted.
What is not malicious about a driver whose pure function (this thing literally has no other value or purpose) is maintaining an invincible NT_AUTHORITY process of their pre-installed management software? And achieving that by allocating a RWX page in services.exe? What are we even doing W^X for? Maybe we have different expectations of what a driver is. Take a look for yourself, even the updated PC Manager Software on…
Writing "drivers" that do questionable things for even more questionable reasons seems to be par for the course in the Windows ecosystem. If I understand the whole situation correctly, Fortnite installs WHQL certified kernel driver, whose sole purpose is to cause BSOD when LSASS.EXE maps pages from the Fortnite process...
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#99Earlier quoted context omitted.
What is not malicious about a driver whose pure function (this thing literally has no other value or purpose) is maintaining an invincible NT_AUTHORITY process of their pre-installed management software? And achieving that by allocating a RWX page in services.exe? What are we even doing W^X for? Maybe we have different expectations of what a driver is. Take a look for yourself, even the updated PC Manager Software on…
Writing "drivers" that do questionable things for even more questionable reasons seems to be par for the course in the Windows ecosystem. If I understand the whole situation correctly, Fortnite installs WHQL certified kernel driver, whose sole purpose is to cause BSOD when LSASS.EXE maps pages from the Fortnite process...
Re: Microsoft finds privilege escalation vulnerability in Huawei driver
#100Earlier quoted context omitted.
Hanlon's razor - Never attribute to malice that which is adequately explained by stupidity.
Honest question: is it plausible that someone who is knowledgeable enough to understand and implement this exploit is also oblivious to ita exploitability?