Live data from Hacker News

The Microsoft Update mechanism has been used to spread malware

f-secure.com

11–20 of 64 posts

Re: The Microsoft Update mechanism has been used to spread malware

#11

Here we have an example of complexity arising from copy protection/licensing. It so happens that this complexity caused a security vulnerability which, when exploited on any one computer, affects close to a billion computers. Is anyone else infuriated that a vulnerability like this exists in what is analogous to copy protection code? In other words, if Microsoft had been spending more of their resources on making sof…

The same would happen on ubuntu if someone steals the repository keys. This has nothing to do with copy protection.

But my point is that more teams needed access to signing keys because some of those teams were dedicated only to licensing issues. If they didn't need signing keys, those keys wouldn't have been compromised.

I suppose I can break it down another way.

Complexity introduces vulnerabilities.

Some complexity is necessary for the software to accomplish what the customer wants.

Some complexity is arguably necessary to protect the interests of the vendor. This is arguable because it varies between open source and proprietary software.

To me, it is upsetting when the code to protect the vendor's interests is where a critical security vulnerability exists. I don't think this is a controversial statement.

Re: The Microsoft Update mechanism has been used to spread malware

#12
post #7

Oh look, another scaremongering and purposely misleading article from F-Secure. This is starting to become a regular thing isn't it; I guess the recession must have hit them particularly hard.

I'm curious, could you please quote some of the points you thought were purposefully misleading in the article?

And here come the shills, one or perhaps two at a time to defend the article from any critique. I'm afraid I've grown bored of this dance, entertaining as it may have been I've become listless.

Re: The Microsoft Update mechanism has been used to spread malware

#13
post #12

Earlier quoted context omitted.

I'm curious, could you please quote some of the points you thought were purposefully misleading in the article?

And here come the shills, one or perhaps two at a time to defend the article from any critique. I'm afraid I've grown bored of this dance, entertaining as it may have been I've become listless.

I guess I'll just remain scared and mislead then.

Re: The Microsoft Update mechanism has been used to spread malware

#15

Here we have an example of complexity arising from copy protection/licensing. It so happens that this complexity caused a security vulnerability which, when exploited on any one computer, affects close to a billion computers. Is anyone else infuriated that a vulnerability like this exists in what is analogous to copy protection code? In other words, if Microsoft had been spending more of their resources on making sof…

The same would happen on ubuntu if someone steals the repository keys. This has nothing to do with copy protection.

Let's not forget that kernel.org itself was hacked. Nor that Firefox et al update themselves. People who live in glass houses...

Re: The Microsoft Update mechanism has been used to spread malware

#16
post #12

Earlier quoted context omitted.

I'm curious, could you please quote some of the points you thought were purposefully misleading in the article?

And here come the shills, one or perhaps two at a time to defend the article from any critique. I'm afraid I've grown bored of this dance, entertaining as it may have been I've become listless.

I have no connection to the antivirus industry. It was meant to be a legitimate question. Please reconsider answering it.

Re: The Microsoft Update mechanism has been used to spread malware

#17
post #12

Earlier quoted context omitted.

I'm curious, could you please quote some of the points you thought were purposefully misleading in the article?

And here come the shills, one or perhaps two at a time to defend the article from any critique. I'm afraid I've grown bored of this dance, entertaining as it may have been I've become listless.

yeah, shills. sure. no way you're getting downvoted for spreading FUD and then exolicitly refusing to back it up. Nope. Must be shills.

Re: The Microsoft Update mechanism has been used to spread malware

#18
post #4

This is like finding out the zombies have made it into the compound. I wonder how big this hole is to fix. I also wonder, as many have, if this was written by an Intelligence agency and, if so, if they had access to Windows' source code.

My Windows already fixed it. http://support.microsoft.com/kb/2718704

Re: The Microsoft Update mechanism has been used to spread malware

#19

Here we have an example of complexity arising from copy protection/licensing. It so happens that this complexity caused a security vulnerability which, when exploited on any one computer, affects close to a billion computers. Is anyone else infuriated that a vulnerability like this exists in what is analogous to copy protection code? In other words, if Microsoft had been spending more of their resources on making sof…

Microsoft has over 90,000 employees, and no doubt some of those people were hired specifically to protect their software licensing. They're probably not pulling their top OS developers to work on this. So the idea that they should have been "spending more of their resources on making software work..." is not really valid.

In fact, there is no company or software community anywhere that writes highly complex and bug free software. It's not possible.

Re: The Microsoft Update mechanism has been used to spread malware

#20

Here we have an example of complexity arising from copy protection/licensing. It so happens that this complexity caused a security vulnerability which, when exploited on any one computer, affects close to a billion computers. Is anyone else infuriated that a vulnerability like this exists in what is analogous to copy protection code? In other words, if Microsoft had been spending more of their resources on making sof…

The same would happen on ubuntu if someone steals the repository keys. This has nothing to do with copy protection.

Yes.

But you can always get the source and build the package yourself. Can you do that with Windows?

Post reply on HN