Live data from Hacker News

Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

thenextweb.com

11–20 of 137 posts

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#11
Haha. Great to see iTunes and QuickTime (Windows versions, probably?) on the list... Apple should really either update them (I'm not sure iTunes 11 will be released for windows too), or just abandon them (and ask customers to use iCloud for backup). A few days ago I opened a .mov on a Windows machine with QuickTime - it was horrible. I can't imagine how dreadful iTunes probably is. No wonder all PC guys hate iTunes...

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#12
Interesting to note that both Apple vulnerabilities listed exist only for their Windows software. (QuickTime: http://lists.apple.com/archives/security-announce/2012/May/m... iTunes: http://support.apple.com/kb/HT5485)

I wonder if these are lower priority for Apple or if they perhaps just aren't as good when developing for Windows.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#14

Sorry for going off topic but, I hadn't seen the nextweb new design before. I found it quite disorientating, there is so much orange "stuff". I just didn't know where to look.

I agree, it feels like a complete downgrade to me. It feels like they're trying to be Gawker.

I felt the same. I was thrown off with the side bar on the left rather than right though.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#16

Interesting to note that both Apple vulnerabilities listed exist only for their Windows software. (QuickTime: http://lists.apple.com/archives/security-announce/2012/May/m... iTunes: http://support.apple.com/kb/HT5485 ) I wonder if these are lower priority for Apple or if they perhaps just aren't as good when developing for Windows.

I think it could be that the platform works differently enough that you can build vulnerable Windows software by just making some assumptions that would be correct in OSX land but not in Windows. Vice versa, most probably.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#17
post #9
post #2

It's actually this bit from farther down that surprised me the most: > 56 percent of exploits blocked in Q3 use Java vulnerabilities. So much for the idea of a managed language runtime being inherently more secure...

Well CLR seems to be OK so I think this is down to the implementation rather than the concept.

Fewer browsers will run CLR code, so harder to do a drive-by.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#20
post #5

This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.

I still remember how painful it was to ship anything, waiting in queue for security team signoff. Good to see it payoff though. Good on Microsoft - making secure products and smarter engineers in the process.
Post reply on HN