Live data from Hacker News

Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

thenextweb.com

31–40 of 137 posts

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#31
post #29
post #4

I usually get shouted down when I say this but Microsoft's focus on secure code over the last 10 years has paid off. Not only is the OS too hard a target hence the increase in Java, adobe product exploits, but their software running on their OS has fallen in line too. I know the saying many eyes make bugs shallow, but so does billions of dollars and years of concentrated effort. Kudos to Microsoft for getting their a…

> I know the saying many eyes make bugs shallow, but so does billions of dollars and years of concentrated effort. The saying holds. Billions of dollars buys many eyes.

That's not really how secure coding works at Microsoft though. There aren't more eyes on the code, just more developer training and more processes in place. (At least that was my experience working there from 2006 to 2009.)

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#32
post #5

This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.

What can we trace this security priority initiative of Microsoft back to?

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#33
If you're running Chrome please for the love of all that is holy enable Click-To-Play for all plugins. With it disabled it is like running without a pop-up blocker.

You can do so in Settings -> Advanced Settings -> Content Settings -> Plug-Ins -> Click To Play.

When you visit a site which has a plug-in you'll get a UI control similar to the pop-up blocker which allows you to add it to the exceptions list and or to allow it just this one time. You should add YouTube to the exceptions list.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#34
post #2

It's actually this bit from farther down that surprised me the most: > 56 percent of exploits blocked in Q3 use Java vulnerabilities. So much for the idea of a managed language runtime being inherently more secure...

The runtime isn't written in a managed language, and that's where most of the vulnerabilities happen, right? The holes aren't in application code, but in _running arbitrary code_, which the JVM fails to do safely. The surface area exposed is larger, because you're allowing the browser to download and run arbitrary programs, something you don't do with unmanaged languages very much. Edit: Also, just consider how much…

[deleted]

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#35
post #5

This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.

What can we trace this security priority initiative of Microsoft back to?

Jan 15, 2002 email from Bill Gates to all MSFT staff [1]. Includes some real gems, like;

>So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve.

1.http://www.wired.com/techbiz/media/news/2002/01/49826

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#36
Reading http://www.securelist.com/en/analysis/204792250/IT_Threat_Ev..., I find it surprising that the Netherlands manages to be the best malware exporter in the world (third in 'production', close behind Russia and the USA (both with a much larger population), but also in the top 10 for 'least consumption', a list that neither Russia nor the USA made).

Does anybody have any idea how that comes about? The only reason I can think of is that Amsterdam is a huge node in the Internet backbone (http://en.wikipedia.org/wiki/Amsterdam_Internet_Exchange). Malware authors might want to host their stuff close to such nodes, so that they can distribute their wares efficiently.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#37
Ah Shockwave, good to see you again my old friend.

I can't believe it's still around and kicking, given the last release of Director seems to be about two years ago.

I don't play any online games, but can somebody vouch for whether it is still used to develop browser games anymore?

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#38

Glancing at the list, I see there are only four companies in the world who cannot claim they don't have a single product on Kapersky's top 10 vulnerabilities list.

But the fact that the largest software company in the world is among them is what's notable.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#39

If you're running Chrome please for the love of all that is holy enable Click-To-Play for all plugins. With it disabled it is like running without a pop-up blocker. You can do so in Settings -> Advanced Settings -> Content Settings -> Plug-Ins -> Click To Play. When you visit a site which has a plug-in you'll get a UI control similar to the pop-up blocker which allows you to add it to the exceptions list and or to al…

Or better yet, switch YouTube to the HTML5 player:

http://www.youtube.com/html5

One less site that needs Flash.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#40
post #5

This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.

What can we trace this security priority initiative of Microsoft back to?

The "Summer of Worms", after Slammer, Blaster, and Welchia owned up some huge fraction of every Windows machine connected to the Internet, including large portions of the DoD. Microsoft's software security was repeatedly on the front page of CNN and the subject of Congressional hearings.
Post reply on HN