I usually get shouted down when I say this but Microsoft's focus on secure code over the last 10 years has paid off. Not only is the OS too hard a target hence the increase in Java, adobe product exploits, but their software running on their OS has fallen in line too. I know the saying many eyes make bugs shallow, but so does billions of dollars and years of concentrated effort. Kudos to Microsoft for getting their a…
> I know the saying many eyes make bugs shallow, but so does billions of dollars and years of concentrated effort. The saying holds. Billions of dollars buys many eyes.
Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
31–40 of 137 posts
Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
#32This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.
Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
#33You can do so in Settings -> Advanced Settings -> Content Settings -> Plug-Ins -> Click To Play.
When you visit a site which has a plug-in you'll get a UI control similar to the pop-up blocker which allows you to add it to the exceptions list and or to allow it just this one time. You should add YouTube to the exceptions list.
Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
#34It's actually this bit from farther down that surprised me the most: > 56 percent of exploits blocked in Q3 use Java vulnerabilities. So much for the idea of a managed language runtime being inherently more secure...
The runtime isn't written in a managed language, and that's where most of the vulnerabilities happen, right? The holes aren't in application code, but in _running arbitrary code_, which the JVM fails to do safely. The surface area exposed is larger, because you're allowing the browser to download and run arbitrary programs, something you don't do with unmanaged languages very much. Edit: Also, just consider how much…
Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
#35This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.
What can we trace this security priority initiative of Microsoft back to?
>So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve.
Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
#36Does anybody have any idea how that comes about? The only reason I can think of is that Amsterdam is a huge node in the Internet backbone (http://en.wikipedia.org/wiki/Amsterdam_Internet_Exchange). Malware authors might want to host their stuff close to such nodes, so that they can distribute their wares efficiently.
Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
#37I can't believe it's still around and kicking, given the last release of Director seems to be about two years ago.
I don't play any online games, but can somebody vouch for whether it is still used to develop browser games anymore?
Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
#38Glancing at the list, I see there are only four companies in the world who cannot claim they don't have a single product on Kapersky's top 10 vulnerabilities list.
Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
#39If you're running Chrome please for the love of all that is holy enable Click-To-Play for all plugins. With it disabled it is like running without a pop-up blocker. You can do so in Settings -> Advanced Settings -> Content Settings -> Plug-Ins -> Click To Play. When you visit a site which has a plug-in you'll get a UI control similar to the pop-up blocker which allows you to add it to the exceptions list and or to al…
One less site that needs Flash.
Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list
#40This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.
What can we trace this security priority initiative of Microsoft back to?