Live data from Hacker News

Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

thenextweb.com

81–90 of 137 posts

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#82
post #17
post #9

Earlier quoted context omitted.

Well CLR seems to be OK so I think this is down to the implementation rather than the concept.

Fewer browsers will run CLR code, so harder to do a drive-by.

That's not true. All four major browsers can run CLR code through Silverlight [1] and depending on the statistics you use, the installation base for the plugin is in the same ballpark as Java, somewhere between 65% and 75% [2]. StatOwl even has Silverlight slightly ahead of Java at 69.7% vs 70.0% [3].

Of course, these are desktop stats. On mobile, it's a different story.

[1] http://www.microsoft.com/getsilverlight/Get-Started/Install/...

[2] http://en.wikipedia.org/wiki/Microsoft_Silverlight#Adoption

[3] http://riastats.com/

[4] http://www.statowl.com/custom_ria_market_penetration.php

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#83
post #64
post #25

Earlier quoted context omitted.

It seems to me that the only reason we put up with JVM applets (whereas anyone suggesting we put up with people ActiveX would rightfully be laughed down these days) is because of that steady monotonous stream of crap about how much better Java is for security. It has dropped our collective paranoia far too low.

Java is or was until very recently as anyone who has used it since 1995 will know and remember. Recent issue have arisen, hopefully Oracle is going to get its track record up to what Sun's was. Until then, a few bad recent reports for Java 7 will not wipe out decades of countless security reports for all of Windows Operating System and many relied upon Windows applications. Java applets are still far more efficient a…

History and hopefully don't really factor into a thoughtful analysis of current security issues.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#84
post #36

Reading http://www.securelist.com/en/analysis/204792250/IT_Threat_Ev... , I find it surprising that the Netherlands manages to be the best malware exporter in the world (third in 'production', close behind Russia and the USA (both with a much larger population), but also in the top 10 for 'least consumption', a list that neither Russia nor the USA made). Does anybody have any idea how that comes about? The only reaso…

The Netherlands has a long history of being a hub of international trade, from spices and bulbs to diamonds and IP packets. Add to that its tolerant attitude towards pornography, prostitution and drugs - compared even to much of Western Europe - and it wouldn't be much of a surprise to see organized crime diversifying beyond things like porn hosting (which benefits from the IXP you mention) into malware and identity theft too.

(I have no data to back this up...)

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#85

Let's take a look at CERT, shall we? 17 Sep 2012 VU#480095 Microsoft Internet Explorer 6/7/8/9 contain a use-after-free vulnerability 17 Sep 2012 VU#389795 Windows Phone 7 does not check certificate Common Names when sending or receive Hmm. OK, how about #1 service being remotely attacked right now: MS Terminal Services

The OP is a list of vulerabilities by severity. When I look at the current US-CERT database, I don't see any Microsoft products in the top 10 results by severity[1] or by date[2].

[1] By "Common Vulnerability Scoring System": http://www.kb.cert.org/vuls/byCVSS

[2] By Date: http://www.kb.cert.org/vuls/bypublished

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#86
post #2

It's actually this bit from farther down that surprised me the most: > 56 percent of exploits blocked in Q3 use Java vulnerabilities. So much for the idea of a managed language runtime being inherently more secure...

So the question remains - how best to run Java on a Windows machine and minimise your risk?

I've got Win7/64, service packs up to date, java autoinstaller thing....what else can I do?

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#87
post #45
post #43

Earlier quoted context omitted.

The problem mostly isn't the runtime itself, but instead the various 3rd party modules (all of which are written in late-90's-era C/C++) that get hooked up to the JVM. For instance, the Quicktime API for Java exposed scalar integers, intended to be "opaque", but in fact raw memory locations. The JVM is good. The Java Applet Plugin, on the other hand, is a problem.

Well, sure. But I think that's maybe missing my point -- a managed runtime needs "holes" in it to do its job, which exposes the security problems of the rest of the system via inevitably leaky abstractions. The point was that the managed runtime does nothing to address this, it has to drill down to a C API at some point (or deeper, consider a similar hole in a shader compiler or video codec accelerator). And contrast…

The best way would be a sandoxing model like SELinux/AppArmor/GateKeeper coupled with a microkernel.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#88

Earlier quoted context omitted.

What can we trace this security priority initiative of Microsoft back to?

Jan 15, 2002 email from Bill Gates to all MSFT staff [1]. Includes some real gems, like; >So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve. 1. http://www.wired.com/techbiz/media/news/2002/01/49826

> Rather than developing standalone applications and Web sites, today we're moving towards smart clients with rich user interfaces interacting with Web services.

Spot on. 2002.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#90
post #70
post #55

Earlier quoted context omitted.

Amsterdam is a criminal epicenter

Any further links or reading? I am very interested in this subject.

Just look at the number of banks and high frequency trading shops :D
Post reply on HN