Live data from Hacker News

Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

thenextweb.com

111–120 of 137 posts

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#111

Haha. Great to see iTunes and QuickTime (Windows versions, probably?) on the list... Apple should really either update them (I'm not sure iTunes 11 will be released for windows too) , or just abandon them (and ask customers to use iCloud for backup). A few days ago I opened a .mov on a Windows machine with QuickTime - it was horrible. I can't imagine how dreadful iTunes probably is. No wonder all PC guys hate iTunes.…

PC guy here. Have used Fedora for years as my daily OS and the only reason i have a Windows VM on my linux machine is actually because i love iTunes so much. I don't have an iDevice, either.

I've used a vast array of media players for Linux and Windows and nothing i can find matches the features iTunes has for organizing my music library.

However, it's difficult to understand why Apple doesn't update iTunes on Windows more frequently. I'm pretty sure the last iTunes update on Windows fixed well over twenty-five security vulnerabilities in open source libraries that were known for upwards of six months to everyone.

While that STILL doesn't match the negligence of companies like Oracle and Adobe, it's still negligence. Unacceptable negligence which is putting users at risk.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#114
post #53
post #18

Is it getting safer to say that antivirus software may soon be a thing of the past?

My question is, would you run Windows 7/8 without any anti-virus software at all? Do you feel that comfortable? After years of Linux/OS X I can safely say that I won't use an OS that requires anti-virus ever again.

Man I really hate to break it to you but Linux (and almost certainly OS X) has many privilege-escalation bugs at any given time. Any executable you run on any operating system could potentially be a virus; the main thing protecting you on Linux is that the combinations of buggy kernels and buggy libraries are much wider than on Windows, which generally stays pretty up-to-date and thus consistent across many machines.

Don't pretend Unix-type OSes are immune to malware. Don't forget the Morris worm.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#116

Earlier quoted context omitted.

What can we trace this security priority initiative of Microsoft back to?

Jan 15, 2002 email from Bill Gates to all MSFT staff [1]. Includes some real gems, like; >So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve. 1. http://www.wired.com/techbiz/media/news/2002/01/49826

Good for him. This doesn't seem to be the attitude of many in the startup scene. It isn't the attitude of all too many app developers. It also doesn't seem to be the highest priority at Apple.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#117
post #114
post #53

Earlier quoted context omitted.

My question is, would you run Windows 7/8 without any anti-virus software at all? Do you feel that comfortable? After years of Linux/OS X I can safely say that I won't use an OS that requires anti-virus ever again.

Man I really hate to break it to you but Linux (and almost certainly OS X) has many privilege-escalation bugs at any given time. Any executable you run on any operating system could potentially be a virus; the main thing protecting you on Linux is that the combinations of buggy kernels and buggy libraries are much wider than on Windows, which generally stays pretty up-to-date and thus consistent across many machines.…

Yes, especially on HN.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#118
post #85

Let's take a look at CERT, shall we? 17 Sep 2012 VU#480095 Microsoft Internet Explorer 6/7/8/9 contain a use-after-free vulnerability 17 Sep 2012 VU#389795 Windows Phone 7 does not check certificate Common Names when sending or receive Hmm. OK, how about #1 service being remotely attacked right now: MS Terminal Services

The OP is a list of vulerabilities by severity. When I look at the current US-CERT database, I don't see any Microsoft products in the top 10 results by severity[1] or by date[2]. [1] By "Common Vulnerability Scoring System": http://www.kb.cert.org/vuls/byCVSS [2] By Date: http://www.kb.cert.org/vuls/bypublished

Whatever. " Not one Microsoft product on Kaspersky’s top 10" implies that Microsoft products are secure. They are not.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#119

Earlier quoted context omitted.

Remember this? http://www.gizmodo.com.au/2012/05/adobes-photoshop-security-... They left Photo CS 5.5 users twisting in the wind, recommending customers pay to upgrade their one-year-old software to CS 6. I don't know if it was the external pressure or a slow in-house process, but it took them a month to release a fix for CS 5.5 users: http://www.adobe.com/support/security/bulletins/apsb12-11.ht...

If you wanted to put Microsoft under a microscope from 2003-2010, during the time where they were actually putting in the work to transition from a 1990's software security practice to a 201x security practice, you'd find plenty of "smoking guns" to win arguments with on message boards.

So you're implying what were witnessing at the moment is Adobe improving as steadily and quickly as it can?

Why do I find that hard to believe. Oh right, because I've launched and used Adobe software in my life.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#120

Interesting to note that both Apple vulnerabilities listed exist only for their Windows software. (QuickTime: http://lists.apple.com/archives/security-announce/2012/May/m... iTunes: http://support.apple.com/kb/HT5485 ) I wonder if these are lower priority for Apple or if they perhaps just aren't as good when developing for Windows.

Quicktime on Windows is stuck at version 7, which is riddled with numerous problems. It's this old Quicktime codebase that is the source of the Quicktime and iTunes vulnerabilities on Windows. The current version on Mac and iOS is Quicktime X. This version was a complete rewrite (that started on iOS and eventually migrated to the Mac). The complete rewrite allowed for a vastly more secure design (among other improvem…

But the iTunes backend is still QuickTime 7 on both Mac OS X and Windows. QuickTime is really only present on Windows machines nowadays as the backend of iTunes.
Post reply on HN