Live data from Hacker News

Microsoft has released software updates to plug at least 570 security holes

krebsonsecurity.com

1–10 of 132 posts

Re: Microsoft has released software updates to plug at least 570 security holes

#5
Sounds like a lot but compare it to Edge also being patched for 428 Chromium CVEs this month.

If 20 years ago you told me a single piece of software had 428 vulnerabilities I wouldn't have believed it.

If Chromium has that many security bugs, perhaps the move fast and break things approach of spraying diarrhea masquerading as code into a keyboard — in a rush to add new features no one asked for — needs to be reexamined.

Re: Microsoft has released software updates to plug at least 570 security holes

#6

Sounds like a lot but compare it to Edge also being patched for 428 Chromium CVEs this month. If 20 years ago you told me a single piece of software had 428 vulnerabilities I wouldn't have believed it. If Chromium has that many security bugs, perhaps the move fast and break things approach of spraying diarrhea masquerading as code into a keyboard — in a rush to add new features no one asked for — needs to be reexamin…

> If 20 years ago you told me a single piece of software had 428 vulnerabilities I wouldn't have believed it.

For something as complex as an operating system or a web browser, even one from 20 years ago (say, Windows XP or IE/Firefox) I wouldn't have believed there were 428 vulnerabilities either, I would have assumed there were much more than that.

Re: Microsoft has released software updates to plug at least 570 security holes

#7

Sounds like a lot but compare it to Edge also being patched for 428 Chromium CVEs this month. If 20 years ago you told me a single piece of software had 428 vulnerabilities I wouldn't have believed it. If Chromium has that many security bugs, perhaps the move fast and break things approach of spraying diarrhea masquerading as code into a keyboard — in a rush to add new features no one asked for — needs to be reexamin…

Even if it had the Microsoft logo attached? Windows was always known to not be the most secure of products. I can't imagine anything else from the same company would be any better

Re: Microsoft has released software updates to plug at least 570 security holes

#8
post #3

An employee just got phished by adding a number to a legitimate deviceAdd login route that bypasses 2FA and adds a device with full access to office and mail Probably working as intended...

I always click NO to these, that's full human error. edit: The underlying issue is that they send a 2FA before asking for a password at all.

Re: Microsoft has released software updates to plug at least 570 security holes

#9
post #7

Sounds like a lot but compare it to Edge also being patched for 428 Chromium CVEs this month. If 20 years ago you told me a single piece of software had 428 vulnerabilities I wouldn't have believed it. If Chromium has that many security bugs, perhaps the move fast and break things approach of spraying diarrhea masquerading as code into a keyboard — in a rush to add new features no one asked for — needs to be reexamin…

Even if it had the Microsoft logo attached? Windows was always known to not be the most secure of products. I can't imagine anything else from the same company would be any better

[deleted]

Re: Microsoft has released software updates to plug at least 570 security holes

#10

Sounds like a lot but compare it to Edge also being patched for 428 Chromium CVEs this month. If 20 years ago you told me a single piece of software had 428 vulnerabilities I wouldn't have believed it. If Chromium has that many security bugs, perhaps the move fast and break things approach of spraying diarrhea masquerading as code into a keyboard — in a rush to add new features no one asked for — needs to be reexamin…

20 years ago software wasn't as much battle tested as today, had way less feature set, was less connected to the internet, and etc. 428 CVEs looks small, assuming not all have CVSS 9.8 or something.
Post reply on HN