Live data from Hacker News

Microsoft has released software updates to plug at least 570 security holes

krebsonsecurity.com

91–100 of 132 posts

Re: Microsoft has released software updates to plug at least 570 security holes

#93
post #66

If I find a bug in very important MS products, I usually do report them using their shitty feedback app. Not once has any of that yielded anything. Maybe a way to find tons of high impact bugs would be to let MS developers access those bug reports?

There's more direct channels to report security vulnerabilities - which this about.

Re: Microsoft has released software updates to plug at least 570 security holes

#94
post #12

It would be nice if microsoft had windows update for .net, visual c++, office, windows, edge ... just all their software in one updater, but that would be too easy...

Isn't that... Windows Update? At least last time I looked it would update .net runtimes, Office, what else? OK, Visual Studio has its own update mechanism. Edge is part of the OS, isn't it?

And teams. And new outlook. And powertoys. Onedrive. SQL Server. The Microsoft store. Winget. I'm also not confident Windows Update actually does update Office, which also retains its own update mechanism.

Re: Microsoft has released software updates to plug at least 570 security holes

#95
post #76
post #18

Earlier quoted context omitted.

How many were introduced by misuse of AI coding/vibe coding though?

Vibe-coded apps probably have loads, but mostly because they're using less capable models than the people who're doing the bug-hunting. Once vibe-coders are using models like Mythos too you should expect the number of bugs in vibe-coded apps to collapse quickly, because the LLM will write the bugs but will also fix them (assuming the system prompt tells it to.)

For some reasons, models are blind to their own output...

Re: Microsoft has released software updates to plug at least 570 security holes

#96
post #65
post #45

Earlier quoted context omitted.

I don't see why AI would deskill what you love to do. People still do embroidery even though mass manufacturing exists. If you love something you would continue doing it irrespective of automation.

For better or worse this round of "automation" will hit harder than most others because it comes for what makes you you . Your brain, not your body. The industrial revolution replaced your body, this one could in theory replace you entirely. And it isn't coming for some job, it comes for most. It's not just a hobby but being able to do the job. You are replacing 10000 types of jobs with 1 type: AI prompter. We'll pro…

Yeah this round replaces both body and knowledge.

Basically what is left is internal politics and cross company dynamics until we get to the point where a company is self autonomous.

Re: Microsoft has released software updates to plug at least 570 security holes

#97

Earlier quoted context omitted.

It depends on how good their testing practices and code review / auditing are. I want to believe they are some of the best in the industry, but that's making assumptions. But jumping to assumptions that fixes introduce bugs is a bit rash and assumes incompetence / unprofessionality / unmonitored AI usage / kneejerk bugfix processes.

Microsoft (in)famously fired all their QA people like a decade ago.

Most Saas delegated QA to their clients...

Re: Microsoft has released software updates to plug at least 570 security holes

#98

Earlier quoted context omitted.

highly unlikely for many of them. SharePoint, bitlocker, Active directory, hyper-v, rdp, DHCP and MSMQ are all software/technologies that have decades of history and long pre-dated LLMs. seriously, do people not realise it was entirely possible to write insecure or bad code before LLMs?

It’s like people don’t remember the whole outsourcing trend and all the awful code that came from that.

Hey, I wrote slop at Microsoft way before it was cool.

Re: Microsoft has released software updates to plug at least 570 security holes

#99
post #76

Earlier quoted context omitted.

Vibe-coded apps probably have loads, but mostly because they're using less capable models than the people who're doing the bug-hunting. Once vibe-coders are using models like Mythos too you should expect the number of bugs in vibe-coded apps to collapse quickly, because the LLM will write the bugs but will also fix them (assuming the system prompt tells it to.)

For some reasons, models are blind to their own output...

One reason seems obvious/intuitive: because their own output matches their own biases, that is, is a direct result of their model walks.

Re: Microsoft has released software updates to plug at least 570 security holes

#100
post #36

It seems like bug hunting might be the one area where AI is actually making the world a better place.

99.9% of people complaining about AI making the world a worse place would be fully happy with AI if they shared in the economic benefits of automation.

"People complaining slavery makes the world a worse place would be fully happy if they were slave owners"

Probably, but just proves people can ignore bad things when they benefit them.

Not what it pretends to prove, that the thing isn't bad.

Post reply on HN