Live data from Hacker News

Microsoft has released software updates to plug at least 570 security holes

krebsonsecurity.com

101–110 of 132 posts

Re: Microsoft has released software updates to plug at least 570 security holes

#101

Earlier quoted context omitted.

Isn't that... Windows Update? At least last time I looked it would update .net runtimes, Office, what else? OK, Visual Studio has its own update mechanism. Edge is part of the OS, isn't it?

it's still an opt-in setting though. Windows and OS-components like drivers and Edge do get auto updated yes, but to enable Microsoft Update, you still need to turn on a setting in the Settings app. even setting up a new PC/laptop with windows, this is off by default.

That's likely because of antitrust. If they let their software hook into Windows Update, then they would need to let everybody do the same.

Re: Microsoft has released software updates to plug at least 570 security holes

#102
post #18

Earlier quoted context omitted.

How many were introduced by misuse of AI coding/vibe coding though?

Is it worse than what humans were doing on their own anyway?

No, just more prolific.

Re: Microsoft has released software updates to plug at least 570 security holes

#103
post #37
post #4

I wonder how many bugs will be introduced with these fixes...

They don't introduce bugs. They introduce feature experiences.

That feature experience often crops up as a choose-your-own-adventure game! Looks like their users are loving it [0].

[0] https://www.neowin.net/news/it-admins-feel-overwhelmingly-si...

Re: Microsoft has released software updates to plug at least 570 security holes

#104

It seems like bug hunting might be the one area where AI is actually making the world a better place.

There's also the weird scenario of a reporting bias where instead of admitting to a bunch of vulnerabilities, you can frame it as "look at how useful AI is".

We even have companies implementing solutions for ffmpeg vulnerabilities themselves instead of just handing them the vulns to fix themselves.

It's very possible the tide reverses if it's not in people's interest to advocate for AI anymore, so we better not get too used to it just in case.

It's nice that we currently have an alignment of AI advocacy and infosec, though. Maybe Microsoft can even point their AI to their questionable UX and UI practices next.

Re: Microsoft has released software updates to plug at least 570 security holes

#105
post #36

It seems like bug hunting might be the one area where AI is actually making the world a better place.

99.9% of people complaining about AI making the world a worse place would be fully happy with AI if they shared in the economic benefits of automation.

[deleted]

Re: Microsoft has released software updates to plug at least 570 security holes

#106
post #76

Earlier quoted context omitted.

Vibe-coded apps probably have loads, but mostly because they're using less capable models than the people who're doing the bug-hunting. Once vibe-coders are using models like Mythos too you should expect the number of bugs in vibe-coded apps to collapse quickly, because the LLM will write the bugs but will also fix them (assuming the system prompt tells it to.)

For some reasons, models are blind to their own output...

Not my experience with my homie Claudius.

The code review agent usually has feedback to be resolved before committing, which includes bugs and unhandled edge cases. Sometimes the primary context is understandably embarrassed.

Sometimes it truly be your own people.

Re: Microsoft has released software updates to plug at least 570 security holes

#107
post #99

Earlier quoted context omitted.

For some reasons, models are blind to their own output...

One reason seems obvious/intuitive: because their own output matches their own biases, that is, is a direct result of their model walks.

I think this could be true if you use a single Claude context, since it has its own reasoning in the context.

But a separate code review agent does much better, in my experience.

Re: Microsoft has released software updates to plug at least 570 security holes

#108

It seems like bug hunting might be the one area where AI is actually making the world a better place.

I am curious, they say we should expect a trend of more security patches every update.

It this is true and Microsoft devs are using agents it means that AI is doing a shitty job and is introducing more bugs/vulns per month than it fixes them. Otherwise you would have had a lot of bugs/vulns fixed in the first 2 security updates then a steady and significant reduction every month because any new code would have been scanned and fixed before release.

Re: Microsoft has released software updates to plug at least 570 security holes

#109
post #18

Earlier quoted context omitted.

How many were introduced by misuse of AI coding/vibe coding though?

Is it worse than what humans were doing on their own anyway?

Well yes if they expect to find and correct more bugs every update which is pretty much what they are saying.

Re: Microsoft has released software updates to plug at least 570 security holes

#110
post #93
post #66

If I find a bug in very important MS products, I usually do report them using their shitty feedback app. Not once has any of that yielded anything. Maybe a way to find tons of high impact bugs would be to let MS developers access those bug reports?

There's more direct channels to report security vulnerabilities - which this about.

Perhaps the feedback boxes they put in every app should actually be read. That’s a them problem.
Post reply on HN