Earlier quoted context omitted.
Isn't that... Windows Update? At least last time I looked it would update .net runtimes, Office, what else? OK, Visual Studio has its own update mechanism. Edge is part of the OS, isn't it?
it's still an opt-in setting though. Windows and OS-components like drivers and Edge do get auto updated yes, but to enable Microsoft Update, you still need to turn on a setting in the Settings app. even setting up a new PC/laptop with windows, this is off by default.
Microsoft has released software updates to plug at least 570 security holes
101–110 of 132 posts
Re: Microsoft has released software updates to plug at least 570 security holes
#102Re: Microsoft has released software updates to plug at least 570 security holes
#103I wonder how many bugs will be introduced with these fixes...
They don't introduce bugs. They introduce feature experiences.
[0] https://www.neowin.net/news/it-admins-feel-overwhelmingly-si...
Re: Microsoft has released software updates to plug at least 570 security holes
#104It seems like bug hunting might be the one area where AI is actually making the world a better place.
We even have companies implementing solutions for ffmpeg vulnerabilities themselves instead of just handing them the vulns to fix themselves.
It's very possible the tide reverses if it's not in people's interest to advocate for AI anymore, so we better not get too used to it just in case.
It's nice that we currently have an alignment of AI advocacy and infosec, though. Maybe Microsoft can even point their AI to their questionable UX and UI practices next.
Re: Microsoft has released software updates to plug at least 570 security holes
#105Re: Microsoft has released software updates to plug at least 570 security holes
#106Earlier quoted context omitted.
Vibe-coded apps probably have loads, but mostly because they're using less capable models than the people who're doing the bug-hunting. Once vibe-coders are using models like Mythos too you should expect the number of bugs in vibe-coded apps to collapse quickly, because the LLM will write the bugs but will also fix them (assuming the system prompt tells it to.)
For some reasons, models are blind to their own output...
The code review agent usually has feedback to be resolved before committing, which includes bugs and unhandled edge cases. Sometimes the primary context is understandably embarrassed.
Sometimes it truly be your own people.
Re: Microsoft has released software updates to plug at least 570 security holes
#107Earlier quoted context omitted.
For some reasons, models are blind to their own output...
One reason seems obvious/intuitive: because their own output matches their own biases, that is, is a direct result of their model walks.
But a separate code review agent does much better, in my experience.
Re: Microsoft has released software updates to plug at least 570 security holes
#108It seems like bug hunting might be the one area where AI is actually making the world a better place.
It this is true and Microsoft devs are using agents it means that AI is doing a shitty job and is introducing more bugs/vulns per month than it fixes them. Otherwise you would have had a lot of bugs/vulns fixed in the first 2 security updates then a steady and significant reduction every month because any new code would have been scanned and fixed before release.
Re: Microsoft has released software updates to plug at least 570 security holes
#109Re: Microsoft has released software updates to plug at least 570 security holes
#110If I find a bug in very important MS products, I usually do report them using their shitty feedback app. Not once has any of that yielded anything. Maybe a way to find tons of high impact bugs would be to let MS developers access those bug reports?
There's more direct channels to report security vulnerabilities - which this about.