Live data from Hacker News

Windows 10 0day exploit goes wild, and so do Microsoft marketers

arstechnica.com

11–20 of 78 posts

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#11

tl;dr: a null deref in windows kernel when you connect to a malicious SMB share

tl;dr: a CVSS 7.8 Windows vulnerability in the SMB service can allow an attacker to DoS any machine with the filesharing service exposed; the possibility of RCE seems to have been discarded; exploits are freely available online. This article complains that Microsoft's communication is lacking details and transparency in times of war

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#12
post #6

He asked a PR person, probably one with little security background (how many security people do you know who went into PR?) gave the stock answer which does happen to actually be good security advice: run the latest supported version with patches. The reporter was just butthurt about not getting a scoop and decided to write an article complaining about PR practices in place of an actual story. Really like the click b…

It's a rant about PR bullshit, specifically this:

>Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible,

EDIT and this

>The time has come for Microsoft vulnerability disclosure communications to mute the marketers and let the security engineers do the talking instead.

I found it funny to be honest

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#13

Does anybody know how many days it would take from when a critical security bug is discovered in Windows and assuming that the fix is just a few lines of code and not a component rewrite and marketing is not in the way, I am wondering how many steps are from when a fix is created until is released.(I imagine that there may some QA and some managers that need to approve it but I have no idea)

It depends. Some bugs can be fixed easily and some might be too complicate to fix even though it looks simple. Usually all critical bugs are attended as soon as they are created (few hours delay). But the actual fix depends on the bug and there is no general formula for that

>assuming that the fix is just a few lines of code

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#14
The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet:

"I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, they're not helping their users but doing marketing damage control, and opportunistic patch release."

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#15

The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…

The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before.

If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#16

Earlier quoted context omitted.

It depends. Some bugs can be fixed easily and some might be too complicate to fix even though it looks simple. Usually all critical bugs are attended as soon as they are created (few hours delay). But the actual fix depends on the bug and there is no general formula for that

>assuming that the fix is just a few lines of code

Even assuming that, there could be a massive testing load to ensure that those few lines of code don't mess up something tangentially related, or cause new security issues of their own.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#17
post #15

The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…

The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.

There are very competent people on this planet who make a very good buck out of zero-days (not to mention remotely control users' machines, and steal data). IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years.

It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is a PR hype.

If they want researchers to stop doing preliminary public disclosures, they should prioritize security higher than PR damage control.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#18
post #15

The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…

The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.

And when Microsoft do cut QA short people complain that Microsoft doesn't care about quality/is using retail as a beta test. It is really a no-win situation to be honest.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#19
post #15

Earlier quoted context omitted.

The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.

There are very competent people on this planet who make a very good buck out of zero-days (not to mention remotely control users' machines, and steal data). IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is…

> IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years.

Except the researcher themselves knew it was one more week, and not "several years." You cannot claim they were ignorant if their own statements shows that they were not.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#20

Earlier quoted context omitted.

There are very competent people on this planet who make a very good buck out of zero-days (not to mention remotely control users' machines, and steal data). IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is…

> IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. Except the researcher themselves knew it was one more week, and not "several years." You cannot claim they were ignorant if their own statements shows that they were not.

You might be right. But they only claimed it, didn't they?

I personally like Windows 10 a lot and I applaud any effort to turn it into a long-term stable OS.

Post reply on HN