Live data from Hacker News

Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

thenextweb.com

121–130 of 137 posts

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#121
I'm a long time Java dev and lately it's been terrible, totally terrible, for Java from a security point of view. A gigantic fiasco. Flash's track record is very poor too. Saying that something is "less vulnerable" than these two really doesn't mean much.

We're talking about hundreds of millions of zombie PCs due to Java applets + Flash exploits. So being "less vulnerable" than these technologies doesn't mean much.

So no Microsoft product in the top 10? You mean Word is not as big as an attack vector as Java applets and Excel is not as big as an entry point as Flash? Is there any surprise in here!?

That's not the interesting thing: what concerns most people is the browser they use to surf the Web. Is Safari + Java applet plugin more vulnerable then IE + Java applet? Is Chrome + Flash more vulnerable then IE + Flash?

That's what counts.

And also: how do you install Java on your system if you really need it (e.g. because you're a Java dev) and yet make sure it's not available from your browser? Or from another user account? This kind of stuff is trivial to do on Linux: it's been a long time since I'm using a throwaway user account that has no Java installed to "surf the Web" (using Chrome but whatever). It's trivial to do because on Linux you can install Java from a regular user account (no need to be root).

On Windows this is not possible: installing Java requires the admin password and opens a whole can of worms ; )

I can tell you: I'm surfing from Linux using Chrome which has Flash. I also have Java installed in a separate (developer) user account. And I'm pretty sure this is more secure than surfing from a Windows machine, no matter where Microsoft stands in that report from their "friend in bed" Kaspersky...

Also, for a little touch of irony regaring the article, Kaspersky's revenues are virtually entirely coming from sales of anti-virus protecting Windows OSes. Why aren't they succesful on the Linux servers powering the Internet?

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#122
post #95
post #92

Earlier quoted context omitted.

Google isn't the first company that would come to my mind. I'd rather go for Apple. Their mobile ecosystem might be a lot more secure than Android's, but the way they acknowledge OSX vulnerabilities and how soon they fix them is a weak spot. Oracle with Java could also get a lot of heat.

Apple regularly loses security shootouts, and is widely derided by security people. Their only advantages are their niche status (which they are losing) and their lack of consideration towards old apps (they can dump old APIs which are hard to secure, and make other backwards-incompatible fixes, because they just don't care that much about backwards compatibility).

Apple isn't a niche player in mobile. Wether you like Apple's App Store or not, in terms of security it's a raging success.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#123

Earlier quoted context omitted.

If you wanted to put Microsoft under a microscope from 2003-2010, during the time where they were actually putting in the work to transition from a 1990's software security practice to a 201x security practice, you'd find plenty of "smoking guns" to win arguments with on message boards.

So you're implying what were witnessing at the moment is Adobe improving as steadily and quickly as it can? Why do I find that hard to believe. Oh right, because I've launched and used Adobe software in my life.

TL;DR: you probably won't notice unless you are looking for bugs in their products, and trying to write exploits.

You will certainly not notice any improvement in their "creative" apps.

But these do not really form a part of most people's "internet attack surface". The priorities are Reader and Flash. Perhaps AIR.

Adobe Reader X is a lot more secure than Reader 9 was. The bugs are still there - many Reader 9 bugs affect X. However, exploitation is much harder, and I haven't seen anyone get reliable code execution in X yet.

They are supposed to be working hard on Flash too, although I haven't looked at that recently. I remain unconvinced that Flash is actually fixable, but perhaps they could win with strong enough sandboxing and exploit mitigation...

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#124

Oracle took the top 2, but Adobe had 5 runners up. Too bad Adobe couldn't overtake Oracle, they clearly put in a lot of effort at it. And Microsoft.. not even being listed? Are they even trying anymore?

but oracle products account for 53 of the malware attacks !

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#125

Earlier quoted context omitted.

I hate iTunes too for all of the reasons mentioned above, however there's one thing it does at least half-ok'ish: It doesn't eat a ton of CPU while playing a few simple MP3s... I've tried using Clementine (an Amarok-fork, my favourite music-player by far, at least on Linux) but it's just a resource-hog - comparatively at least. So yeah - does anyone have suggestions on what to use for music playback? Something that d…

I've been using http://www.foobar2000.org/ for almost 10 years now. Though most of my music now is in the cloud, I always keep a heavily modded version of fb2k on my PC. This is BY FAR the best audio player available. I had some respect for Amarok when I was on KDE 6-7 years ago. Nowhere close to fb2k though. Nowadays on Linux I prefer just plain old mpd.

> Heavily modded version

That's the problem i found with foobar. I always enjoyed WinAmp and still miss it to this day on mac. Itunes is no comparison.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#126
post #5

This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.

"Happy that is finally being acknowledged on the outside." Not to mention by a reputable security company in the business (we all know there's some sources whom are... biased... to put it nicely). Congrats to Microsoft, glad to see they've put security so highly on their priority list. Not to mention the involvement they try to get with hackers, and worldwide trying to stop spam botnets, etc... Very nice to see a cor…

I think it's actually "who" in this case: the pronoun is the subject of "are biased."

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#127

Earlier quoted context omitted.

If you wanted to put Microsoft under a microscope from 2003-2010, during the time where they were actually putting in the work to transition from a 1990's software security practice to a 201x security practice, you'd find plenty of "smoking guns" to win arguments with on message boards.

So you're implying what were witnessing at the moment is Adobe improving as steadily and quickly as it can? Why do I find that hard to believe. Oh right, because I've launched and used Adobe software in my life.

This is exactly what Slashdot commenters said about Microsoft software in 2007.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#128
post #102
post #95

Earlier quoted context omitted.

Apple regularly loses security shootouts, and is widely derided by security people. Their only advantages are their niche status (which they are losing) and their lack of consideration towards old apps (they can dump old APIs which are hard to secure, and make other backwards-incompatible fixes, because they just don't care that much about backwards compatibility).

This is a rather biased view. Maybe check that top ten list again.

The one that Apple holds two positions in for arbitrary code execution vulnerabilities?

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#129
post #71

This reminds me of the bear joke: They only had to outrun oracle and adobe...

The implication here is that Microsoft didn't actually improve their security so much as Oracle and Adobe failed to keep up with theirs. I don't know whether you intended to say that, but either way, it's a false statement.

...or a criticism of Oracle and Adobe, which is then 100% true statement.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#130

Earlier quoted context omitted.

Jan 15, 2002 email from Bill Gates to all MSFT staff [1]. Includes some real gems, like; >So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve. 1. http://www.wired.com/techbiz/media/news/2002/01/49826

Good for him. This doesn't seem to be the attitude of many in the startup scene. It isn't the attitude of all too many app developers. It also doesn't seem to be the highest priority at Apple.

it was a response to the very real threat of Linux. MS was getting publicly beaten on an almost monthly basis by malware authors. It was a whack-a-mole contest to keep our boxes patched. I still scratch my head and wonder why our bosses have kept demanding Windows Windows Windows...
Post reply on HN