He asked a PR person, probably one with little security background (how many security people do you know who went into PR?) gave the stock answer which does happen to actually be good security advice: run the latest supported version with patches. The reporter was just butthurt about not getting a scoop and decided to write an article complaining about PR practices in place of an actual story. Really like the click b…
It's a rant about PR bullshit, specifically this: >Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible, EDIT and this >The time has come for Microsoft vulnerability disclosure communications to mute the marketers and let the security engineers do the talking instead. I found it funny to be honest
Windows 10 0day exploit goes wild, and so do Microsoft marketers
21–30 of 78 posts
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#22Earlier quoted context omitted.
>assuming that the fix is just a few lines of code
Even assuming that, there could be a massive testing load to ensure that those few lines of code don't mess up something tangentially related, or cause new security issues of their own.
http://www.computerworld.com/article/2878026/microsoft-to-bu...
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#23Earlier quoted context omitted.
>assuming that the fix is just a few lines of code
Even assuming that, there could be a massive testing load to ensure that those few lines of code don't mess up something tangentially related, or cause new security issues of their own.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#24Earlier quoted context omitted.
> IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. Except the researcher themselves knew it was one more week, and not "several years." You cannot claim they were ignorant if their own statements shows that they were not.
You might be right. But they only claimed it, didn't they? I personally like Windows 10 a lot and I applaud any effort to turn it into a long-term stable OS.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#25Earlier quoted context omitted.
It's a rant about PR bullshit, specifically this: >Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible, EDIT and this >The time has come for Microsoft vulnerability disclosure communications to mute the marketers and let the security engineers do the talking instead. I found it funny to be honest
I am still shocked that Windows was recoverable from the fiasco of XP security problems. They have gotten exponentially better in security over the years.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#26Earlier quoted context omitted.
You might be right. But they only claimed it, didn't they? I personally like Windows 10 a lot and I applaud any effort to turn it into a long-term stable OS.
Well, if MS claims the patch is coming in one week, one approach might be to wait one week and then release the exploit. Works out regardless of the accuracy of the claim.
So they already reneged once on this bug which fits into a previous pattern. If that is right putting pressure on them sounds entirely justified and not at all petty.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#27Earlier quoted context omitted.
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
There are very competent people on this planet who make a very good buck out of zero-days (not to mention remotely control users' machines, and steal data). IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is…
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#28The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
He's not causing problems, he's solving them.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#29Earlier quoted context omitted.
You might be right. But they only claimed it, didn't they? I personally like Windows 10 a lot and I applaud any effort to turn it into a long-term stable OS.
Well, if MS claims the patch is coming in one week, one approach might be to wait one week and then release the exploit. Works out regardless of the accuracy of the claim.
This bug was reported in December, and there's no reason to believe that they didn't have a patch in time for inclusion in the January Patch Tuesday. They chose to withhold that patch due to non-technical, apparently PR-related, reasons, and the researcher in question is complaining that this has happened before with other bugs reported by him. That's a pretty cavalier approach to security, and early disclosure is the only way the researcher can punish MS for it.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#30Earlier quoted context omitted.
There are very competent people on this planet who make a very good buck out of zero-days (not to mention remotely control users' machines, and steal data). IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is…
Just because there are other people who act totally unethically doesn't mean you get bonus points for doing kinda the right thing.