Live data from Hacker News

The Microsoft Update mechanism has been used to spread malware

f-secure.com

21–30 of 64 posts

Re: The Microsoft Update mechanism has been used to spread malware

#21
post #3

It really was an unbelievable oversight to use the same certs in the Terminal Services activation system. Quite a demonstration that even if you go to great pains to secure the code if you aren't careful with your credentials then it's for nothing.

A very similar thing happened with France during WW2.

I always remind myself I'm not as smart as I think I am.

Re: The Microsoft Update mechanism has been used to spread malware

#23
post #7

Oh look, another scaremongering and purposely misleading article from F-Secure. This is starting to become a regular thing isn't it; I guess the recession must have hit them particularly hard.

Frankly, I don't have an idea of what are you trying to say or imply.

Re: The Microsoft Update mechanism has been used to spread malware

#24
post #21
post #3

It really was an unbelievable oversight to use the same certs in the Terminal Services activation system. Quite a demonstration that even if you go to great pains to secure the code if you aren't careful with your credentials then it's for nothing.

A very similar thing happened with France during WW2. I always remind myself I'm not as smart as I think I am.

What happened with France?

Re: The Microsoft Update mechanism has been used to spread malware

#25

Here we have an example of complexity arising from copy protection/licensing. It so happens that this complexity caused a security vulnerability which, when exploited on any one computer, affects close to a billion computers. Is anyone else infuriated that a vulnerability like this exists in what is analogous to copy protection code? In other words, if Microsoft had been spending more of their resources on making sof…

Microsoft has over 90,000 employees, and no doubt some of those people were hired specifically to protect their software licensing. They're probably not pulling their top OS developers to work on this. So the idea that they should have been "spending more of their resources on making software work..." is not really valid. In fact, there is no company or software community anywhere that writes highly complex and bug f…

I agree with you that they are not necessarily removing developers from other projects to work on licensing. However, a percentage of code in Windows is dedicated to validating licensing and preventing piracy.

> In fact, there is no company or software community anywhere that writes highly complex and bug free software. It's not possible.

I agree with this point. For this reason, the point I'm trying to make is that reducing complexity is a key way to make software more secure. And when reducing complexity, we should look at what is in the user's best interest.

Code has bugs--that is an unescapable fact for the foreseeable future. Therefore, any code running on your computer makes you slightly less safe. Therefore, any code on your machine which is not accomplishing something in your best interests could be considered an unnecessary security risk.

I am arguing that it is not in your best interest to insure that you bought a little certificate from Microsoft before your computer operates the way you have configured it to.

After all that, of course it is in your best interests to have Microsoft grow its war chest and be a healthy company that can employ tens of thousands of smart developers to write good code (which we choose to keep using year after year).

But, every time a product breaks because they have to make sure I'm not a criminal, and the way they do it is sloppy, I get upset, and I think it's rightfully so. Usually it is small, proprietary CMS or CRM software that drives me crazy. But today it's this issue.

Re: The Microsoft Update mechanism has been used to spread malware

#26
post #18
post #4

This is like finding out the zombies have made it into the compound. I wonder how big this hole is to fix. I also wonder, as many have, if this was written by an Intelligence agency and, if so, if they had access to Windows' source code.

My Windows already fixed it. http://support.microsoft.com/kb/2718704

The awesome part is how they force you to download an additional signed WGA validator exe before the site coughs up the patch, which itself is signed. If I was the attacker, I'd definitely be MITM'ing this page.

Zombies in the compound indeed.

Re: The Microsoft Update mechanism has been used to spread malware

#28
post #21

Earlier quoted context omitted.

A very similar thing happened with France during WW2. I always remind myself I'm not as smart as I think I am.

What happened with France?

I suspect it's a reference to 'the Maginot Line':

http://en.wikipedia.org/wiki/Maginot_Line

Post reply on HN