And _this_, ladies and gentlemen, is why we have disclosure deadlines for security vulnerabilities. For example, Project Zero expects vendors to fix security vulnerabilities within 90 days of notification. Looking at this story, it's possible that 90 days is almost too long and should be shortened. As time goes on, it's becoming more and more common for multiple parties to become aware of the same vulnerabilities. No…
Next up on HN: extreme outrage after a botched security update breaks hundreds of millions of machines. Not all bugs can be fixed with a simple one-line fix, and the faster patches need to be cranked out, the lower quality they'll be.
Hackers exploited Word flaw for months while Microsoft investigated
31–40 of 105 posts
Re: Hackers exploited Word flaw for months while Microsoft investigated
#32Earlier quoted context omitted.
But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc Just for the record in case someone isn't aware: Modern Linuxes are often easier to install and install software onto (as long as that software isn't written specifically for Windows or Mac OS.)
I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…
So many apps fail with HiDPi that I just use an external monitor.
Having to compress folders by selecting "send to" and digging around the tray for an eject button, is something I can't figure out how to solve so easily.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#33Vendors, even ones as large as Microsoft, do not have infinite resources available to evaluate vulnerabilities. There are only so many of the issues you can work on at once. They have to evaluate each issue and prioritize the fix. In this case, they merely did not recognize the potential scope of the problem at hand.
Unless it comes from Google of course, because they know Google take the 90 day deadline seriously (or 7 days for active attacks such as this).
That alone speaks volumes, and pretty much validates the necessity of Google's forced disclosure policy.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#34Earlier quoted context omitted.
But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc Just for the record in case someone isn't aware: Modern Linuxes are often easier to install and install software onto (as long as that software isn't written specifically for Windows or Mac OS.)
I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…
Really? You mention in another thread, you used Ubuntu. So you apparently didn't notice this [0] or this [1]?
The issue with this and complexity, is that login screen resolution is often handled by GRUB, not Linux.
Edit: In future you can drop into a commandline via Ctrl+Alt+F1
> Secondary drives require manual mounting (or doing it yourself at the command line).
Install usbmount if its connected by usb, and it'll be automatic.
If it's an internal drive, try gnome-volume-manager and it's a tickbox away. (Which is on quite a few distros by default).
[0] https://askubuntu.com/questions/794074/login-screen-resoluti...
[1] https://askubuntu.com/questions/73804/wrong-login-screen-res...
Re: Hackers exploited Word flaw for months while Microsoft investigated
#35If you can't patch it, you must issue a patch that announces the vuln and disables the minimal set of functionality that enables it. Even if that's the whole program.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#36I thought that it is the norm for M$ to hand out the zero-days to the 3-letter-agencies for "a while" and patches them ONLY when someone else gets hold and starts using the same vuln.. so it makes PERFECT sense that they would do something like that. Also who in their right mind allow Word/Excel/Powerpoint to access the internet? (oh yes it's called "365" and it makes software, that is completely unfit for the task,…
Re: Hackers exploited Word flaw for months while Microsoft investigated
#37We need civil penalties for failing to patch any serious vulnerability (that can be defined as RCE, priv. escalation, etc) within 30 days of disclosure. If you can't patch it, you must issue a patch that announces the vuln and disables the minimal set of functionality that enables it. Even if that's the whole program.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#38Earlier quoted context omitted.
I don't want anyone to be able to shutdown and/or withdraw software that I'm using for any reason. That cure is worse than the disease.
Personally I don't want you to have to. As far as I'm concerned, if you're notified in big, red letters (perhaps every time the software starts)? Works for me. As long as you know -- and are reminded. (That's because different people use the same software. If the notice only appeared once, a new person might start using the software/machine and not be aware of what's going on) But if you had a piece of software with…
A standard splash screen on load that pops up for 10 seconds and says "this program has known active vulnerabilities that are unpatched". If people choose to ignore it, that's on them. Cheap and easy, no?
Re: Hackers exploited Word flaw for months while Microsoft investigated
#39Vendors, even ones as large as Microsoft, do not have infinite resources available to evaluate vulnerabilities. There are only so many of the issues you can work on at once. They have to evaluate each issue and prioritize the fix. In this case, they merely did not recognize the potential scope of the problem at hand.
Nah, that's more false than it is true. I've seen Microsoft sit on cases simply because they can. I'm sure that they were not resource-bound in this case, they simply didn't make it a top priority. Their self-imposed timeline is 180 days by default. Unless it comes from Google of course, because they know Google take the 90 day deadline seriously (or 7 days for active attacks such as this). That alone speaks volumes,…
Re: Hackers exploited Word flaw for months while Microsoft investigated
#40Earlier quoted context omitted.
Personally I don't want you to have to. As far as I'm concerned, if you're notified in big, red letters (perhaps every time the software starts)? Works for me. As long as you know -- and are reminded. (That's because different people use the same software. If the notice only appeared once, a new person might start using the software/machine and not be aware of what's going on) But if you had a piece of software with…
Not sure why you're down voted. I had the same thought as parent, but this seems like the answer. A standard splash screen on load that pops up for 10 seconds and says "this program has known active vulnerabilities that are unpatched". If people choose to ignore it, that's on them. Cheap and easy, no?