> We reported the issues to Microsoft in March 2021, who has only remediated one so far I feel that I read something like this almost every single time Microsoft is mentioned in a vulnerability disclosure. What makes the company so bad at dealing with security reports? I don't expect it to be a lack of talents or resources, or is it?
Microsoft Teams: 1 feature, 4 vulnerabilities
31–40 of 264 posts
Re: Microsoft Teams: 1 feature, 4 vulnerabilities
#32In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…
> a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft Zoom had and continues to have a significant developer presence in China. Those individuals are subject to CCP coercion. There was also a time when they routed American calls through the mainland [1]. That has been fixed. But it remains excessive to cast all past criticism of Zoom as Microsoft's work. [1] https://techcrunch.com/2020/04/0…
Re: Microsoft Teams: 1 feature, 4 vulnerabilities
#33One in this temperament: try accidently pasting a very large amount of data in the chatbox in Teams. Then spend the next 40 minutes re-starting Teams to try to remove the data from said box while your laptop tries to fly away and Teams keeps many processors and gigs of memory lit trying to parse your data. Microsoft should (but won't) reconsider the idea that one chatbox to rule many underlying types of software is a…
Re: Microsoft Teams: 1 feature, 4 vulnerabilities
#34Re: Microsoft Teams: 1 feature, 4 vulnerabilities
#35In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…
> a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft Zoom had and continues to have a significant developer presence in China. Those individuals are subject to CCP coercion. There was also a time when they routed American calls through the mainland [1]. That has been fixed. But it remains excessive to cast all past criticism of Zoom as Microsoft's work. [1] https://techcrunch.com/2020/04/0…
Security flaws in a product are part of the life cycle, unavoidable and might be accepted as long as proper and timely response is taken. That's due diligence. But lying about security? That's not even negligence.
Re: Microsoft Teams: 1 feature, 4 vulnerabilities
#36In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…
> a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft Zoom had and continues to have a significant developer presence in China. Those individuals are subject to CCP coercion. There was also a time when they routed American calls through the mainland [1]. That has been fixed. But it remains excessive to cast all past criticism of Zoom as Microsoft's work. [1] https://techcrunch.com/2020/04/0…
I figured that it was done by a big party that had a trusted relationship with tech journalists because they bigged up vulnerabilities that were relatively minor to journalists who didnt seem to be aware of it.
It's possible it wasnt Microsoft but the pattern of stories indicated Zoom was a public relations target of someone who freaked out after seeing how fast they were growing and MS certainly took full advantage.
Re: Microsoft Teams: 1 feature, 4 vulnerabilities
#37What is the solution? More security education for general SWEs? It seems like whatever team worked on this feature never considered any security perspectives.
Make all software which isn't released as open source liable for the cost of security breaches?
"I'll have some Beware-of-the-Leopard signs printed up."
Re: Microsoft Teams: 1 feature, 4 vulnerabilities
#38MS Teams is the worst software I've ever used. This is not hyperbole. A room full of monkeys on a typewriter would never create something as bad as teams.
Monkeys could barely create software if at all. That means you have set a low badness bar for Teams to surpass.
Re: Microsoft Teams: 1 feature, 4 vulnerabilities
#39In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…
> a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft Zoom had and continues to have a significant developer presence in China. Those individuals are subject to CCP coercion. There was also a time when they routed American calls through the mainland [1]. That has been fixed. But it remains excessive to cast all past criticism of Zoom as Microsoft's work. [1] https://techcrunch.com/2020/04/0…
For all my harsh criticism of both Microsoft and Google I wish them well: I want them to tidy up and become trustworthy.
Because the alternative where China becomes world leading is actually worse.
For all their warts Americans and American companies have done much good and gotten way more criticism for their faults compared to others.
That doesn't however mean that they should get off the hook easily, only that we should work to put them in an position were we can actually trust each other.
Re: Microsoft Teams: 1 feature, 4 vulnerabilities
#40What is the solution? More security education for general SWEs? It seems like whatever team worked on this feature never considered any security perspectives.
Make all software which isn't released as open source liable for the cost of security breaches?
If anything, freeware (whether open source or proprietary) should be exempt from costs. You get what you pay for, after all.