Live data from Hacker News

Windows 10 0day exploit goes wild, and so do Microsoft marketers

arstechnica.com

41–50 of 78 posts

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#41
post #29

Earlier quoted context omitted.

Well, if MS claims the patch is coming in one week, one approach might be to wait one week and then release the exploit. Works out regardless of the accuracy of the claim.

Patch Tuesday is the second Tuesday of each month. Unless something odd happens, you can count on the fix being out a week from tomorrow. There's also a justification for this — they sat on it because they were releasing other SMB-related patches on the February Patch Tuesday. I don't really think anybody can reasonably argue that MS would not release the fix next week. But that's not the point. This bug was reported…

It's slightly worse than that: the bug was reported in September; December appears to be when they had the patch ready.

So there were two months of apparently unjustified delay.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#42
post #12
post #6

He asked a PR person, probably one with little security background (how many security people do you know who went into PR?) gave the stock answer which does happen to actually be good security advice: run the latest supported version with patches. The reporter was just butthurt about not getting a scoop and decided to write an article complaining about PR practices in place of an actual story. Really like the click b…

It's a rant about PR bullshit, specifically this: >Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible, EDIT and this >The time has come for Microsoft vulnerability disclosure communications to mute the marketers and let the security engineers do the talking instead. I found it funny to be honest

In this case it seems to have been fully-fledged lying, not just bullshit: Microsoft (told the researcher they) delayed releasing this patch so they could release a number of SMB-related fixes at once.

They might have good reasons for doing that, but it isn't true to say they "proactively update impacted devices as soon as possible".

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#43
post #35

Earlier quoted context omitted.

> so he's causing microsoft and USERS problems they didn't have before. He's not causing problems, he's solving them.

Gifting exploiters a 0day before the KNOWN patch release date, is causing problems.

No, it was only a 0day before he made it public. He is merely providing security-conscious persons information and a way to defend themselves from an exploit which MS has not fixed. He is turning a 0day into a known vuln.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#44
post #29

Earlier quoted context omitted.

Well, if MS claims the patch is coming in one week, one approach might be to wait one week and then release the exploit. Works out regardless of the accuracy of the claim.

Patch Tuesday is the second Tuesday of each month. Unless something odd happens, you can count on the fix being out a week from tomorrow. There's also a justification for this — they sat on it because they were releasing other SMB-related patches on the February Patch Tuesday. I don't really think anybody can reasonably argue that MS would not release the fix next week. But that's not the point. This bug was reported…

Sure, if MS promised to issue a patch in January, then go ahead and release info when they don't. But it's weird to wait for a February patch, and then release a week early.

Like I'm more or less ok with "full disclosure upon discovery" as a consistent release policy. Or "wait for a patch up to 90 days". Or several other models. "Wait until one week before patch" is an oddball policy which seems like it has all the cons and none of the pros of other models.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#45

Earlier quoted context omitted.

MS is acting 'totally unethically' by not patching this bug immediately and rewarding the researcher.

Meh. The bug requires you to connect Windows to a malicious SMB server. Now that everybody knows that, if anybody is really concerned, they can stop SMB connections from LAN to WAN by blocking TCP 139, 445 and UDP 137, 138.

> Now that everybody knows that

Wait, when did everyone become aware of that? I'm willing to bet the vast majority of windows users have no idea. _Some_ people only know _because_ he released the bug.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#46
post #12
post #6

He asked a PR person, probably one with little security background (how many security people do you know who went into PR?) gave the stock answer which does happen to actually be good security advice: run the latest supported version with patches. The reporter was just butthurt about not getting a scoop and decided to write an article complaining about PR practices in place of an actual story. Really like the click b…

It's a rant about PR bullshit, specifically this: >Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible, EDIT and this >The time has come for Microsoft vulnerability disclosure communications to mute the marketers and let the security engineers do the talking instead. I found it funny to be honest

Microsoft always seems to prefer going on offense rather than playing defense. They are one of the least self-aware companies I can think of. For example, this absolutely insane "funeral march" for iPhone and Blackberry they held in 2010 to celebrate the launch of Windows Phone 7 [1]. What other company would even consider this?

[1] https://www.engadget.com/2010/09/10/microsoft-celebrates-win...

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#47

Does anybody know how many days it would take from when a critical security bug is discovered in Windows and assuming that the fix is just a few lines of code and not a component rewrite and marketing is not in the way, I am wondering how many steps are from when a fix is created until is released.(I imagine that there may some QA and some managers that need to approve it but I have no idea)

Disclosure: I work at MS but not on the kernel or anything related to this security bug. Opinions are my own. I've seen one-line bug fixes introduce many other bugs. Adding a null check is always suspicious. Is the system in an invalid state? Should it fail fast instead of swallowing the error? Maybe the code wasn't touched in several years. Maybe the person that wrote it no longer works there. Maybe the code in ques…

Maybe the person that wrote it no longer works there. Maybe the code in question doesn't have good test coverage or documentation

These are not valid excuses for a company the size of Microsoft.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#48
post #47

Earlier quoted context omitted.

Disclosure: I work at MS but not on the kernel or anything related to this security bug. Opinions are my own. I've seen one-line bug fixes introduce many other bugs. Adding a null check is always suspicious. Is the system in an invalid state? Should it fail fast instead of swallowing the error? Maybe the code wasn't touched in several years. Maybe the person that wrote it no longer works there. Maybe the code in ques…

Maybe the person that wrote it no longer works there. Maybe the code in question doesn't have good test coverage or documentation These are not valid excuses for a company the size of Microsoft.

These are the kind of consideration only companies the size of Microsoft are likely to have.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#49

Earlier quoted context omitted.

Meh. The bug requires you to connect Windows to a malicious SMB server. Now that everybody knows that, if anybody is really concerned, they can stop SMB connections from LAN to WAN by blocking TCP 139, 445 and UDP 137, 138.

> Now that everybody knows that Wait, when did everyone become aware of that? I'm willing to bet the vast majority of windows users have no idea. _Some_ people only know _because_ he released the bug.

I'm now aware, and I was able to block connections in my organizations firewall that protects a few thousand users. Not every single user needs to be aware for it to be effective.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#50
post #29

Earlier quoted context omitted.

Patch Tuesday is the second Tuesday of each month. Unless something odd happens, you can count on the fix being out a week from tomorrow. There's also a justification for this — they sat on it because they were releasing other SMB-related patches on the February Patch Tuesday. I don't really think anybody can reasonably argue that MS would not release the fix next week. But that's not the point. This bug was reported…

Sure, if MS promised to issue a patch in January, then go ahead and release info when they don't. But it's weird to wait for a February patch, and then release a week early. Like I'm more or less ok with "full disclosure upon discovery" as a consistent release policy. Or "wait for a patch up to 90 days". Or several other models. "Wait until one week before patch" is an oddball policy which seems like it has all the c…

Releasing a week early makes for a smallish window during which the exploit is unpatched and in the wild, while still being impactful enough that it forces Microsoft to react to it somehow. I'm not sure it's the Right Way of Doing Things, but it's defensible.
Post reply on HN