Microsoft should hire this programmer: https://i.redd.it/sd72mfmj7ety.jpg
Hackers exploited Word flaw for months while Microsoft investigated
41–50 of 105 posts
Re: Hackers exploited Word flaw for months while Microsoft investigated
#42Earlier quoted context omitted.
Not sure why you're down voted. I had the same thought as parent, but this seems like the answer. A standard splash screen on load that pops up for 10 seconds and says "this program has known active vulnerabilities that are unpatched". If people choose to ignore it, that's on them. Cheap and easy, no?
That still requires that a third party is allowed to flash things on my screen without my explicit consent.
We already have a solution to this, which I hate: walled gardens. I'm exploring options that preserve the peace while not letting companies effectively own their users.
Maybe there is no answer that makes everybody happy. That's why it's worth asking questions.
Just so I understand this, you're saying that if you have a piece of hardware that's say, taking down the local ISP because you're running compromised software on it, you don't want to even be notified before your box is compromised or that there might be a problem.
Well, dang. Something's going to happen. That much is sure. What's the first notification you'd like that you're destroying the internet experience for others and perhaps ruining a local business? SWAT team at the door?
I hear your complaint. I'm just not able to figure out how it makes sense.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#43Earlier quoted context omitted.
I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…
> Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). Really? You mention in another thread, you used Ubuntu. So you apparently didn't notice this [0] or this [1]? The issue with this and complexity, is that login screen resolution is often handled by GRUB, not Linux. Edit: In future you can drop into a commandline via Ctrl+Alt+F1 > Secondary drives require manual mounting (…
Neither of those solutions are user friendly are they?. You think an average person knows what grub is? I did come across the second one actually, but I have no idea if the solution is still relevant or not. I haven't seen anything to indicate what login manager I'm even running, where is this information displayed?
I'm talking about kdm/gdm or whatever is installed these days.
> If it's an internal drive, try gnome-volume-manager and it's a tickbox away. (Which is on quite a few distros by default).
It's there and configured to mount at startup. I keep most of my steam games on there. But if I log in and start up steam all the games are missing. If I navigate to the drive through the file manager and then start steam then it will find them properly. I have no idea what's going on but it doesn't appear to be mounting the drive at startup.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#44Earlier quoted context omitted.
I find they still fail a lot of the time. Some issue's I've come across recently: * no UI scaling for hi res. Sure you can change it manually, but you have to be able to read the login screen to get that far. * Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). * Default is to max resolution available (I'd say 1080p is a more sensible default, especially if there is no auto…
> Can't change login screen resolution (haven't seen a way to do this on any distro I've tried). Really? You mention in another thread, you used Ubuntu. So you apparently didn't notice this [0] or this [1]? The issue with this and complexity, is that login screen resolution is often handled by GRUB, not Linux. Edit: In future you can drop into a commandline via Ctrl+Alt+F1 > Secondary drives require manual mounting (…
Re: Hackers exploited Word flaw for months while Microsoft investigated
#45I thought that it is the norm for M$ to hand out the zero-days to the 3-letter-agencies for "a while" and patches them ONLY when someone else gets hold and starts using the same vuln.. so it makes PERFECT sense that they would do something like that. Also who in their right mind allow Word/Excel/Powerpoint to access the internet? (oh yes it's called "365" and it makes software, that is completely unfit for the task,…
Not sure why you're being downvoted. This is literally the company that built in "_NSAKEY" into the kernel, which is still present (just called "_KEY2" now.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#46In their monthly update, couldn't Microsoft have released a patch to have this setting to the correct configuration? Of course this would only be the short term solution, rather than waiting for 9 months for the permanent solution.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#47Re: Hackers exploited Word flaw for months while Microsoft investigated
#48Earlier quoted context omitted.
Pure nonsense. Or did you try a distribution from 2002?
Ubuntu 17.04. Is that recent enough for you? I've tried antergos, red hat and a couple of others, all with similar issues. Many I didn't get far with because I simply couldn't read the login screen. Antergos doesn't even have user switching working out of the box but it was the only one that supported my graphics card until very recently. I used the gnome variant of each.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#49We need civil penalties for failing to patch any serious vulnerability (that can be defined as RCE, priv. escalation, etc) within 30 days of disclosure. If you can't patch it, you must issue a patch that announces the vuln and disables the minimal set of functionality that enables it. Even if that's the whole program.
So, turn a nontrivial set of vulns into successful DoS attacks?
Re: Hackers exploited Word flaw for months while Microsoft investigated
#50And _this_, ladies and gentlemen, is why we have disclosure deadlines for security vulnerabilities. For example, Project Zero expects vendors to fix security vulnerabilities within 90 days of notification. Looking at this story, it's possible that 90 days is almost too long and should be shortened. As time goes on, it's becoming more and more common for multiple parties to become aware of the same vulnerabilities. No…
Next up on HN: extreme outrage after a botched security update breaks hundreds of millions of machines. Not all bugs can be fixed with a simple one-line fix, and the faster patches need to be cranked out, the lower quality they'll be.