> Asked if Microsoft had previously fuzzed the Windows Defender component, a company representative said yes. > "Fuzzing is one of a number of techniques we employ to update and strengthen our software," the representative said in an e-mail. "It is a standard practice we use as part of the Security Development Lifecyle for our products." This journalist is naive. This answer says "sure we use fuzzing, but we have no…
That's awfully cynical. The answer they got is more indicative of the fact that they're talking to a representative rather than one of the engineers who would have actually been responsible for fuzzing it, so all the representative can really do is say what the policy is rather than answer the specific question of "was this particular component fuzzed"?
Re: A Windows Defender bug was so gaping its PoC exploit had to be encrypted
#41A good PR representative doesn't want to get caught flat-footed, and usually gets all the information they need from inside sources so that they can bullshit properly without (accidentally) misleading the public and causing the company legal trouble. Microsoft can afford good PR staff. If they didn't say yes, than the answer is probably no.