Earlier quoted context omitted.
Even assuming that, there could be a massive testing load to ensure that those few lines of code don't mess up something tangentially related, or cause new security issues of their own.
Assuming you just need to add a check for null pointer and that this bug is very critical like hackers are exploiting it, assume engineers create a fix and are 100% it is safe, hopefully there was no other component that was depending on the broken code , how much it will take to fix it, maybe there is somewhere a history of critical bugs , with the date of when it was found and when it was fixed then we can find the…
Windows 10 0day exploit goes wild, and so do Microsoft marketers
51–60 of 78 posts
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#52tl;dr: a null deref in windows kernel when you connect to a malicious SMB share
PoC GIF: https://twitter.com/vvalien1/status/826935182456418304
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#53Earlier quoted context omitted.
> Now that everybody knows that Wait, when did everyone become aware of that? I'm willing to bet the vast majority of windows users have no idea. _Some_ people only know _because_ he released the bug.
I'm now aware, and I was able to block connections in my organizations firewall that protects a few thousand users. Not every single user needs to be aware for it to be effective.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#54The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
> They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before.
Not in the slightest. You do not understand how the internet works. The vulnerable systems were vulnerable yesterday, and are vulnerable today because MS didn't think it was worth hurrying to patch them. Users' harm was caused by Microsoft who gave them a broken product, and by any hypothetical hackers, not by a security researcher telling the public what the hackers probably already knew.
Microsoft had a chance to release an emergency bulletin as soon as they were informed of the vuln, with mitigation steps. (ie, block SMB, etc) They didn't, and in fact spent time recommending useless things (Win10, Edge) that only serve to slander competitors by implication, and pimp more of their products.
Microsoft needs the understand that the new timeframe for releasing mitigations, if not patches, is closer to 24h than 24 days. But even if they hit that metric, they don't deserve any fanfare until they do it without lying or misdirecting.
Downvoters: RTFA - The Microsoft reports are intentionally misleading wrt. steps customers need to follow to be safe, and they claim to be better that their competitors (Apple, etc) in this regard despite obvious and consistent proof to the contrary. Microsoft is responding to security concerns with marketing speak, and they're knowingly setting their customers up for catastrophic data loss or hacks by recommending useless fixes.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#55Earlier quoted context omitted.
There are very competent people on this planet who make a very good buck out of zero-days (not to mention remotely control users' machines, and steal data). IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is…
Just because there are other people who act totally unethically doesn't mean you get bonus points for doing kinda the right thing.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#56The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
Microsoft has sat on bugs for years saying they were working on them. Do you disclose after a week? A Month? a Year?
If it were a company or team with a solid history of patching swiftly I could see trusting them. But this is Microsoft, they have the resources to fix bugs. They chose an OS design that sacrificed security for other things. Worst, they chose to betray trust in the past. Someday Microsoft might earn that trust back, but they are a long way off from earning mine.
If I informed them of the bug and it wasn't fixed in the next patch, then I would need solid evidence they are working on it or I release the exploit. If it were a group I trusted I would follow up several times until I lost faith in them.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#57Earlier quoted context omitted.
Just because there are other people who act totally unethically doesn't mean you get bonus points for doing kinda the right thing.
You're absolutely right! The researcher acted in a questionably ethical manner here by waiting to disclose the vulnerability. The only ethical approach is full and immediate public disclosure.
The last thing I'd want as a developer or a manager is to wake up in the morning with a PR shit storm and angry users on my hands because some inane script kiddie found it appropriate to disclose a zero day without reaching out to me or my team first. Sure, some other guy might know about or find the vulnerability and exploit it by the time a patch comes out; it's guaranteed that they will if you release a 0day.
We can discuss all we want on what a reasonable delay to release a patch might be, but absolutely not on the notion that immediate public disclosure is the right thing to do. It wastes everyone' time, disrupts workflows, puts fellow developers, their managers, and their users under intense pressure and stress, all so some kid can enjoy an ego trip. To me it just seems gross and childish.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#58Earlier quoted context omitted.
Well, if MS claims the patch is coming in one week, one approach might be to wait one week and then release the exploit. Works out regardless of the accuracy of the claim.
Patch Tuesday is the second Tuesday of each month. Unless something odd happens, you can count on the fix being out a week from tomorrow. There's also a justification for this — they sat on it because they were releasing other SMB-related patches on the February Patch Tuesday. I don't really think anybody can reasonably argue that MS would not release the fix next week. But that's not the point. This bug was reported…
Do you know that, it is it just speculation? I could speculate that there were technical reasons around having two smb patchsets to test in various combinations vs bundling into one.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#59Earlier quoted context omitted.
You're absolutely right! The researcher acted in a questionably ethical manner here by waiting to disclose the vulnerability. The only ethical approach is full and immediate public disclosure.
Full and immediate public disclosure seems irresponsible and counterproductive IMO. The last thing I'd want as a developer or a manager is to wake up in the morning with a PR shit storm and angry users on my hands because some inane script kiddie found it appropriate to disclose a zero day without reaching out to me or my team first. Sure, some other guy might know about or find the vulnerability and exploit it by th…
What full disclosure does it put everyone on the same footing. Developers, users, and attackers all at once. It reduces the window for potential abuse as much as possible. As policy, it sharpens the incentives to be very careful in your development processes and improve security measures.
It's worth considering that this is actually a long-running historical debate. One of the commonly espoused positions is yours - contact devs privately, give them a reasonable amount of time to patch, then disclose after a patch. After all, it minimizes disruption to production planning and workflows and still protects users. Seems reasonable right? Everyone wins!
Catch is, it's historically been abused by companies more interested in their production schedules than the security of their users. Maybe that's not you! In which case, well done, you're completely awesome! However, this has historically turned out to be rather a lot of software companies.
Full disclosure, the policy I advocated for, seeks to short-circuit this. It offers maximum information to a maximum of people in a minimum of time. It pressures companies to fix their products rapidly and to ship better products in the first place. It also offers users the ability to be aware that they may be under attack and protect themselves in lieu of a patch which may or may not ever come into being.
At the end of the day, the question is this: who are you protecting with your disclosure policy? I would suggest that the policy you have advanced seeks to balance the interests of users and of developers/managers. It's perhaps worth considering that your users may prefer a policy that aligns your incentives more with theirs. Perhaps your customers might prefer policies that encourage a proactive stance.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#60Earlier quoted context omitted.
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
And when Microsoft do cut QA short people complain that Microsoft doesn't care about quality/is using retail as a beta test. It is really a no-win situation to be honest.
It's only unwinable because Microsoft refuses to take a PR/cash hit of telling people to stop using something while it's broken.