Live data from Hacker News

Windows 10 0day exploit goes wild, and so do Microsoft marketers

arstechnica.com

61–70 of 78 posts

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#61
post #29

Earlier quoted context omitted.

Patch Tuesday is the second Tuesday of each month. Unless something odd happens, you can count on the fix being out a week from tomorrow. There's also a justification for this — they sat on it because they were releasing other SMB-related patches on the February Patch Tuesday. I don't really think anybody can reasonably argue that MS would not release the fix next week. But that's not the point. This bug was reported…

They chose to withhold that patch due to non-technical, apparently PR-related, reasons Do you know that, it is it just speculation? I could speculate that there were technical reasons around having two smb patchsets to test in various combinations vs bundling into one.

The cynical answer would be: try harder Microsoft, and do not let your customers remain vulnerable simply because you can't test two patch-sets at the same time.

If 'trying harder' is not possible due to financial reasons, then the only recourse is disclosure.

This bug will be fixed now, but certainly could have been excluded again because of technical reasons---they're publishing a separate set of patches on SMB again soon, maybe those patches have higher priority to people on the Microsoft org-chart than the patches for this bug.

When companies aren't given hard deadlines for disclosure, they'll just delay forever because there is always a technical reason that you can't do enough testing to satisfy yourself, while doing X, Y, Z which are added to your schedule for political/financial reasons.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#62
post #55

Earlier quoted context omitted.

You're absolutely right! The researcher acted in a questionably ethical manner here by waiting to disclose the vulnerability. The only ethical approach is full and immediate public disclosure.

Full and immediate public disclosure seems irresponsible and counterproductive IMO. The last thing I'd want as a developer or a manager is to wake up in the morning with a PR shit storm and angry users on my hands because some inane script kiddie found it appropriate to disclose a zero day without reaching out to me or my team first. Sure, some other guy might know about or find the vulnerability and exploit it by th…

> It wastes everyone' time, disrupts workflows, puts fellow developers, their managers, and their users under intense pressure and stress, all so some kid can enjoy an ego trip.

The users were put under stress when Microsoft knowingly released false statements about the bug's scope and possible mitigations.

As for the devs, they're paid anyways, and adjusting workflows is literally a manager's job. They aren't harmed in the slightest, and it wouldn't be relevant if they were because they're the ones releasing the buggy products. Market feedback is a good thing.

> To me it just seems gross and childish.

Are you employed by MS, or do you own significant amounts of stock? Because from the PoV of someone who supports many of their customers (though indirectly) our feeling is exactly the opposite.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#63
post #29

Earlier quoted context omitted.

Patch Tuesday is the second Tuesday of each month. Unless something odd happens, you can count on the fix being out a week from tomorrow. There's also a justification for this — they sat on it because they were releasing other SMB-related patches on the February Patch Tuesday. I don't really think anybody can reasonably argue that MS would not release the fix next week. But that's not the point. This bug was reported…

They chose to withhold that patch due to non-technical, apparently PR-related, reasons Do you know that, it is it just speculation? I could speculate that there were technical reasons around having two smb patchsets to test in various combinations vs bundling into one.

Why do they deserve the benefit of the doubt when their press release contains actual lies? When someone lies to me everything they say becomes suspect. It's the standard we expect individuals to live up to, why do you want to give more slack to a company?

Further, so what? There's always some problem. They should either suck it up and work harder or come clean and give users actual choice in how to respond.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#64

Earlier quoted context omitted.

They chose to withhold that patch due to non-technical, apparently PR-related, reasons Do you know that, it is it just speculation? I could speculate that there were technical reasons around having two smb patchsets to test in various combinations vs bundling into one.

Why do they deserve the benefit of the doubt when their press release contains actual lies? When someone lies to me everything they say becomes suspect. It's the standard we expect individuals to live up to, why do you want to give more slack to a company? Further, so what? There's always some problem. They should either suck it up and work harder or come clean and give users actual choice in how to respond.

Why do they deserve the benefit of the doubt when their press release contains actual lies?

I didn't say they do. I responding to the parent post on the bit I quoted ("They chose..."). If it's irrelevant under other precondition, take it up with the parent post.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#65

Does anybody know how many days it would take from when a critical security bug is discovered in Windows and assuming that the fix is just a few lines of code and not a component rewrite and marketing is not in the way, I am wondering how many steps are from when a fix is created until is released.(I imagine that there may some QA and some managers that need to approve it but I have no idea)

They could have a solution out the door in less than 24h but it may be a mitigation (ie, disable the service) rather than a proper fix. But that's pretty easy. In fact, it's usually the first thing an engineer does when verifying a bug report - "Ok I've reproduced it, now let's shut off the service and make sure the problem goes away."

Release a patch that disables the vulnerable service and give people a way to bypass that and turn it back on once they've taken proper internal measures. (Read the CVE, block ports, etc...)

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#66
post #48
post #47

Earlier quoted context omitted.

Maybe the person that wrote it no longer works there. Maybe the code in question doesn't have good test coverage or documentation These are not valid excuses for a company the size of Microsoft.

These are the kind of consideration only companies the size of Microsoft are likely to have.

Touché!

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#67
> What is the threshold where you decide to release a bug description?

Absolute minimum: 1 month after patch.

Also: Leave 1 month, as an absolute minimum, to publish a patch.

Why that? Because it takes time to track a bug and fix it and test the fix and ship it to 1 billion consumers in 150 countries and languages.

Welcome to the world of real users where things take time to happen.

Of course, one may think that he's an idealistic enthusiast pressuring the evil big companies when giving them less time. But nope, the only thing one may truly accomplish is being an unrealistic asshole putting millions of computers and people at risk. Think twice before you disclose. There will also be your mom's computer on the other end of that 0-day ;)

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#68
post #59

Earlier quoted context omitted.

Full and immediate public disclosure seems irresponsible and counterproductive IMO. The last thing I'd want as a developer or a manager is to wake up in the morning with a PR shit storm and angry users on my hands because some inane script kiddie found it appropriate to disclose a zero day without reaching out to me or my team first. Sure, some other guy might know about or find the vulnerability and exploit it by th…

The last thing I'd want as a developer or manager is to wake up in the morning with a PR shitstorm and enraged users because I shipped some vuln. What full disclosure does it put everyone on the same footing. Developers, users, and attackers all at once. It reduces the window for potential abuse as much as possible. As policy, it sharpens the incentives to be very careful in your development processes and improve sec…

> It reduces the window for potential abuse as much as possible.

Immediate public disclosure to everyone, including blackhats, reduces the window for potential abuse as much as possible? Cynical answer: You are technically correct … It reduces the window of potential abuse to 0. While at the same time it opens the window for actual (guaranteed) abuse.

Generally speaking, immediate public disclosure is harmful to the very people you want to protect with the disclosure because they are left defenseless to hordes of intruders that, before the disclosure, probably didn’t even know about the issue. By “put[ting] everyone on the same footing”, the developers scramble to release something, anything, that kind of works to mitigate the situation which causes the software quality to suffer.

Even high quality software with careful developers will occasionally suffer from security vulnerabilities. You put every company and individual under general suspicion of misusing responsible disclosure, and by immediate public disclosure you want to get back at them for having a security issue in their software. You don’t care about protecting anyone.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#69
post #46
post #12

Earlier quoted context omitted.

It's a rant about PR bullshit, specifically this: >Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible, EDIT and this >The time has come for Microsoft vulnerability disclosure communications to mute the marketers and let the security engineers do the talking instead. I found it funny to be honest

Microsoft always seems to prefer going on offense rather than playing defense. They are one of the least self-aware companies I can think of. For example, this absolutely insane "funeral march" for iPhone and Blackberry they held in 2010 to celebrate the launch of Windows Phone 7 [1]. What other company would even consider this? [1] https://www.engadget.com/2010/09/10/microsoft-celebrates-win...

They are one of the least self-aware companies I can think of.

That was Uncle Fester's Microsoft. That behavior was an extension of Ballmer's pugilistic personality.

Today's Microsoft is just as tone-deaf, but in a different respect. For the life of me I can't understand why Nadella thinks that their recent behavior wrt. Win 10 is a good idea. E.g. rebooting user's machines during presentations, having spyware that it's not possible to disable, advertising in the OS, etc.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#70
post #21

Earlier quoted context omitted.

I am still shocked that Windows was recoverable from the fiasco of XP security problems. They have gotten exponentially better in security over the years.

The NT Kernel is a very secure and resilient design, it was just mucked up over the years with Win32 blurring the lines between the kernel and userland. MinWin was an internal project that started in Windows 7 where the tendrils of things like Win32 were extricated from the kernel. In addition to improving security, this also enabled things like multi-platform support and headless servers.

I understand what you're saying "in theory".

But in practice, here's what happened. In 2002 Chairman Bill said:

   An internal Microsoft e-mail tells the software
   giant's employees that security and privacy are
   the most important issues for the company's products.
https://www.cnet.com/news/gates-security-is-top-priority/

And yet, 15 years later, we're discussing yet another 0day. And Win 10's built in spyware is the absolute opposite of "privacy".

I'd rather judge Microsoft on their actual historical record, and not on whether Cutler's initial design for NT was secure and resilient.

Post reply on HN