Live data from Hacker News

The Microsoft Update mechanism has been used to spread malware

f-secure.com

61–64 of 64 posts

Re: The Microsoft Update mechanism has been used to spread malware

#61
post #51

Earlier quoted context omitted.

I agree with you that they are not necessarily removing developers from other projects to work on licensing. However, a percentage of code in Windows is dedicated to validating licensing and preventing piracy. > In fact, there is no company or software community anywhere that writes highly complex and bug free software. It's not possible. I agree with this point. For this reason, the point I'm trying to make is that…

But having updates cryptographically signed and checked against a list of (presumably) trusted certificates is in my best interest. The "bug" here was in key management, not in SW that's running in my computer.

I shouldn't have used the word "certificate." What I meant was "license."

The code that caused the certificate chain to be compromised is related to licensing Terminal Services on Windows Server. That is how their key management failed, and that is what I'm railing against--The fact that this ability to sign binaries with a legitimate Microsoft certificate has been hidden away in copies of Windows Server for years by mistake. And not for any direct customer benefit, but to employ a licensing scheme.

Re: The Microsoft Update mechanism has been used to spread malware

#62
post #47

Earlier quoted context omitted.

But my point is that more teams needed access to signing keys because some of those teams were dedicated only to licensing issues. If they didn't need signing keys, those keys wouldn't have been compromised. I suppose I can break it down another way. Complexity introduces vulnerabilities. Some complexity is necessary for the software to accomplish what the customer wants. Some complexity is arguably necessary to prot…

> But my point is that more teams needed access to signing keys because some of those teams were dedicated only to licensing issues. If they didn't need signing keys, those keys wouldn't have been compromised. Cryptographically signed binaries are not used to manage licensing issues, they are used to make sure that no-one intercepts your download and replaces it with a malicious binary. It is absolutely essential tha…

The issue was that Microsoft left behind the ability to sign code with a Microsoft certificate by mistake.

The entire reason the attackers could use the certificate was because Microsoft left behind that functionality in the suite of software that allows enterprise customers to license their instances of Terminal Servers.

I am not railing against cryptographic signing as a concept -- what happened was Microsoft played fast and loose with their certificate chain in order to provide their customers with a way to prove that they had paid for software.

The certificate chain could have been a lot cleaner if that licensing bit wasn't necessary.

Re: The Microsoft Update mechanism has been used to spread malware

#63
post #50

Earlier quoted context omitted.

Oh yeah, sure, blame it on the Belgians!

Fellow Belgian here, our ancestors had been naive... Our main line of defense, the fort d'Ében-Émael , had been built by German workers. The German army had their plans, and knew the weak point of the fort: its vast, undefended roof (it was used as a football field by the soldiers). During a dark night, they landed with gliders on the roof, and manually set up shaped charges[1] to destroy the turrets, which were resi…

I'd be willing to bet some young combat engineer said "but what about the roof?" and some old general replied "you'll never get a horse up there!".

Re: The Microsoft Update mechanism has been used to spread malware

#64
post #63
post #50

Earlier quoted context omitted.

Fellow Belgian here, our ancestors had been naive... Our main line of defense, the fort d'Ében-Émael , had been built by German workers. The German army had their plans, and knew the weak point of the fort: its vast, undefended roof (it was used as a football field by the soldiers). During a dark night, they landed with gliders on the roof, and manually set up shaped charges[1] to destroy the turrets, which were resi…

I'd be willing to bet some young combat engineer said "but what about the roof?" and some old general replied "you'll never get a horse up there!".

It's worse than that.

The roof should have been mined, but the soldiers petitioned the hierarchy to keep their sports field...

Post reply on HN