Live data from Hacker News

Windows 10 0day exploit goes wild, and so do Microsoft marketers

arstechnica.com

71–78 of 78 posts

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#71
post #59

Earlier quoted context omitted.

The last thing I'd want as a developer or manager is to wake up in the morning with a PR shitstorm and enraged users because I shipped some vuln. What full disclosure does it put everyone on the same footing. Developers, users, and attackers all at once. It reduces the window for potential abuse as much as possible. As policy, it sharpens the incentives to be very careful in your development processes and improve sec…

> It reduces the window for potential abuse as much as possible. Immediate public disclosure to everyone, including blackhats, reduces the window for potential abuse as much as possible? Cynical answer: You are technically correct … It reduces the window of potential abuse to 0. While at the same time it opens the window for actual (guaranteed) abuse. Generally speaking, immediate public disclosure is harmful to the…

The key difference between before and after disclosure is that people are vulnerable and ignorant before, with no chance whatsoever to defend themselves. After disclosure, people are vulnerable and warned, with the potential to defend themselves. In both scenarios, there is the very real threat of attackers.

I care about protecting people. I hold the idiosyncratic belief that keeping secrets from the vulnerable does not make them safer. I understand that many people do not agree with this.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#72

Earlier quoted context omitted.

Full and immediate public disclosure seems irresponsible and counterproductive IMO. The last thing I'd want as a developer or a manager is to wake up in the morning with a PR shit storm and angry users on my hands because some inane script kiddie found it appropriate to disclose a zero day without reaching out to me or my team first. Sure, some other guy might know about or find the vulnerability and exploit it by th…

> It wastes everyone' time, disrupts workflows, puts fellow developers, their managers, and their users under intense pressure and stress, all so some kid can enjoy an ego trip. The users were put under stress when Microsoft knowingly released false statements about the bug's scope and possible mitigations. As for the devs, they're paid anyways, and adjusting workflows is literally a manager's job. They aren't harmed…

> Are you employed by MS, or do you own significant amounts of stock?

This sort of insinuation count as a personal attack and is off limits on HN, so please don't do it here.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#73
post #15

Earlier quoted context omitted.

The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.

You know who sounds really petty though? The whiners taking Microsoft's side despite them missing the bug in the first place and sleeping on the report, and now attacking the person who reported it. > They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. Not in the slightest. You do not understand how the internet works. The vulnerable systems wer…

> You do not understand how the internet works.

> Downvoters: RTFA

These things break the HN guidelines. Please (re-)read them and post civilly and substantively, or not at all:

https://news.ycombinator.com/newsguidelines.html

https://news.ycombinator.com/newswelcome.html

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#74
post #71

Earlier quoted context omitted.

> It reduces the window for potential abuse as much as possible. Immediate public disclosure to everyone, including blackhats, reduces the window for potential abuse as much as possible? Cynical answer: You are technically correct … It reduces the window of potential abuse to 0. While at the same time it opens the window for actual (guaranteed) abuse. Generally speaking, immediate public disclosure is harmful to the…

The key difference between before and after disclosure is that people are vulnerable and ignorant before, with no chance whatsoever to defend themselves. After disclosure, people are vulnerable and warned, with the potential to defend themselves. In both scenarios, there is the very real threat of attackers. I care about protecting people. I hold the idiosyncratic belief that keeping secrets from the vulnerable does…

> After disclosure, people are vulnerable and warned, with the potential to defend themselves.

Only in your wildest wet dreams are people able to defend themselves. You maybe, but certainly not random Joe down the street. And that's assuming Joe reads tech news to begin with.

The only people who this significantly affects in practice are a) the black hats who now have a window of opportunity to do mischief, and - much more importantly - b) the devs who end up needing to patch software under intense pressure.

But anyway, as you pointed out, it's been an ongoing debate for decades.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#75
post #15

The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…

The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.

They weren't patching, in this case the process has taken months. It's just marketing so they can say there's just a small number of bugs.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#76
post #71

Earlier quoted context omitted.

The key difference between before and after disclosure is that people are vulnerable and ignorant before, with no chance whatsoever to defend themselves. After disclosure, people are vulnerable and warned, with the potential to defend themselves. In both scenarios, there is the very real threat of attackers. I care about protecting people. I hold the idiosyncratic belief that keeping secrets from the vulnerable does…

> After disclosure, people are vulnerable and warned, with the potential to defend themselves. Only in your wildest wet dreams are people able to defend themselves. You maybe, but certainly not random Joe down the street. And that's assuming Joe reads tech news to begin with. The only people who this significantly affects in practice are a) the black hats who now have a window of opportunity to do mischief, and - muc…

It also affects professionals who read CVEs and posts to full-disclosures to learn that what mitigations are available. Those tend to be the people responsible for protecting whole networks, who are capable of deploying Snort signatures or roping off vulnerable boxes. Or just people who appreciate knowing that their servers might be vulnerable. I've been in a couple of those positions.

The standing assumption in security is that for any given vuln, the black hats already know. This is a defensive assumption, stemming both from the general unknowability of the subject and the frequent occurrences of it actually being demonstrably true. It's the devs who need to patch software under intense pressure, and the product organization that sets their priorities, and the growth hackers who just want things shipped now whose priorities could perhaps stand to gain from a little adjustment.

I've worked places where engineers would have welcomed that sort of outside pressure.

To put it another way, I do not believe that keeping people ignorant keeps them safe. I fully understand why some people might prefer to believe otherwise.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#77
post #71

Earlier quoted context omitted.

The key difference between before and after disclosure is that people are vulnerable and ignorant before, with no chance whatsoever to defend themselves. After disclosure, people are vulnerable and warned, with the potential to defend themselves. In both scenarios, there is the very real threat of attackers. I care about protecting people. I hold the idiosyncratic belief that keeping secrets from the vulnerable does…

> After disclosure, people are vulnerable and warned, with the potential to defend themselves. Only in your wildest wet dreams are people able to defend themselves. You maybe, but certainly not random Joe down the street. And that's assuming Joe reads tech news to begin with. The only people who this significantly affects in practice are a) the black hats who now have a window of opportunity to do mischief, and - muc…

If we're gonna be brutally realistic about human nature: most people won't budge if they are comfortable and maintain an illusion that things are under control, unless there's external pressure. I have no links to scientific studies but IMO that's common sense and is widely observable.

I too find the actions of the researcher slightly questionable but he himself said this isn't the first time and he's sick of important fixes being delayed.

You know what? It worked. You might disagree with the approach, but what about the results? MS is absolutely gonna release a fix now, there's no denying that.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#78

Earlier quoted context omitted.

Even assuming that, there could be a massive testing load to ensure that those few lines of code don't mess up something tangentially related, or cause new security issues of their own.

Assuming you just need to add a check for null pointer and that this bug is very critical like hackers are exploiting it, assume engineers create a fix and are 100% it is safe, hopefully there was no other component that was depending on the broken code , how much it will take to fix it, maybe there is somewhere a history of critical bugs , with the date of when it was found and when it was fixed then we can find the…

I've worked on software where without fail every new release would go through more than a week of soak testing.
Post reply on HN