Live data from Hacker News

Security Update for Microsoft Malware Protection Engine

technet.microsoft.com

81–85 of 85 posts

Re: Security Update for Microsoft Malware Protection Engine

#81
post #72

Earlier quoted context omitted.

How is that different from pointing out a name like Microsoft? Either way, it might be uncouth, but I don't see the connection to responsible disclosure.

It's not me that is having a problem with this, I'm just pointing out why some people are having problems with Tavis in general. You don't think it is reasonable to at least tell a vendor there is a security problem first before telling the rest of the world? Maybe responsible disclosure is the wrong name for this, I like the coordinated disclosure idea better. Maybe I am using the wrong terms but I cannot edit my po…

I think it's reasonable to tell the vendor first. I don't think it's reasonable to freak out about a general, detail-free announcement, and especially not with "omg there goes my weekend" and "you're helping the bad guys" nonsense.

The mere announcement of the existence of a bug, with little enough detail that it won't help anyone find it (i.e. "RCE in Windows" is useless), does no practical harm. It might be a bit rude.

It's the announcement of details that help people find the bug that hurts. If the original announcement was "RCE in Windows due to type error in malware protection JavaScript interpreter" then that would potentially help bad guys put together an exploit before good guys can release a patch.

Stuff like responsible disclosure (coordinated disclosure would be a fine term too) is about the second one, only, as far as I understand it. It's about mitigating the practical effects of the vulnerability as much as possible, not about protecting the reputation of the company or avoiding rudeness.

Re: Security Update for Microsoft Malware Protection Engine

#82
post #62

Earlier quoted context omitted.

Not sure about millions but many do have update for Windows turned off, due to Microsoft's security-trust-destroying habit of deploying invasive and undesired non-security updates automatically. Windows 10 especially has a nasty streak with updates, and while security updates are smart, forcing new content updates, advertisements, and spyware into the Tuesday fast track teaches users that the only way to be safe from…

File this one under "play stupid games - win stupid prizes". Idiots like this are why Windows updates are completely forced in the first place. A couple generations of "experts" knew better and refused to let Windows update. Then billions of dollars were lost cleaning up worms that had already been patched, but people kept canceling the update dialog. See SqlSlammer, CodeRed, etc. You had your chance to handle your o…

Yes, if one wants safety, one got to be unsafe regarding the company who provides the infrastructure one paid for. One either has Internal-Adds or Internet-Aids. Or both.

One could of course get tarred and feathered until one looks like a penguin - but hey, who is that desperate. Lets ask that question again, the day such a exploit is rolled out world wide with a patch on his back.

Funny times.

Microsoft recommends for all HN Readers: Spam musubi - buy the delicious Hawaian delacay now. In a store near you! Get a free sample with this Coupon-Code: 0xDEADBEEF

Re: Security Update for Microsoft Malware Protection Engine

#83

Earlier quoted context omitted.

I know comparatively little about this stuff, so please excuse the question if it's dumb... If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit? My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.

This is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion? I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions. In the tech world, this seems unique to security. For example, none of…

Because we all have potatos in the fire and are afraid of the guy with the gasoline canister dancing in circles.

Its just something you learn real fast if you Dev. Producing something, like a Ming-Vase is really hard. Shooting a Ming-vase to smithereens is really easy (ask your Son/Daughter for indoor soccer-practice).

So yeah, you are allowed to have a opinion on things you dont know about, but that your live/livestock depends on. Everyone gets to vote on police work without ever doing a degree in CSI.

Re: Security Update for Microsoft Malware Protection Engine

#84

Earlier quoted context omitted.

This is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion? I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions. In the tech world, this seems unique to security. For example, none of…

Because we all have potatos in the fire and are afraid of the guy with the gasoline canister dancing in circles. Its just something you learn real fast if you Dev. Producing something, like a Ming-Vase is really hard. Shooting a Ming-vase to smithereens is really easy (ask your Son/Daughter for indoor soccer-practice). So yeah, you are allowed to have a opinion on things you dont know about, but that your live/livest…

Have you paid attention to these exploits the they produce? They're often not "easy". Also, if they are, that's the dev's fault, not theirs. Shooting the messenger to avoid responsibility, it never gets old...

Re: Security Update for Microsoft Malware Protection Engine

#85
post #62

Earlier quoted context omitted.

Not sure about millions but many do have update for Windows turned off, due to Microsoft's security-trust-destroying habit of deploying invasive and undesired non-security updates automatically. Windows 10 especially has a nasty streak with updates, and while security updates are smart, forcing new content updates, advertisements, and spyware into the Tuesday fast track teaches users that the only way to be safe from…

File this one under "play stupid games - win stupid prizes". Idiots like this are why Windows updates are completely forced in the first place. A couple generations of "experts" knew better and refused to let Windows update. Then billions of dollars were lost cleaning up worms that had already been patched, but people kept canceling the update dialog. See SqlSlammer, CodeRed, etc. You had your chance to handle your o…

"You had your chance to handle your own updates and proved that you cannot be trusted to do so. This is the next logical step."

Personally, I would describe the user voluntarily allowing their computer to become infested with first party adware and spyware as winning the stupid prize, but your mileage may vary.

Post reply on HN