Live data from Hacker News

Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

thenextweb.com

91–100 of 137 posts

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#91

Earlier quoted context omitted.

Every time I join the YouTube HTML5 trial it gets silently turned off and videos start playing in Flash again a week or two later. Does that happen to anyone else?

Yes! I have turned that on many times and I always end up watching flash videos again. I wonder if it had to do with my session cookie expiring. Does anyone know how they toggle this experiment on/off for different users?

I'm in the beta, I've never had to rejoin. Possibly because I'm logged into my Google account, which is linked to my Youtube account. Note that some Youtube videos are still delivered as Flash, I believe is whenever adverts are shown.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#92

Earlier quoted context omitted.

Jan 15, 2002 email from Bill Gates to all MSFT staff [1]. Includes some real gems, like; >So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve. 1. http://www.wired.com/techbiz/media/news/2002/01/49826

I was hugely impressed by Bill when I read that memo, I checked with my friends who worked there to see if it was 'real' or a PR stunt, and they universally agreed it was very very real. I suspect Google is about to be tested in this way given the adoption of Android on mobile devices. It is fortunate that they have a strong security culture to begin with but nothing proves that like being battle tested.

Google isn't the first company that would come to my mind. I'd rather go for Apple. Their mobile ecosystem might be a lot more secure than Android's, but the way they acknowledge OSX vulnerabilities and how soon they fix them is a weak spot.

Oracle with Java could also get a lot of heat.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#93

Haha. Great to see iTunes and QuickTime (Windows versions, probably?) on the list... Apple should really either update them (I'm not sure iTunes 11 will be released for windows too) , or just abandon them (and ask customers to use iCloud for backup). A few days ago I opened a .mov on a Windows machine with QuickTime - it was horrible. I can't imagine how dreadful iTunes probably is. No wonder all PC guys hate iTunes.…

I hate iTunes on every platform. It's bloated; it tries to do too many things and it does them all wrong. Just as an example, searching for anything with iTunes is a horrible experience, particularly when compared with searching the 'net with any of the top search engines. Book, app and media management are terrible. Cross-computer management of the same is terrible. Backing-up your iPhone, if you are not careful, ca…

I hate iTunes too for all of the reasons mentioned above, however there's one thing it does at least half-ok'ish:

It doesn't eat a ton of CPU while playing a few simple MP3s...

I've tried using Clementine (an Amarok-fork, my favourite music-player by far, at least on Linux) but it's just a resource-hog - comparatively at least.

So yeah - does anyone have suggestions on what to use for music playback? Something that doesn't suck? Something that doesn't waste precious CPU-cycles without reason, generating heat and wasting battery on the go?

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#94

Not one Microsoft product on top 10 vulnerabilities affecting Microsoft operating system.

That is a more significant finding!

Dropping out of the overall top ten may have little or nothing to do with better security since the calculation is intentionally skewed to measure by number of affected users.

MS bugs got raised to the top in a desktop dominant world, but they've lost ground (and therefore importance in this calculation) against mobile/tablet/etc devices making the most successful cross platform products capable of affecting more users.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#95
post #92

Earlier quoted context omitted.

I was hugely impressed by Bill when I read that memo, I checked with my friends who worked there to see if it was 'real' or a PR stunt, and they universally agreed it was very very real. I suspect Google is about to be tested in this way given the adoption of Android on mobile devices. It is fortunate that they have a strong security culture to begin with but nothing proves that like being battle tested.

Google isn't the first company that would come to my mind. I'd rather go for Apple. Their mobile ecosystem might be a lot more secure than Android's, but the way they acknowledge OSX vulnerabilities and how soon they fix them is a weak spot. Oracle with Java could also get a lot of heat.

Apple regularly loses security shootouts, and is widely derided by security people. Their only advantages are their niche status (which they are losing) and their lack of consideration towards old apps (they can dump old APIs which are hard to secure, and make other backwards-incompatible fixes, because they just don't care that much about backwards compatibility).

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#96

Earlier quoted context omitted.

I hate iTunes on every platform. It's bloated; it tries to do too many things and it does them all wrong. Just as an example, searching for anything with iTunes is a horrible experience, particularly when compared with searching the 'net with any of the top search engines. Book, app and media management are terrible. Cross-computer management of the same is terrible. Backing-up your iPhone, if you are not careful, ca…

I hate iTunes too for all of the reasons mentioned above, however there's one thing it does at least half-ok'ish: It doesn't eat a ton of CPU while playing a few simple MP3s... I've tried using Clementine (an Amarok-fork, my favourite music-player by far, at least on Linux) but it's just a resource-hog - comparatively at least. So yeah - does anyone have suggestions on what to use for music playback? Something that d…

I've been using http://www.foobar2000.org/ for almost 10 years now. Though most of my music now is in the cloud, I always keep a heavily modded version of fb2k on my PC.

This is BY FAR the best audio player available.

I had some respect for Amarok when I was on KDE 6-7 years ago. Nowhere close to fb2k though. Nowadays on Linux I prefer just plain old mpd.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#97

Ah Shockwave, good to see you again my old friend. I can't believe it's still around and kicking, given the last release of Director seems to be about two years ago. I don't play any online games, but can somebody vouch for whether it is still used to develop browser games anymore?

AFAIK its only advantage was 3D authoring support, and Flash has that too now, so I see no reason to continue using it at all.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#98
post #2

It's actually this bit from farther down that surprised me the most: > 56 percent of exploits blocked in Q3 use Java vulnerabilities. So much for the idea of a managed language runtime being inherently more secure...

So the question remains - how best to run Java on a Windows machine and minimise your risk? I've got Win7/64, service packs up to date, java autoinstaller thing....what else can I do?

Set your browser to never auto-launch plugins, but require click to play.

If you're not already using ad-block, you will be amazed by how much it improves the performance of your general internet-surfing. So, besides security mindedness, there are already other good reasons for doing it.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#99

If you're running Chrome please for the love of all that is holy enable Click-To-Play for all plugins. With it disabled it is like running without a pop-up blocker. You can do so in Settings -> Advanced Settings -> Content Settings -> Plug-Ins -> Click To Play. When you visit a site which has a plug-in you'll get a UI control similar to the pop-up blocker which allows you to add it to the exceptions list and or to al…

Or better yet, switch YouTube to the HTML5 player: http://www.youtube.com/html5 One less site that needs Flash.

HTML5 videos on YT start automatically, which is exactly what I don't want, and in fact the second-biggest reason I use click-to-flash (first being animated ads). At one point, I was being forcibly opted into HTML5 video on YT and had to disable that feature in Firefox to get back out of it.
Post reply on HN