Live data from Hacker News

Windows 10 0day exploit goes wild, and so do Microsoft marketers

arstechnica.com

1–10 of 78 posts

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#2
Does anybody know how many days it would take from when a critical security bug is discovered in Windows and assuming that the fix is just a few lines of code and not a component rewrite and marketing is not in the way, I am wondering how many steps are from when a fix is created until is released.(I imagine that there may some QA and some managers that need to approve it but I have no idea)

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#4

Does anybody know how many days it would take from when a critical security bug is discovered in Windows and assuming that the fix is just a few lines of code and not a component rewrite and marketing is not in the way, I am wondering how many steps are from when a fix is created until is released.(I imagine that there may some QA and some managers that need to approve it but I have no idea)

It depends. Some bugs can be fixed easily and some might be too complicate to fix even though it looks simple. Usually all critical bugs are attended as soon as they are created (few hours delay). But the actual fix depends on the bug and there is no general formula for that

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#6
He asked a PR person, probably one with little security background (how many security people do you know who went into PR?) gave the stock answer which does happen to actually be good security advice: run the latest supported version with patches.

The reporter was just butthurt about not getting a scoop and decided to write an article complaining about PR practices in place of an actual story.

Really like the click bait title though, it's a nice touch. /s

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#8

Does anybody know how many days it would take from when a critical security bug is discovered in Windows and assuming that the fix is just a few lines of code and not a component rewrite and marketing is not in the way, I am wondering how many steps are from when a fix is created until is released.(I imagine that there may some QA and some managers that need to approve it but I have no idea)

There is an interesting (and very amusing) article about the general concept:

    https://blogs.msdn.microsoft.com/ericlippert/2003/10/28/how-many-microsoft-employees-does-it-take-to-change-a-lightbulb
it doesn't directly answer the question, but things are far more complicated than they look.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#9
post #6

He asked a PR person, probably one with little security background (how many security people do you know who went into PR?) gave the stock answer which does happen to actually be good security advice: run the latest supported version with patches. The reporter was just butthurt about not getting a scoop and decided to write an article complaining about PR practices in place of an actual story. Really like the click b…

Truth be told, Microsoft has among the worst PR agencies/policies from the tech industry. Very bureaucratic, slow to get something out of them, and you usually end up with just canned answers and most questions dodged. It's hardly even worth the effort to contact Microsoft's PR about something.

Unless you know a higher-up exec, like Mary Jo Foley or Paul Thurrott does, for instance, you're unlikely to get a real answer for a security question. For a journalist, writing what you think happened, and then waiting for Microsoft to react, contact you, and tell you what really happened is likely a much more effective strategy to get something out of Microsoft.

Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers

#10

tl;dr: a null deref in windows kernel when you connect to a malicious SMB share

That's not what this article is about though really

Sure, but the main question I had when reading the headline was if I should go into "Oh shit!" mode.
Post reply on HN