5 ms·
I think it's rather ironic that this was published by Trend Micro, a company that has had at least two critical vulnerabilities in their own "security" solution
by jnky 11y ago
I think it's rather ironic that this was published by Trend Micro, a company that has had at least two critical vulnerabilities in their own "security" solution:
https://bugs.chromium.org/p/project-zero/issues/detail?id=693 https://bugs.chromium.org/p/project-zero/issues/detail?id=69...
https://bugs.chromium.org/p/project-zero/issues/detail?id=773 https://bugs.chromium.org/p/project-zero/issues/detail?id=77...
I realize that the two teams are probably unrelated, but maybe it would be worth verifying that their "security" software is indeed, you know, secure.
- dfc 11y agoGoogle has had security vulns too. Do you find it "ironic"[^1] that Tavis would disclose vulns in other companies software? [^1]: You really should look up the definition of this word.
- jnky 11y ago> Google has had security vulns too. Do you find it "ironic"[^1] that Tavis would disclose vulns in other companies software? No, the thing in this instance is that a) Trend Micro is a dedicated "security" company and b) the vulnerabilities in its software were especially negligent. > You really should look up the definition of this word. One definition I found was "happening in the opposite way to what is expected, and typically causing wry amusement because of this". Considering that, I'm quite happy with my usage of the word. That said, English is not my first language and I often see people nitpicking about this particular word. My feeling is that people understood me just fine despite of it.
- dfc 11y agoYou expected an antivirus company to write perfect code and not have any vulns? That is hilarious. Look up Fireye vs. ERNW. You will love that one.
- deleted 11y ago[deleted]
- pilif 11y ago> You expected an antivirus company to write perfect code and not have any vulns? no. But I expect them to have their shit together well enough to not be the laughing stock of the internet because of how amateurish their flaws are (come on - unauthenticated remote accessible JS shell with full local machine access? This didn't even happen to microsoft in the 90ies) AV programs are by definition in an utterly exposed spot on your machine: They run in a privileged account and they intercept all reads and writes to the disk. They also unpack every archive, parse every file, check every single byte written. An AV program is opening every mail attachment, practically inspecting and sometimes even partially running every trojan on your machine, even those you blatantly ignore as being spam. For an application in such an exposed point on your machine, I expect them to at least follow current security-best-practices, tough honestly, I would wish they would go far beyond that due to the immense risk they subject themselves to. And then we have trend micro, an AV program, which opens a remote accessible RPC endpoint which can be used by everyone. This is the exact opposite of what I'm expecting them to be doing.
- dfc 11y agoI did not realize that Trend Micro was held to such a high standard. My (uninformed) opinion of them was that they were nowhere close to best of breed. But more importantly, it seems like there is a difference between the way things are and the way you think things ought to be. Look at all of the AV industry bugs from google's project zero: Avast (9): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AProduct-Avast&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... Comodo (9): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-Comodo&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... ESET (3): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-ESET&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... FireEye (2): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-FireEye&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... Kaspersky [you will love the archive unpacking vulns] (15): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-Kaspersky https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... malwarebytes (1): https://bugs.chromium.org/p/project-zero/issues/detail?id=714 https://bugs.chromium.org/p/project-zero/issues/detail?id=71... All in one list: https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-Comodo%2CVendor-Kaspersky%2CVendor-ESET%2CVendor-AVAST%2CVendor-FireEye%2CVendor-TrendMicro&sort=severity&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary+Severity&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q...
- benmmurphy 11y agothis looks like it may have come from ZDI which was only just recently purchased by trendmicro