4 ms·
I worked with MSRC several times over the years and found them to be smart security professionals (and often former hackers) who care deeply about improving sec
by billyhoffman 10y ago
I worked with MSRC several times over the years and found them to be smart security professionals (and often former hackers) who care deeply about improving security.
I suggest you take the long view and compare how Microsoft handled security disclosures in the past ("That vulnerability is entirely theoretical.") compared with today (inviting hackers to their oncampus Bluehat conference, sponsoring CanSecWest, etc). Things could always get better, but they've come a long way.
More specifically, "only" 2 weeks to issue a security fix is actually pretty good for thick client/desktop software. It's less than ideal for something like a web app where they control all the machines that need to adopt the fix, but still. Also, the severity of reported issue is a factor in when something gets fixed.
Consider looking at something like rfp's RFPolicy if you'd like guidance on how to disclose in a reasonable, timely way
- louis-paul 10y agoI completely agree with you, in general they have come a long way (bounties, culture, recognition...). They're just not there yet (by there in mean Facebook-grade responsiveness). I was only voicing my personal experience, which has been very poor (maybe the team, or the seriousness of the bugs), but in general I have heard some good things, especially for truly critical issues.
- danjoc 10y ago>Facebook-grade responsiveness When did Facebook become the pinnacle of security response? The last thing I read about them was pretty horrible. Much worse than the Microsoft response here. http://exfiltrated.com/research-Instagram-RCE.php http://exfiltrated.com/research-Instagram-RCE.php
- gedrap 10y agoI remember this story, and people familiar with the industry (tptackek and friends) explained the situation quite well why Facebook did the correct thing, although not fair for unfamiliar with the industry readers https://news.ycombinator.com/item?id=10754194 https://news.ycombinator.com/item?id=10754194
- ktRolster 10y ago"only" 2 weeks to issue a security fix is actually pretty good for thick client/desktop software. That's actually even more of a reason to migrate away from Microsoft.
- milesskorpen 10y agoI think you misread his comment — the issue was reported _years_ ago and then fixed just two weeks back.
- Artemis2 10y agoYou misread it! I reported one a long time ago, which was fixed in two weeks (so relatively quickly). Another, very similar, reported nearly a year ago, still isn't fixed.