6 ms·
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before
by cujo 10y ago
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before.
If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
- pdimitar 10y agoThere are very competent people on this planet who make a very good buck out of zero-days (not to mention remotely control users' machines, and steal data). IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is a PR hype. If they want researchers to stop doing preliminary public disclosures, they should prioritize security higher than PR damage control.
- UnoriginalGuy 10y ago> IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. Except the researcher themselves knew it was one more week, and not "several years." You cannot claim they were ignorant if their own statements shows that they were not.
- pdimitar 10y agoYou might be right. But they only claimed it, didn't they? I personally like Windows 10 a lot and I applaud any effort to turn it into a long-term stable OS.
- tedunangst 10y agoWell, if MS claims the patch is coming in one week, one approach might be to wait one week and then release the exploit. Works out regardless of the accuracy of the claim.
- tveita 10y ago«He told Ars that the software maker initially planned to patch the flaw in December but later decided to delay the release until February so it could be included with other planned SMB fixes.» «it is not the first time Microsoft sits on my bugs» So they already reneged once on this bug which fits into a previous pattern. If that is right putting pressure on them sounds entirely justified and not at all petty.
- pdpi 10y agoPatch Tuesday is the second Tuesday of each month. Unless something odd happens, you can count on the fix being out a week from tomorrow. There's also a justification for this — they sat on it because they were releasing other SMB-related patches on the February Patch Tuesday. I don't really think anybody can reasonably argue that MS would not release the fix next week. But that's not the point. This bug was reported in December, and there's no reason to believe that they didn't have a patch in time for inclusion in the January Patch Tuesday. They chose to withhold that patch due to non-technical, apparently PR-related, reasons, and the researcher in question is complaining that this has happened before with other bugs reported by him. That's a pretty cavalier approach to security, and early disclosure is the only way the researcher can punish MS for it.
- mjw1007 10y agoIt's slightly worse than that: the bug was reported in September; December appears to be when they had the patch ready. So there were two months of apparently unjustified delay.
- tedunangst 10y agoSure, if MS promised to issue a patch in January, then go ahead and release info when they don't. But it's weird to wait for a February patch, and then release a week early. Like I'm more or less ok with "full disclosure upon discovery" as a consistent release policy. Or "wait for a patch up to 90 days". Or several other models. "Wait until one week before patch" is an oddball policy which seems like it has all the cons and none of the pros of other models.
- eli 10y agoJust because there are other people who act totally unethically doesn't mean you get bonus points for doing kinda the right thing.
- mlmlmasd 10y agoMS is acting 'totally unethically' by not patching this bug immediately and rewarding the researcher.
- WayneBro 10y agoMeh. The bug requires you to connect Windows to a malicious SMB server. Now that everybody knows that, if anybody is really concerned, they can stop SMB connections from LAN to WAN by blocking TCP 139, 445 and UDP 137, 138.
- mlmlmasd 10y ago> Now that everybody knows that Wait, when did everyone become aware of that? I'm willing to bet the vast majority of windows users have no idea. _Some_ people only know _because_ he released the bug.
- cmdrfred 10y agoI'm now aware, and I was able to block connections in my organizations firewall that protects a few thousand users. Not every single user needs to be aware for it to be effective.
- mlmlmasd 10y agoYes, but the point is you wouldn't be aware unless he released the info. He gave individual users an option to protect themselves in the absence of a patch from MS.
- pdimitar 10y agoWhat would your solution be?
- UnoriginalGuy 10y agoAnd when Microsoft do cut QA short people complain that Microsoft doesn't care about quality/is using retail as a beta test. It is really a no-win situation to be honest.
- EdHominem 10y agoThe correct way to do this is immediately release a bulletin to admins to block the affected service, then push a patch to disable it, then push a patch to fix and reenable it when they feel ready. It's only unwinable because Microsoft refuses to take a PR/cash hit of telling people to stop using something while it's broken.
- mlmlmasd 10y ago> so he's causing microsoft and USERS problems they didn't have before. He's not causing problems, he's solving them.
- cujo 10y agoGifting exploiters a 0day before the KNOWN patch release date, is causing problems.
- mlmlmasd 10y agoNo, it was only a 0day before he made it public. He is merely providing security-conscious persons information and a way to defend themselves from an exploit which MS has not fixed. He is turning a 0day into a known vuln.
- gnud 10y agoWell, I'm not sure I agree in this case. > He told Ars that the software maker initially planned to patch the flaw in December but later decided to delay the release until February so it could be included with other planned SMB fixes.
- drzaiusapelord 10y ago>The researcher sounds really petty. We live in the age of security researcher marketing. No one wants to be the anonymous guy who submitted sometnhing. They want to be the star and have all these articles written about them and all this attention. The easiest, of course unethical, way to get this is to release something before its patched regardless of what the OEM is doing in regards to patch scheduling. To release one week before patch Tuesday is a pretty big middle-finger to a lot of people for no other reason than what looks like personal gain or spite. I imagine this decision is going to bring him a lot of negative attention. I wouldn't hire someone who 0-day'd a security bug a week before its patch out of spite. Thankfully, connecting to a random smb is a fairly edge case. I believe most firewalls block smb to/from the internet and most consumer ISPs block the protocol outright. This probably won't have much of a real world impact.
- Mithaldu 10y agoAs a longtime windows user: No. There's no excuse for them to delay patching it without explaining to him in detail why there's a delay, and even if he had been a dick about it, they should've had a very good explanation for the public. They had neither and that is unacceptable. Reason being: Even if he doesn't publicize it, someone else might know and be using it without MS knowledge. Anytime you become aware of an exploit one must act as if it already is being abused.
- bryanrasmussen 10y agoI don't know, I guess that really depends on the frequency and context of 'not the first time Microsoft sits on one of my bugs'. I'm not a security researcher but I suppose if I was and Microsoft was sitting on my bugs pretty frequently and they were really serious I might just give them a shot across the bows one fine day.
- VikingCoder 10y agoPresuming the USERS don't ALREADY have a problem is the inherent flaw in your logic. A researcher who earns no money finding exploits is at an inherent disadvantage to black hats who DO get funding for selling the exploits they find.
- EdHominem 10y agoYou know who sounds really petty though? The whiners taking Microsoft's side despite them missing the bug in the first place and sleeping on the report, and now attacking the person who reported it. > They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. Not in the slightest. You do not understand how the internet works. The vulnerable systems were vulnerable yesterday, and are vulnerable today because MS didn't think it was worth hurrying to patch them. Users' harm was caused by Microsoft who gave them a broken product, and by any hypothetical hackers, not by a security researcher telling the public what the hackers probably already knew. Microsoft had a chance to release an emergency bulletin as soon as they were informed of the vuln, with mitigation steps. (ie, block SMB, etc) They didn't, and in fact spent time recommending useless things (Win10, Edge) that only serve to slander competitors by implication, and pimp more of their products. Microsoft needs the understand that the new timeframe for releasing mitigations, if not patches, is closer to 24h than 24 days. But even if they hit that metric, they don't deserve any fanfare until they do it without lying or misdirecting. Downvoters: RTFA - The Microsoft reports are intentionally misleading wrt. steps customers need to follow to be safe, and they claim to be better that their competitors (Apple, etc) in this regard despite obvious and consistent proof to the contrary. Microsoft is responding to security concerns with marketing speak, and they're knowingly setting their customers up for catastrophic data loss or hacks by recommending useless fixes.
- dang 10y ago> You do not understand how the internet works. > Downvoters: RTFA These things break the HN guidelines. Please (re-)read them and post civilly and substantively, or not at all: https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newswelcome.html https://news.ycombinator.com/newswelcome.html
- sqeaky 10y agoWhat is the thresshold where you do decide to release the bug description? Microsoft has sat on bugs for years saying they were working on them. Do you disclose after a week? A Month? a Year? If it were a company or team with a solid history of patching swiftly I could see trusting them. But this is Microsoft, they have the resources to fix bugs. They chose an OS design that sacrificed security for other things. Worst, they chose to betray trust in the past. Someday Microsoft might earn that trust back, but they are a long way off from earning mine. If I informed them of the bug and it wasn't fixed in the next patch, then I would need solid evidence they are working on it or I release the exploit. If it were a group I trusted I would follow up several times until I lost faith in them.
- tinus_hn 10y agoThey weren't patching, in this case the process has taken months. It's just marketing so they can say there's just a small number of bugs.