7 ms·
> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers
by olig15 9y ago
> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky.
> "That can help the bad guys," he said.
This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how this could have 'helped the bad guys'.
- zitterbewegung 9y agoThey are commenting on the disclosure of the exploix and how to exploit it. Obviously everyone will have the patch installed.
- snowwolf 9y agoYeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others (https://twitter.com/taviso/status/861575086632968192 https://twitter.com/taviso/status/861575086632968192) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes users more insecure. Surely it is better to alert people (and especially organisations) that a major security issue has been found so that they can be prepared to patch their systems as soon as a fix is released?
- richmarr 9y agoI know comparatively little about this stuff, so please excuse the question if it's dumb... If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit? My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.
- snowwolf 9y agoMalicious actors are far more proactive already about watching for security patches and reverse engineering them to work out how to exploit unpatched systems. Once a patch is released the cat is out the bag, and the only solution is to patch as quickly as possible.
- dom0 9y ago> surely it also allows malicious actors to prepare to exploit? "There is an RCE in Windows" is not helping anyone.
- sillysaurus3 9y agoThis is a tangent, but: Isn't it strange that in security, it feels ok to give an uninformed opinion? I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions. In the tech world, this seems unique to security. For example, none of us would feel like we should have a say in how Rust rolls forward unless we're experts in Rust, or at least involved in Rust in some way. Yet there are many who feel they should have a say in whether Project Zero ought to do X or Y even without any experience. I wonder why?
- lol768 9y agoI'd guess that security feels pretty personal to a lot of people. They may not be experts in the area, but maybe they run servers,- deal with sensitive data or just don't want their personal machines compromised. A poor approach to vulnerability disclosure for a zero-day could cause them real issues, whereas perhaps a language design decision is less critical.
- Angostura 9y agoI'm surprised you feel that way. Who here hasn't commented on an aspect of UI design, or UX, or Apple's roadmap or whether product X should be open source or comply with standard Z or whatever?
- captainmuon 9y agoHe basically announced that he knows a secret worth millions. Criminals and state actors might do everything they can to get this secret, starting with trying to hack him, over bribing him, blackmailing him, serving him secret court orders, or even physically assaulting him with the famous wrench. Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a website" paints a huge target on you. Although the danger is kind of abstract, there is no security gain from tweeting about this, so I'd say he shouldn't have done it.
- caf 9y agoIt's not worth millions if it's already been reported to Microsoft.
- user5994461 9y agoTell that to the millions of people who won't have the patch before next week.
- dsp1234 9y agoWhy would they not have it until next week. Per the advisory, the engine update is part of the normal windows defender updates, which happen up to 3 times daily. I just checked this morning, and I have the updated version already, and took no action. Those millions would have had to have disabled windows defender updates in order to not get this update before next week.
- user5994461 9y agoIt turns out the update is part of the Defender update, not windows update. That's a much more frequent schedule.
- criley2 9y agoNot sure about millions but many do have update for Windows turned off, due to Microsoft's security-trust-destroying habit of deploying invasive and undesired non-security updates automatically. Windows 10 especially has a nasty streak with updates, and while security updates are smart, forcing new content updates, advertisements, and spyware into the Tuesday fast track teaches users that the only way to be safe from Microsoft is to not take software from them automatically.
- spatulon 9y agoTavis also got some blowback on Twitter simply for announcing that he'd found a vulnerability. It's baffling to me why people think it's a problem. If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.
- captainmuon 9y agoIt's not that the bad guys will find it now by looking for it in Windows. It's more like they could grab a gun (thugs) or creatively worded court order (government) and pay him a visit... A remote zero day in Windows is worth millions on the black market, and in skilled hands the amount of damage or money you can make is nearly limitless.
- lawnchair_larry 9y agoPlease do not spread baseless FUD. None of this is true.
- staticassertion 9y agoLiterally nonsense. But, in fact, totally representative of the crazy lengths people go to to justify why Tavis's tweet that he found ~a vulnerability~ is somehow dangerous.
- shallot_router 9y agoOh come on. They're going to tie him up and torture him before he gets a chance to press "Send" on his report email, then?
- drzaiusapelord 9y agoAre we taking twitter as a legitimate medium? 90% of what I see there are contrarians riding the coattails of others. Of course Tavis has all these crazy replies. Its a bit like how the paparazzi get celebs to notice them. They 'neg' the famous person to get the desired response and attention they want. People not playing these games don't see his tweet as being controversial. It almost had no details, what exactly is there to argue here? Your average copy of Windows probably has tens of thousads of unfound zero days. Its rational that they will be continued to be found. I think the narrative of "but people on twitter are talking" is fairly bullshitty. Twitter is not reputable, anyone can reply to anyone, and unless you start naming the names of respected security researchers then these replies are from just kids and a trolls looking for attention.
- CiPHPerCoder 9y agoA lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet: https://twitter.com/taviso/status/860679110728622080 https://twitter.com/taviso/status/860679110728622080 The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind the fact that there's no details in the tweet relating to the actual vulnerability or exploit. To be clear: I don't know what relationship (if any) Graham Cluley has to the people being jerks to Tavis, and it's possible that this quote was taken out of context. However, given the backlash Tavis's tweet summoned from some Twitter users with inflexible opinions about disclosure ethics, and this alien remark in the article, I'd hedge on the two being related.
- SA500 9y agoGraham's a longtime critic of Tavis. Think he used to work for an AV provider. Here's the history anyway https://www.google.co.uk/search?q=Graham+Cluley&oq=Graham+Cluley&aqs=chrome..69i57&sourceid=chrome&ie=UTF-8#q=Graham+Cluley+Tavis+Ormandy https://www.google.co.uk/search?q=Graham+Cluley&oq=Graham+Cl...
- snakeanus 9y agoIt seems that he is the Sophos guy.
- mikhailt 9y agoThere are many sides to this and you're generalizing it to people not understanding the full value of security disclosure is misleading. I can assure you a lot of those people fully understand the value of security disclosures and they are for it. What many people have the problem with, is with Tavis' tone and his approach to announcing his findings. No reasonable security researchers find a bug, announce it first to Twitter or other mass public postings and then inform affected vendor(s) with the disclosures. That's not it should be done and it is not a responsible discourse policy, this is what people have problems with Tavis. Tavis is doing amazing work, work that we need but he has to be careful with how he announce his findings to the public.
- dickbasedregex 9y agoThis is going to sound glib but it just sounds like some people in security research are butthurt. And not for any valid reason.
- robinson-wall 9y agoAnyone confused about what parent's comment is quoting, this HN link was originally pointing to http://www.bbc.co.uk/news/technology-39856391 http://www.bbc.co.uk/news/technology-39856391
- duncans 9y agoI tried the proof of concept zip (https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5 https://bugs.chromium.org/p/project-zero/issues/detail?id=12...) on my machine this morning. It crashed msmpeng. Had to manually update. Perhaps they should wait for a few days to allow it to roll out organically before releasing the details?
- BearGoesChirp 9y agoI'm still wondering if the best possible plan (when done over a long time) is immediate and full release of all known information to the public. The immediate effect is worse. You will have people making use of the vulnerability as soon as the information is out the door. But what about the secondary (and tertiary, etc.) impacts? Will companies be more likely to spend more on security because they will have lost the chance of having 90 days to fix an issue before it goes public? Will consumers who see the damage done in the immediate end up searching for more secure options? It seems weird (and very very beneficial to the corporations making these security vulnerabilities) that we blame the researcher for releasing the details more than the entity who made the insecure software, sometimes even more than we blame the ones exploiting the vulnerability. Think of it this way, we already have a given window before we go public. 90 days, which you mention in your post. Why do we have 90 days? Why not 180? If you get to the 90th day with no fix in sight, going public exposes all users to the same damage. If it were 180 days, or something much longer like 10 years, is there a chance that entities behind the software in question will just ignore the bug because patching bugs doesn't generate income like new features? Does the reasoning we have for having a 90 day clock instead of a longer maybe justify a shorter than 90 day clock?
- user5994461 9y agoThe disclosure is irresponsible. The post published today contains information on how to exploit the bug with a working code for POC, confirmed to work. The windows patch is published today. It's gonna take weeks to propagate to the windows computers around the world.
- joshuamorton 9y agoThe windows patch contains mitigation techniques for the vulnerability, likely enough for an attacker to to reverse engineer. Its better to have the details out in the open so that users can take action to mitigate in the meantime.
- JonathonW 9y agoWindows Defender updates (malware definitions and engine updates) don't run on the same schedule as other Windows updates-- they're downloaded at least three times daily, and installed immediately once they're downloaded. IIRC, they're also not disabled by the UI switch that disables other Windows updates. A user would have to go pretty far out of their way in mucking around with things that shouldn't be mucked around with in order for this update to take "weeks" to propagate to them.