9 ms·
Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting
by Kholo 9y ago
Complete BS. This is what happens when you have top class PR at your disposal to define the narrative.
Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic.
Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts and propping up of another billionaire or two. I can hear the whisky glasses clinking.
Corporations do not get to set the agenda and the narrative. When they are allowed to, the results are very predictable - in this case Microsoft will make more than they loose. Who here disagrees that is going to happen? And who here believes that is right?
The answer is simple whether its Microsoft today or Facebook and Google tomorrow win-win should not be an option when such things happen.
- Shinkirou 9y agoNo system is perfect. Remember Heartbleed? Microsoft released a patch to correct this particular issue in March, however the IT infrastructure in companies is slow, the whole process is convoluted, yada yada. The point is: the NSA caused this particular problem. Steps should be taken be everyone to ensure something like this doesn't happen ever again.
- mrmondo 9y agoJust because the media (including Microsoft) tagged those projects (that were maintained by small groups of core develops and are free (unpaid) software) with fancy names - those problems weren't anything like the massive, global impact of just one of Microsoft's ticking timebombs due to poor software design and lack of emphasis on security in their products. OpenSSL doesn't and didn't have the PR powerhouse of Microsoft and people didn't pay for their software let alone fund its development.
- threeseed 9y ago> Microsoft's ticking timebombs due to poor software design and lack of emphasis on security in their products I assume you know nothing about software with flippant comments like this. Completely securing software is an incredibly difficult thing to do and merely throwing resources isn't going to change that. It is just as likely to affect well designed software as it is poorly designed. Especially given that all of us rely heavily on third party libraries and underlying infrastructure.
- fencepost 9y agoThe NSA did not cause this particular problem. The NSA may have identified the vulnerability, however there is certainly an argument that their other responsibilities outweigh any responsibility that they might have to act as a free security investigation team and report a security vulnerability to an outside corporation. If Russian government intelligence agency security researchers found that bug first would you say that they have a responsibility to disclose it to Microsoft (notably a United States company)? Would you be surprised if they felt and acted differently?
- gech 9y ago> however there is certainly an argument that their other responsibilities outweigh any responsibility that they might have to act as a free security investigation team and report a security vulnerability to an outside corporation. Yeah, a shitty one. Free? No they're funded by tax payer dollars. I do think we need to argue about priority of responsibilities. Was this exploit used to spy on allies?
- fencepost 9y ago> Was this exploit used to spy on allies? Don't know, and unlikely to ever find out. If so, it was likely very targeted to avoid detection on modern systems. Was it ever used to spy on Iran's nuclear enrichment program? > I do think we need to argue about priority of responsibilities. Ok. What responsibilities does a US government agency have to disclose vulnerabilities? Should they be required to disclose all vulnerabilities found in software and equipment from US companies? Since a lot of that technology is used around the world, are you on with the corollary of it being harder for the US to spy on anyone using modern equipment? How about disclosing problems found in tech products used by US companies? Should the NSA do that as well to keep those companies safe? The US provides a fair amount of funding to organizations focused on finding and responsibly disclosing security problems, notably CERT[1] and US-CERT [2]. The NSA is a completely separate thing. 1: http://cert.org/about/ http://cert.org/about/ 2: https://www.us-cert.gov/ https://www.us-cert.gov/ Edit: removed snark
- shitloadofbooks 9y agoAnd who do we fine for all the bugs in Open Source software then. The most serious vulnerabilities of late have all been in Open Source packages: - ShellShock - Heartbleed - etc Do we fine the person who committed the faulty logic, the reviewers, the entire community who "peer reviewed" it?
- tomstockmail 9y agoHeartbleed and ShellShock were serious but nowhere near the seriousness of WannaCrypt. Don't let the top headlines of HN and a fancy logo be how you rate vulnerabilities.
- bigiain 9y agoI'd be happy enough to go with "you fine whoever wrote the invoice or cashed the cheque". You wanna sell it? Take responsibility for it. You scratch your own itch and give it away for free? Good on you.
- 21 9y agoIt doesn't quite work like that. If I give away "free lemonade", but people get sick because I've made it in dirty conditions, I will not get away just because it's free.
- bigiain 9y agoMaybe... What's your alternative? Are you suggesting we _do_ fine all the OpenSSL contributors? Or that we do not hold anyone except end users responsible for software/hardware security? I'm not sure metaphors or comparisons between software and lemonade are entirely helpful - although they do push the discussion along, which is at least interesting... (So if I didn't _make_ the lemonade, but published my "4 lemons pulped, 1/2 a cup of sugar, and 2 teaspoons of rat poison" lemonade recipe on github - then you made it and got sick... Who's in the firing line then? What if the README says "this recipe is satire"?)
- dotancohen 9y agoRedhat and Canonical will be in a world of hurt.
- dasil003 9y agoUh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecure technology stack with no vendor to take responsibility and no source code to even take on the problem themselves. There's plenty of blame to go around to be sure, but giving the NSA a pass for developing zero days is batshit insane. These guys are playing god instead of helping make infrastructure more secure overall, and it will not end well, even if they outcompete the Chinese or whatever other bogeyman they cook up to justify their power grab.
- ouid 9y agohow much do you think it would cost Microsoft to support XP forever?
- nevir 9y agoThere's a big argument for only releasing evergreen style software, and giving the middle finger to IT orgs that want more control
- goatherders 9y agoThis. There are lots of groups to blame, but corporate IT departments are high on the list.
- Consultant32452 9y agoWhat does "evergreen style software" mean? A quick search didn't return an obvious answer.
- Sammi 9y agoSoftware that continually updates itself automatically. It's what Chrome popularized.
- josephg 9y ago> Instead what will happen is more tightening of the walled garden You know what? I'm starting to get excited for the walled garden to get more walls. Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applications and download my contacts list, all without my permission. We don't let web apps do that, because web app developers aren't trusted by default. We don't let mobile apps do that, because mobile app developers aren't trusted by default. Why on earth do we implicitly trust any executable file run on the desktop so much? Telling users not to double click on executables is obviously not working. Even for experienced users I have no idea whether some random app on the internet is trustworthy. Its a reverse lottery. I also suspect ransomware like this one would have been slowed down if it needed explicit user permission to read & modify files on disk. We even know what the sandbox should look like, because we have two working examples in the form of the web and mobile. And we have sandboxing support & APIs in most operating systems. We're just missing the UI part. I'm imagining something like: - All apps get signed by the developer (Lean on SSL? Not sure the chain here.) - The app needs to request capabilities from the user, like on iOS. "App X by Y developer wants permission to read the files in your home directory". (/ Read your contacts / Register at startup / Take screenshots / Modify these files). - Capabilities can be viewed and revoked at a system-wide level in the control panel / system preferences.
- 21 9y agoI'm not sure if you know, but Windows already has that - Metro apps (or whatever the name is now) are sandboxed and with a permission system. But they are much hated.
- threeseed 9y ago> But they are much hated. Most people wouldn't even know that they are sandboxed. But we will see for sure with Windows 10S and its optional upgrade to Pro policy.
- pharrlax 9y ago
- drvdevd 9y agoI think without: 1) Open Source software AND especially 2) significant financial incentives for finding and reporting bugs, it will be business as usual for the foreseeable future.
- ladzoppelin 9y agoFair enough but, like others have said, who do I fine when my Wordpress site gets pawned or for Shellshock, etc? I wish this problem was a simple as blaming/fining MS or Google.
- iamaelephant 9y agoAll software has flaws. It's how we respond to them that matters. https://twitter.com/ben_a_adams/status/863563517898747904 https://twitter.com/ben_a_adams/status/863563517898747904
- ArchReaper 9y ago>Microsoft is responsible for their shit software getting exploited This is an absurdly naive viewpoint. How are they responsible? What is their responsibility? How is it their responsibility when a state-funded group/actor targets their software and finds an exploit? At some point you have to realize that 0days will always exist. It is an impossible task to expect software developers to ship perfect software.