3 ms·
> Asked if Microsoft had previously fuzzed the Windows Defender component, a company representative said yes. > "Fuzzing is one of a number of techniques we em
by frandroid 9y ago
> Asked if Microsoft had previously fuzzed the Windows Defender component, a company representative said yes.
> "Fuzzing is one of a number of techniques we employ to update and strengthen our software," the representative said in an e-mail. "It is a standard practice we use as part of the Security Development Lifecyle for our products."
This journalist is naive. This answer says "sure we use fuzzing, but we have no idea if this particular bit of code was fuzzed." When you ask a binary question and a binary answer isn't provided, someone is usually trying to obfuscate the fact that they're on the wrong side of the binary.
- eridius 9y agoThat's awfully cynical. The answer they got is more indicative of the fact that they're talking to a representative rather than one of the engineers who would have actually been responsible for fuzzing it, so all the representative can really do is say what the policy is rather than answer the specific question of "was this particular component fuzzed"?
- 888uuii 9y agoWe live in a society presently governed by anarchic advertising and mass-hypnosis. Cynical is called-for.
- frandroid 9y agoA good PR representative doesn't want to get caught flat-footed, and usually gets all the information they need from inside sources so that they can bullshit properly without (accidentally) misleading the public and causing the company legal trouble. Microsoft can afford good PR staff. If they didn't say yes, than the answer is probably no.