8 ms·
Using Binary Diffing to Discover Windows Kernel Memory Disclosure Bugs
- mappu 9y agoI know some Windows 7 holdouts, who either prefer the interface or they're against telemetry. That was a defensible position as long as 7 was still under security support, but these findings put an end to that. Time to switch, and -1 trust in Microsoft's lifecycle statements.
- marksomnian 9y agoBut why don't they just switch to Windows 8? It solves all their problems. /s
- jm547ster 9y agoBasically are if they’re moving to 10. It’s more or less a re-skin with added telemetry & Cortana. Personally I preferred 8 to 7, I guess the touchscreen oriented metro interface was enough for desktop purists to recoil in horror. Was really only “hardcore” gamers who were holder-outers anyway
- marksomnian 9y agoOn a serious note, it seems like I was the only one who actually liked the Windows 8 start screen. Being able to rearrange your start menu was a killer feature for me, instead of searching for everything or pinning all my stuff to desktop.
- Cacti 9y agoWindows 8 is a case study in first impressions and how much people hate change. It is superior to 7 in nearly all regards (the app/store infrastructure being a notable exception), and its UI is nearly identical to 7. But people couldn't get over the Start screen, even though it can be disabled. It's really amazing how much flack it got.
- Frogolocalypse 9y agoIt's nice to see I'm not the only person who doesn't mind 8.
- y_u_no_rust 9y agoI liked 8.1 a lot I.0 was a bit rough
- mattnewton 9y agoIt got flak because of the random hodge podge of menu screens that could to decide if they were desktop or tablet oriented. Also getting thrown into full screen apps, the “charms”, and the broken windows store were other favorite targets of criticism. All this for basically no visible improvements if you weren’t using a tablet/laptop hybrid.
- GrayShade 9y agoI might be downvoted since this is just a random anecdote, but at work I've seen a lot of computers having a specific performance issue on Windows 8. The symptoms were Task Manager showing disk usage at or near 100% with the total throughput being around 2 MB/s on an otherwise idle system. The files being accessed were the swap file (although the system had enough free memory) and sometime Office Click to Run stuff. It also happens when the system is not idle, so it's not a random background job. I thought it was fixed in Windows 10, but I've just seen it happen on a low-end laptop. My theory is that so many developers have SSDs now and almost nobody tests on an HDD. That $300 laptop feels unusable, much worse than Windows 7 has ever felt. This issue has been reported in many places (e.g. https://www.drivereasy.com/knowledge/fix-100-disk-usage-in-task-manager-improve-pc-performance-on-windows-10/ https://www.drivereasy.com/knowledge/fix-100-disk-usage-in-t...), but most of those solutions don't work. The other thing that bugs me is the start menu search sometimes not working. Anyway, my point was that between the Windows and Office telemetry (the latter nobody mentions), random Store apps getting installed automatically and long-standing issues such as these, there are other valid reasons to dislike Windows 8/10 than "fear of change".
- NiveaGeForce 9y ago
- dom0 9y agoWindows 7 still has about 50 % market share. That's more than just some holdouts, over all.
- tdb7893 9y agoIn my experience much of that is corporations which are always slow to switch. Almost all the people who buy windows machines I know have gotten windows 10
- beached_whale 9y agoLook at the lifespan of a corporate pc. 3-5 years before warranty, risk management end and they’re replaced. Often the OS is not upgraded in between. Plus Corp software that depends on everything down to how obscure system dll versions. So we are looking at 2020 before most are migrated probably
- colechristensen 9y agoThe enterprises I've known have upgraded en mass and 3-5 year hardware cycles are ... generous.
- beached_whale 9y agoI was guessing the 3-5, for us it 3 and 4(3 laptops/4 desktops). Do you mean the replace HW faster or slower? It depends on size, we have over 60,000 computers and before End of Support for XP we moved to 7 in under a year. That was a kick in the butt and Win10 has been far quicker. It's the standard and almost everything deployed gets it, but there are always stranglers who are slower. You have to take from other projects to do a mass upgrade and it can be a hard sell when it will happen on the systems renewal schedule anyways.
- colechristensen 9y agoI mean slower, much slower.
- Analemma_ 9y agoWe need a cultural shift in this industry away from thinking it’s OK to run outdated and vulnerable software. “Why should we upgrade? $OLD_VERSION works fine!” Yeah, and driving a car with no seatbelts or airbags works fine too... until it doesn’t.
- inferiorhuman 9y agoSure that's great, but air bags and seat belts also come with cameras that record your behavior and report back to the auto manufacturer. And ads.
- iClaudiusX 9y agoAnd the install process has a non-negligible chance of bricking your car until you get it towed back to the dealer.
- snaky 9y agoAnd uninstall process is like "Burnett deleted the new Paint 3D, a system app, which he is entirely entitled to do. He found the system restored it and added a firewall rule allowing it network access."
- jenscow 9y agoBut Windows 7 is still being supported (or so they say).
- panic 9y agoMany people running Windows 7 aren't "in this industry" -- they're ordinary people trying to use their computers to do work, or play games, or keep in touch with other people. What our industry needs to do is stop building software full of crap (ads, spyware, bugs) people don't want. If the software is good, people will upgrade.
- bobcostas55 9y agoIf 10 wasn't seen as an enormous downgrade people would treat the vulnerability issues more seriously. Just the other day I saw a huge powershell script whose purpose was to remove all the bloatware (which apparently re-installs itself on its own if you uninstall it normally). I don't want to bother with that stuff... And on top of that you have the telemetry, endless horror stories of forced restarts for updates, updates resetting settings and/or degrading performance (which took 5 months to resolve in the case of the Creators Update: https://betanews.com/2017/09/11/windows-10-game-performance-fix/ https://betanews.com/2017/09/11/windows-10-game-performance-...)...7 works like clockwork, with no bullshit.
- c3534l 9y agoI think the fact that consumers don't feel like they have an alternative is a problem. Also, remember many people use their computers for purposes that require no security measures be taken. Who cares if someone hacks a computer that is only used for excel and casual web-browsing?
- serf 9y agoit's not about the use-case of the victim, it's about the system resources it adds to the pool for the attacker to use as they wish. Now add "offline" to your list and i'd agree. Every online node is a potential threat not to just the direct victim but to potentially anyone else on the net.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- Jach 9y agoI've been watching my friend deal with Windows 10 shenanigans for over a year. Occasionally he'll get it to a frozen point where it won't secretly update and break everything, won't transmit all sorts of information to HQ, and won't reinstall Candy Crush. He's convinced that most malware would be more respectful with his hardware resources than that OS. When you make the prevention worse than the disease, don't be surprised that the disease gets an upper hand.
- comex 9y ago> Who cares if someone hacks a computer that is only used for excel and casual web-browsing? I’d say most users would care if all their Excel documents got encrypted by some ransomware. Backups help, but they’re not a silver bullet, and the type of unsophisticated user you’re depicting probably doesn’t have them anyway. Aside from that - does that casual web browsing include anyone checking their email? If so, now the attacker can probably get full access to their email account(s). Even a purely automated attack can send spam or scams to the user’s contacts, which is bad, though arguably not the end of the world. If a human attacker is targeting the user individually, they can do much worse - starting with using the email account as a stepping stone to all their other accounts, and limited only by their imagination. I suppose that most users aren’t likely to be targeted in that way, but you never know.
- hetfeld 9y agoYou can always switch to Ubuntu.
- gadling 9y agoBut Windows 7 is still under security support and will be till Jan 2020. (See here: https://support.microsoft.com/en-us/help/13853/windows-lifecycle-fact-sheet https://support.microsoft.com/en-us/help/13853/windows-lifec...)
- saulrh 9y agoMisparse, I think. Both "was"es refer to the state of using 7 being defensible. Maybe a better phrasing: Using 7 would have remained defensible as long as it had security support, but now even that's insufficient. Alternatively, the parent argues that 7 is de facto unsupported now no matter what Microsoft claims.
- amazingman 9y agoThis is a great breakdown. Are you using any specific cognitive techniques or patterns/habits that help you do this?
- SolarNet 9y agoI suspect reading... and Poe's law.
- DamonHD 9y agoLess crunchy than Cole's Law.
- amazingman 9y agoThat’s some delicious snark and all, but if it were only that simple. In general, most people tend to be oblivious to—perhaps even motivated to miss—when the source of a disagreement might be linguistic confusion rather than actual disagreement.
- cjsuk 9y agoTime for class action.
- Fej 9y agoTelemetry was backported to 7/8. I imagine it's not as bad as the 10 telemetry, but still, it's there.
- CtrlAltT5wpm 9y agoRemoving the telemetry on Windows 7 (or 8.1, where I'm at) is far easier than the questionably effective flaming hoops you have to jump through to do the same on 10. It's a matter of uninstalling a few updates and that's more or less it. I've disabled automatic updates as well, but check daily to make sure I'm up to date as far as security is concerned.
- discreditable 9y agoI've long suspected that Microsoft (and other large players) only most eagerly support their latest product. Long-term support is only done begrudgingly. In Microsoft's case, I recall a few Office updates over the past 2yrs that boned up Outlook 2013 for some folks but relatively few affected Outlook 2016.
- katastic 9y agoWindows 7 is still supported. Geez. It came out in >>2009<<. Also, Windows 10 bricks every one of my lower end computers. Windows Defender, Telemetry, and more eat 100% disk usage. It's indefensible. Worse, Windows 10 refuses to let you CORRECT the problem. They make new user accounts that are ABOVE the user's top permissions so you have to go to insane lengths to disable a service. And I say all of this as someone who professionally supports Microsoft installations. There's NO need to defend Microsoft in places that don't need it. They're big boys. They should just get their shit together and handle criticism. Like why did it take 15+ years to get proper rescalable command prompt, or virtual desktops? I've got literally dozens upon dozens of stories of Microsoft products being half invented, half completed and half reliable, and MSDN documents that companies rely on for $$$ decisions that end up being erronious or conflicting with other KB articles.
- aspenmayer 9y agoI don't get this recent usage of "brick." Unless it cooks the CPU or is otherwise non-bootable after installing 10, persisting even through other boot media, that isn't a brick. I've seen upgrades fail due to many issues including prior OS corruption and failing storage media, but clean installs of Windows 10 work nearly every time on nearly any hardware that supports ACPI. Driver issues notwithstanding, I don't see anything to support your assertion that Windows 10 bricks lower end PCs. And if the hardware is older than that, it isn't worth your time to even install any other OS on, is it? Diminishing returns. Not meant to be a criticism, I'm just curious what specific issues you were having that you articulate as bricking.
- hyperman1 9y agoDoes someone know a reliable source of the windows telemetry story today. Googling gives a huge bunch of articles which are out of date, or filled with random assertions from random people. I would be very gratefull for: * Exact, technical-level details of what each windows version (7-8-10) is monitoring ('Basic Health and Quality' says nothing). * How to disable it. So it stays off * And some kind of technical proof (Like a wireshark trace or something)
- snaky 9y agoThings tend to change anyway. You never know what Microsoft will roll out tomorrow. > Microsoft has responded to claims that its Windows 10 Enterprise operating system ignores user preferences in Group Policy with the advice that, basically, it does and you shouldn't meddle with it. > On Monday, we revealed that a security researcher had used a packet sniffer to show that many settings designed to prevent access to the internet were being ignored with connections to a range of third-party servers https://www.theinquirer.net/inquirer/news/3010547/microsoft-says-its-best-not-to-fiddle-with-windows-10-enterprise-group-policies https://www.theinquirer.net/inquirer/news/3010547/microsoft-...
- Brybry 9y agoIt's more than just telemetry or the interface. It's about taking some step forwards, and many more steps backwards. Sure, they made an OS that was better for the world because it forces options that mitigate the damage computer illiterate users were doing but at the expense of usability for power users. For example, picking and choosing windows updates is a much worse process in Windows 10. There's a lot more bloat in general that is a lot harder/more annoying to turn off than the bloat in previous versions of Windows. There are design choices that make working around bugs harder. For example, my friend currently has a serious performance hit if Windows Defender's real time monitoring is on. Windows 10 can automatically turns real time monitoring back on if you turn it off, even if you set a group policy and registry settings to disable it. He'll probably end up disabling Windows Defender entirely just because Microsoft can't trust users to manage their own settings.
- acdha 9y ago> For example, picking and choosing windows updates is a much worse process in Windows 10. That’s because this is a bad idea for almost all users: it increases the odds of updates not being installed or people having problems due to an untested combination of updates which wouldn’t have happened if they’d installed everything. Similarly, if Windows Defender does have a notable performance issue beyond what’s typical for AV as a class, the right way to avoid it is to install a separate AV rather than running an Internet-connected system without it.
- tinus_hn 9y agoWhat increases the odds of people not installing updates is low quality. Microsoft can’t be trusted anymore not to break two things for every one problem they fix.
- acdha 9y agoI agree that the risk is real but your second sentence is unhelpful hyperbole. Yes, there’s room for improvement but that’s just not true – and I say that as someone who stopped personal use of Microsoft’s operating systems when I switched to DR-DOS. Exaggerating the scale does nothing other than lower your credibility.
- NiveaGeForce 9y agoWindows 10 is also much more efficient https://np.reddit.com/r/Windows10/comments/74xc2z/windows_and_efficiency/ https://np.reddit.com/r/Windows10/comments/74xc2z/windows_an... And more secure https://np.reddit.com/r/Surface/comments/6ifyxq/spotify_for_windows_10_available_now_in_the/dj5zq9e/ https://np.reddit.com/r/Surface/comments/6ifyxq/spotify_for_...
- sqldba 9y agoI see that the two they fixed disclosed more memory than expected - but is that enough reason to fix it? It seems like you’d probably want a complete POC before fixing them. Or are there common POCs that these obviously fall into?
- bonzini 9y agoKernel memory disclosure pretty much always provides an easy way to bypass kernel address randomization (KASLR).
- tankenmate 9y agoFor those not fully aware of why; if you can get a copy of a section of the kernel stack (which should have been zeroed but wasn't) you'll get the kernel memory (which is different from user memory) addresses of function calls, data structures, etc which then allow you target where to insert your own code / data. In other words it allows you to accurately hijack kernel functions and/or compromise kernel data structures, e.g. change the owner of a kernel object, process or task. It's half of what you need to compromise the kernel (you now know where to inject code/data). The other is having a way to inject code/data. EDIT - grammar fix.
- chris_wot 9y agoI'm still trying to work out when they fixed this: https://bugs.documentfoundation.org/show_bug.cgi?id=62764 https://bugs.documentfoundation.org/show_bug.cgi?id=62764 They got memory dumps from me, but never got back to me about it. It was incredibly poor form, I literally rebuilt systems from scratch to get them the memory dumps, and they never even told me if it helped. Pretty shitty really. I found a nasty issue, and all I wanted was to know if they were going to fix it. Hell, I didn't even want credit - just knowing it was fixed would have been great.
- bonzini 9y agoThey probably didn't even realize they were fixing it. That happens sometimes.
- traitormonkey 9y agoNot just these. First Tuesday is RCE disclosure day.