8 ms·
> This means we do not rely on the secrecy of source code for the security of products, and our threat models assume that attackers have knowledge of source cod
by vthallam 6y ago
> This means we do not rely on the secrecy of source code for the security of products, and our threat models assume that attackers have knowledge of source code. So viewing source code isn’t tied to elevation of risk
I don't know how much of this is true. Wouldn't it be helpful for bad actors to understand how Windows defenses work looking at the code thereby increasing the risk?
- webmobdev 6y agoYeah, the whole point of looking through the source code is to find undocumented APIs and bugs to exploit.
- monocasa 6y agoA lot of times stuff like undocumented APIs and bugs are easier to find taking apart the binary anyway. Goofy stuff tends to be obfuscated in source as engineers add so much abstraction around the goofy pieces, but it's clear in the final binary.
- webmobdev 6y ago> A lot of times stuff like undocumented APIs and bugs are easier to find taking apart the binary anyway. Is that why Microsoft, and all you people who poke at its binaries, have fixed all the bugs in MS binaries? /s
- deleted 6y ago[deleted]
- monocasa 6y agoWhy do you think the people poking around MS's binaries overwhelmingly want the bugs they find to be fixed?
- webmobdev 6y agoThe point was that if it was so easy, a lot more people would be disclosing the bugs and asking MS to fix. Not everyone hacker has a malicious intent.
- saltyshake 6y agothere are many books written on Windows undocumented APIs. these things aren't hidden at all.
- webmobdev 6y agoYeah, right. Everything is so open about all MS binaries that they don't even need to be closed source! It takes a lot of time and effort to find these poking the binaries, and then experimenting them. The source code makes this task obviously easy.
- thisiszilff 6y agoI'd imagine the answer is yes, viewing the source code would increase the risk relative to an attacker that did not have access to the source code, but the statement is saying that whatever risk assessment Microsoft does already assumes attackers have knowledge of source code. EG, they are conservative and do not rely on source code secrecy when making any security evaluations.
- burnthrow 6y agoThat assumes total security competence at Microsoft. The Linux model benefits from public audit.
- TrueDuality 6y agoFor what it's worth I'm familiar with Microsoft's security team (both for their infrastructure and code) first hand and they are some of the most competent individuals I've ever had the pleasure to know. I'm personally not a huge fan of Windows, and it definitely has flaws but the amount of considerations taken into account, and the speed with which issues are identified and repaired in a code base of that size, especially while maintaining a disgusting amount of backwards compatibility is crazy impressive. That aside, having access to the source code does make finding issues easier. It sounds like that knowledge is assumed in their risk assessments which would make that a fair statement.
- mol4711 6y agoHow about their bug tracking software, MS equivalent to Jira issue tracker (I assume they aren't using an outside product). Do we know if they had access to their issue tracker? That would make it far easier to make zero-day exploits faster.
- RMPR 6y agoRaymond chen posted about that https://devblogs.microsoft.com/oldnewthing/20200317-00/?p=103566 https://devblogs.microsoft.com/oldnewthing/20200317-00/?p=10...
- brianberns 6y agoYes, but on the other hand, all the Linux source code is publicly available, and it's still considered secure.
- glouwbug 6y agoCausation vs. correlation, Linux is secure because it _is_ open source. Closed systems can cut corners, assuming the source stays secret
- acct776 6y agoNo, it is not, by any stretch of the imagination, by security researchers. This has been on the front page all day: https://madaidans-insecurities.github.io/guides/linux-hardening.html https://madaidans-insecurities.github.io/guides/linux-harden... It is safe to assume it is more PRIVATE than a Microsoft OS, but not more secure. Please don't react emotionally to this... It was a bit jarring of a shift in thought to me as well, at first.
- acct776 6y agoDownvoters, consider reading first: https://madaidans-insecurities.github.io/linux.html https://madaidans-insecurities.github.io/linux.html
- tester756 6y agoI'm curious whether somebody will challenge it
- richardwhiuk 6y agoThat article is comes from an extremely naive security posture.
- 0134340 6y agoRegardless of what mitigations Windows has in place, when you run closed source programs, without competent security auditing you never know what it's doing. Once you click run your precious user files are always in jeopardy. Even with GUI isolation, a point of contention in the article, it's trivial with a few bytes of code to implement some other form of keylogging which the user will run without much thought because hey, it's Windows, it's "secure" while having no real idea what the program is doing in the background. To reiterate, any execution of closed programs will result in execution of closed processes. With the Windows model, you don't check your guests at the door. You can't search all guests so you assume all guests are hostile and with it you're always taxed with playing security theater which can not only be expensive in terms of hardware resources but mental resources as well as losing more control over your own environment. Because you let unaudited people in your home, before long you have to lock down most parts of it, even from yourself. In gaining control you've lost control because you don't control for openness in the first place. For the few binaries I run on Linux I sandbox them in a VM anyway. But different models, different hosts, each has their weaknesses.
- daniel-levin 6y agoMicrosoft shares source code with lots of partners. It would be asinine to admit that source code leaks, accidental or otherwise, would compromise their security. If they did that, it would create headaches for their massive contracts where source sharing is a prerequisite. So they toe the party line and say no, in fact, source code leaks do not compromise security.
- macjohnmcc 6y agoMany years ago when I worked at Microsoft I asked for the source code to Solitaire. A few days later I received a stack of CD-ROMs with the entire source code of Windows NT (4.0 maybe).
- rbanffy 6y ago> a stack of CD-ROMs with the entire source code of Windows NT That's a lot of code. Scary.
- mandeepj 6y ago>That's a lot of code. It's estimated to be around 40 million lines of code
- macjohnmcc 6y agoAnd it was not compressed it was just a bunch of files and folders. My guess is it was around 15 CD-ROMs
- rbanffy 6y ago40 million lines of 80 characters would fit in 5 CDs. With a more reasonable average length, it'd fit comfortably in 3. And 40 million lines for an OS is a crazy amount of code.
- herodoturtle 6y agoAnd what of the source code to Solitaire!? Cool memory, thanks for sharing.
- drvdevd 6y agoWhether or not it would be helpful to attackers, this is still the correct threat model for Microsoft to operate with. Sufficiently motivated attackers can reverse anything they distribute publicly anyway.
- mmaunder 6y agoAgreed. They’re using that argument to frame their breach as a win. The reality is that open source is easier to reverse engineer and find vulnerabilities in because you have the source. Our researchers do this every day and closed source makes that harder. Advocacy debates in favor of open source have muddied this conversation - but that is the cold hard reality. Now that an adversary has MS’s source code, it is indeed easier for them to do vulnerability research. So this is a net loss for MSs overall security posture, not a win.
- dwheeler 6y agoIt is generally accepted in the security community that hiding source code does not provide security. The principles for developing secure software were identified in the 1970s by Saltzer and Schroeder, and they're still true today. One of those principles is "open design", that is, don't depend on design secrecy for security of the system. Instead, depend on secrecy of things that are trivially changed (like private keys and passwords). Then, when the secret is exposed (or you think it might be), you quickly change all the secrets and there's no problem. One source of this paper: https://www.cs.virginia.edu/~evans/cs551/saltzer/ https://www.cs.virginia.edu/~evans/cs551/saltzer/ In the case of Windows, the source code is not really secret anyway. Most governments have continuous access to the source code, typically through the Microsoft Government Support Program (GSP) https://www.microsoft.com/en-us/securityengineering/gsp https://www.microsoft.com/en-us/securityengineering/gsp Many businesses and universities also have access to Windows source code. You can see various programs to provide such access in different cases via https://www.microsoft.com/en-us/sharedsource/ https://www.microsoft.com/en-us/sharedsource/ In addition, Microsoft employs a huge number of employees who have access to its source code, and you can't really keep a secret long when a large number of people know the secret. Efforts like bribes, appeals to patriotism, etc. will eventually successfully get someone to reveal a secret if there's a large enough group, especially since it's relatively easy to identify who works for Microsoft or otherwise might have such access. If that's not enough, Microsoft distributes executables, and disassembers & decompilers can provide enough information for static analysis anyway. So you could re-derive what you need to attack Windows if you needed the source code for some reason. Anyone who depends on secrecy of code to provide security is in trouble. Typically the real reason to keep (some) code secret is to support certain proprietary business models and to meet certain legal obligations, and are not really about security. Note that Microsoft understands this; they're quite clear in stating that the security of Windows does not depend on keeping its source code a secret.
- dividuum 6y agoIsn't that the Kerckhoffs's principle? https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle
- deleted 6y ago[deleted]
- jcelerier 6y agowindows source code has been open to academics for something like two decades
- lrem 6y agoNobody seems to mention an important aspect: megacorps like Microsoft, Amazon, Google or Oracle hire thousands of engineers each year. It's not particularly hard for a bad actor to get an agent hired into their target and gain access, for nefarious purposes, in the legit way.
- phendrenad2 6y agoRemember that anyone can manually decompile Microsoft source code. It's a lengthy tedious process, but that's nothing for a determined attacker.
- ipython 6y agoThat’s not nearly comparable to commented source code repo. “Decompiling” leaves you with a barely readable facsimile of the original code, and most likely won’t even compile again. The true value in source code at this level are the comments and symbols. Microsoft provides most ofthe symbols, the comments you can’t recover from a binary.