5 ms·
>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency no
by deepstack 5y ago
>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector.
It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independent security audit companies.
Digital security will never be trust unless these things are addressed in an open transparent way.
- pletsch 5y ago> You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independent security audit companies. Are you under the impression that MS doesn't spend millions on security? They're currently spending roughly $1b/year. This isn't going to be fixed by "a few pen test"
- sandworm101 5y agoIf they are spending a billion, these flaws show that obviously isn't enough.
- marcellus23 5y agoHow do you know they're not doing exactly that? For every 1 vulnerability that gets disclosed, we have no clue how many potential vulnerabilities were caught by security testing or practices. The entire nature of security is that it's impossible to have literally 0 vulnerabilities.
- _wldu 5y agoIt's not possible to find all the bugs and they only get noticed when they fail to find one. No one recognizes all the bugs that they continually find and fix.
- dahfizz 5y agoI don't understand why HN has such a flippant attitude towards cybersecurity. You would think a forum full of developers would understand the complexity of software. But the "just hire a pentester and you'll never have any bugs" and "just follow some (ill-defined) 'best practices' and you'll never be hacked" attitudes are so prevalent.
- runawaybottle 5y agoIf you are not outsourcing security, then you are not taking it seriously. It is the one thing where you need to give the job to the best person. But, we’re more likely to outsource the one thing you don’t need to outsource, like app developers.
- tablespoon 5y ago> I don't understand why HN has such a flippant attitude towards cybersecurity. You would think a forum full of developers would understand the complexity of software. HN is also full of contrarians and people who like to feel superior than everyone else (and often express that through flippant dismissals).
- fulafel 5y agoYou are hugely overestimating the level of security of software like this. There's a constant stream of vulnerability discoveries, disclosures and fixes. Those vulnerabilities don't pop into existence the week someone publicly discloses them and informs the vendor, they've been waiting there for anyone to find them for years. If MS wanted to replace a product like this with one that has a low probability of containing any remotely exploitable vulnerabilities, they'd have to go back to the drawing board, do a full rewrite witha completely different sw development process, take a lot of time or make some major functionality compromises (or probably both).