5 ms·
Wow. Totally unprofessional when you compare it with today's security bulletin standards. This downplays risks and blames the user. Was this common back then?
by sirl1on 3y ago
Wow. Totally unprofessional when you compare it with today's security bulletin standards. This downplays risks and blames the user. Was this common back then?
- sebstefan 3y agoI think it's alright, what shocks me more is that they published something about it and kept repeating back orifice Getting backdoored isn't a problem with the OS if you install the backdoor yourself
- userbinator 3y agoWow. Apparently, respecting user freedom and personal responsibility is now "unprofessional". I haven't seen a more blatant exposure/confirmation of the deep-seated authoritarian control-freak mindset that has permeated the whole computing industry. Yes, back then it was common and expected that users were responsible for their own decisions. Now the industry is taking away that freedom and telling them it's for their own good.
- sirl1on 3y ago> I haven't seen a more blatant exposure/confirmation of the deep-seated authoritarian control-freak mindset that has permeated the whole computing industry. Can I use this as a testimonial? Chill... at least if you want me to discuss this further. > Yes, back then it was common and expected that users were responsible for their own decisions. You do not chose and decide to be victim of a scam. At least I presume the "if you wouldn't have downloaded hacker stuff from weird websites you wouldn't have caught malware" was as wrong back then as it is now and is just shifting the blame to the user.
- vasdae 3y ago>You do not chose and decide to be victim of a scam. You should not be operating a computing device if you don't know how to use it. This was true back then and it continues to be true now.
- flumpcakes 3y agoI find this an incomprehensible position. I've used computers 25 years. I've worked professionally with them for 10+ years. I know more about the runtime and workings of a computer than any of the architects, tech leads, or principal engineers at my company. I don't know how a computing device works fully. 99% of people working in 'tech' don't. So 99% of the professionals aren't to this standard, and we expect end users to be? What percentage of car drivers are fully qualified vehicle inspectors? Do you know how to fully use your phone? Would you be aware if pegasus spyware was installed?
- cesarb 3y ago> What percentage of car drivers are fully qualified vehicle inspectors? AFAIK, all car drivers are required to go through specialized training, and pass through periodic skill examinations. You should not be (and are legally forbidden from) operating a car if you don't know how to use it.
- sjsdaiuasgdia 3y ago> and pass through periodic skill examinations. Not in the US, at least not anywhere I've lived. The only regular re-examination is an eyesight test. There is no skill testing after the initial license issuance, and there won't be unless the license status is fully lost - waiting too long after expiration, revocation, that sort of thing.
- mikestew 3y agoThe only regular re-examination is an eyesight test. And, at least in the state of WA, that "eyesight test" consists of a checkbox on a form that says, "Your eyes aren't shit, are they?". I've checked that box, and I overheard a person well past retirement age tell the same story at a restaurant. I get regular eye exams, but I don't know about the guy at the restaurant. The last time I took a physical skills test was 40-some years ago. The last time I took a "written" test was...I don't know, ten years? And guess what? I still remember getting a question wrong on that test (despite having lived in WA for over ten years at the time), and what do you know, TIL something about WA road laws. They should test me (and everyone else) more often, and not make half the questions "how much can you drink and still safely drive?"
- ta1243 3y agoIf you drive a car down a railway track is it your fault or the sat nav's fault for saying "turn left" We expect certain minimum skill in operating equipment Now open an email and have it silently install exploiting a bug in your mail client/browser/network stack, that's one thing. That wasn't this though, this was some software which did exactly what it said on the tin.
- sirl1on 3y agoSo, Back Orifice wasn't hidden in other executables, but passed on by making people download and install it in all awareness? Didn't know that. Thanks for telling me instead attacking me like OP :/
- HappMacDonald 3y agoOh no, it totally got bundled into different files using other tools with creative names like saranwrap and silkrope whose job it was to disguise the software, and after it was installed silently replace the bundled executable with an ordinary unbundled one to stymie attempts at further analysis. I'm not certain what GP is on about. There were copious ways to distribute (deliberately payload) infected files back in the day and it was common windows user practice to just download and run executables (especially if they appeared to be installers from reputable-seeming websites) and zero free virus scanning or firewall options were available: all were for pay and all were terrible. None certainly shipped with Windows itself. Plus as mentioned elsewhere plenty of third party software like ICQ enabled benign-seeming mechanisms to view documents which could be exploited to instead run infected executables.
- technion 3y agoToday's version of this would simply be an advertisement for Windows defender and a page of advise about how you sleep easy with an e5 license. I do agree some types of people would find that "professional " but I won't be one of them ..
- sirl1on 3y agoDo they really do that? Or is this hyperbole? I just skimmed some of the 2017 bulletins (aren't there newer ones?) and did not find sleazy marketing. Not that I can't imagine Microsoft actually doing that...
- technion 3y agoThis depends what you mean by "security bulletins". In general, Microsoft did stop publishing from their traditional, hand written format a while back. The closest you get this is sort of thing now, which is completely automated and frequently wrong, and assumes you know what CVE you were searching for. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36434 https://msrc.microsoft.com/update-guide/vulnerability/CVE-20... One of the bigger vulnerabilities in recent times was Printnightmare, where they did write ups like this due to visibility. I don't feel it actually says much. https://msrc.microsoft.com/blog/2021/08/point-and-print-default-behavior-change/ https://msrc.microsoft.com/blog/2021/08/point-and-print-defa... There were a lot of Twitter threads about the shitstorm that I can no longer find back when all their bulletins changed formats, but the general reason was moving their "good" bulletins behind an E5 license. Which again, I know some people consider "professional". So to actually answer your question, here's a screenshot from a paywalled security bulletin. You can see from the scrollbar I'm near the top, and the "Recommendations" are all Defender features (with "apply patch" almost a hidden detail). The statement about configuring AMSI is not a Sharepoint recommendation, it's a Windows security feature originally tied into Defender. https://ibb.co/WV1HN3q https://ibb.co/WV1HN3q And everything from here on in this security bulletin on to Sharepoint vulnerabilities - of which very little useful technical information is presented - is about Defender. Of course, not just the EDR, the first point is about EASM, a feature licensed on top of Defender. The detection hunting details further down require a P2 license on top of that to be able to use. Despite all that, it's not a fair comparison. I can't find anything in the E5 portal that is a reflection of this thread, where MS respond to a backdoor people are installing on their own.
- tanepiper 3y agoThanks for the evidence that the internet is just no fun now, too serious. Back in the day people knew how to enjoy themselves.