Hackers Exploited Word Flaw For Months While Microsoft Investigated (reuters.com) 46
An anonymous reader writes: To understand why it is so difficult to defend computers from even moderately capable hackers, consider the case of the security flaw officially known as CVE-2017-0199. The bug was unusually dangerous but of a common genre: it was in Microsoft software, could allow a hacker to seize control of a personal computer with little trace, and was fixed April 11 in Microsoft's regular monthly security update. But it had traveled a rocky, nine-month journey from discovery to resolution, which cyber security experts say is an unusually long time. Google's security researchers, for example, give vendors just 90 days' warning before publishing flaws they find. Microsoft declined to say how long it usually takes to patch a flaw. While Microsoft investigated, hackers found the flaw and manipulated the software to spy on unknown Russian speakers, possibly in Ukraine. And a group of thieves used it to bolster their efforts to steal from millions of online bank accounts in Australia and other countries.
Re: (Score:1)
*would of
Remember, kids... (Score:3)
Microsoft = Job Security*
* If you work for Microsoft, you're screwed. But for everyone else using Microsoft, you're golden.
Microsoft profit motive? (Score:3)
Everyone who wants a new version of Windows must pay a full price, and get a new version that also has flaws.
Mistake. Or not. Is Windows 10 an OS or Spyware? (Score:2)
Windows 10 is possibly the worst spyware ever made. [networkworld.com] Quote: "Buried in the service agreement is permission to poke through everything on your PC."
Re: (Score:2)
Re: (Score:2)
Knee-jerk Reaction (Score:5, Insightful)
Make the vendor responsible for losses in critical applications.
If MS had to cough up millions for every bank hack, you could be damn sure they would refine their code for such applications. Or, you know, go bankrupt. Either way, people win!
Re:Knee-jerk Reaction (Score:4, Interesting)
Microsoft software is not intended for use in critical applications, it says so in the license agreement.
If you're using it in such an environment you're in breach of the terms and so the liability comes back to you. Plus MS will sue you for pirating their software.
Re: (Score:2)
Re: (Score:2)
Microsoft Office is commercial software, if you're not paying them to keep the software up to date, then what are you paying for?
Open Source Office products, are generally gratis, and are patched in a more responsible manner. AND you have access yourself to patch it ... yourself, unlike ... Microsoft Office.
No problem (Score:3)
You can have that however you have to accept a few things:
1) Costs are going to go way up. You aren't going to pay $50 or $100 for a software package, it'll be 5 or 6 figures. You'll be paying for all the additional testing, certification, and risk.
2) You won't get new stuff. Everything you use will be old tech. You'll be 5-10 years out of date because of the additional time needed to test and prove things. When a new chip or whatever comes on the market it'll be a good bit of time before it has undergone a
Re: (Score:3)
You seem to be confusing "consumer" with "critical" applications.
You can have that however you have to accept a few things:
1) Costs are going to go way up. You aren't going to pay $50 or $100 for a software package, it'll be 5 or 6 figures. You'll be paying for all the additional testing, certification, and risk.
Only for critical software. You know, things like banks, hospitals, etc... Those guys should be making damn sure that their environments and software are secure and work as advertised. We're talking peoples lives here.
2) You won't get new stuff. Everything you use will be old tech...
This isn't much of a change from today. ATM's and EKG machines running Windows XP (or older).
3) You will not be permitted to modify anything. You will sign a contract (a real paper one) up front that will specify what you can do with the solution, and what environment it must be run in. Every component will have to be certified, all software on the system, the system itself, any systems it connects to, etc. No changes on your part will be permitted, everything will have to be regression tested and verified before any change is made.
CEO's probably would balk at this, but it's arguably necessary. It may even already be done to some extent, medical equipment must be c
Re: (Score:2)
And yet the software you are complaining about is MS Word. That is consumer software. To me, this just seems lime more "MS should be held accountable for everything because I don't like them," crap.
ArsTechnica (Score:3, Interesting)
What can you say about the CIA? (Score:2)
Word Up!
Months? (Score:2)
For how long as MSWord had VB scripting, .NET and other vulnerabilities buit in?
On the Internet: MS Windows is unsafe for any need (Score:3)
This story is so old and happens so often that it isn't news. That it continues is very frustrating for anyone who has been in the Internet industry since the Internet became popular around the release of Windows 3.1.
Windows is impossible to secure. I'm sure that if I bother to search a few darker spots of the net I will find current working unpatched Windows "total takeover" exploits.
The only good news appears to be that it used to take years rather than only 9 months for Microsoft to respond with effective patches.
Until Microsoft can be held responsible for the losses associated with using their software none of this will ever change. There is a very good reason that most Internet startups do NOT use Windows on their customer facing servers. It is just not maintainable.
Open source isn't perfectly secure, but at least knowledgeable persons can debug and patch it much, much faster than 9 months.
Microsoft usually ignores or spends a long time fixing severe bugs or design issues which can kill any business dumb enough to adopt Windows even with all kinds of regularly ineffective "3rd party protection."
Apple is better than Microsoft, but still weak in so many areas that it is also a non-starter for Internet facing servers.
Here is a simple test: If you need to add Anti-virus software or added firewalls you are using an insecure operating system unfit for use on the Internet.