Slashdot Mirror


Microsoft Admits to Hiding Flaw Details

Spongeform writes "eWeek has an interview with a Microsoft security official admitting to hiding details on software vulnerabilities that are discovered internally. The reason? Microsoft believes that full disclosure of every security-related product change only serves to aid attackers. However, companies using host-based IPS that rely on flaw information to build signatures are basically left at risk because of Microsoft's silent fixes."

3 of 147 comments (clear)

  1. So that's why Microsoft has such a low vulnerabili by Whiney+Mac+Fanboy · · Score: 5, Insightful
    Anyone remember the (deeply flawed) Cert statistics where Microsoft had 812 vulnerabilities compared to Unix + Linux's 2328?

    Well, here's another reason why that report was flawed - it turns out that Microsoft are fixing multiple vulns in one advisory - from the article:
    Manzuik said Microsoft has been silently fixing bugs as far back as 2004. He referred to the company's MS04-007 bulletin as a classic example of Microsoft announcing a fix for a single vulnerability when in fact a total of seven flaws were quietly fixed.
    Of course, Microsoft is going to argue that they fix vulns silently to prevent the 'bad guys' from using the patch info to create attacks, but this is refuted by the same researcher:
    "I don't buy the argument that they are aiding attackers. The attackers are already reverse-engineering the patches. They have the time and resources to find out where the flaw lies. The guy that feels the pain is the system administrator who is in the dark and who can't do his own reverse-engineering,"
    --
    There are shills on slashdot. Apparently, I'm one of them.
  2. Obfuscandalous! by eldavojohn · · Score: 5, Insightful

    I seem to remember being told in my software engineering class of a type of protection that provides a false sense of security. I think that Microsoft may be becoming more and more guilty of it.

    Perhaps it's time they should change their "Who would ever think to put those bytes there anyways?" mantra.

    --
    My work here is dung.
  3. Re:This article is flamebait [or are you a troll?] by Whiney+Mac+Fanboy · · Score: 5, Insightful
    Why should Microsoft tell people about security flaws which are not known about in the public domain? It makes sense to fix them, issue a patch, and then make a statement.

    If you had read the article rather than rushing to get first post, you would know that they're talking about releasing information about flaws after the patch is released.

    If you still don't understand why they should release information, consider the following from the article:
    "Microsoft's customers depend on that information to figure out how to respond to Patch Tuesday. The reality is, system administrators will delay deploying a patch based on the details of the bulletin. When details aren't included, he won't install that patch"
    --
    There are shills on slashdot. Apparently, I'm one of them.