How Microsoft's Windows Red Team Keeps PCs Safe (wired.com)
Wired has a story on Windows' red team, which consists of a group of hackers (one of whom jailbroke Nintendo handhelds in a former life, another has more than one zero-day exploit to his name, and a third signed on just prior to the devastating Shadow Brokers leak), who are tasked with finding holes in the world's most used desktop operating system. From the story: The Windows red team didn't exist four years ago. That's around the time that David Weston, who currently leads the crew as principal security group manager for Windows, made his pitch for Microsoft to rethink how it handled the security of its marquee product. "Most of our hardening of the Windows operating system in previous generations was: Wait for a big attack to happen, or wait for someone to tell us about a new technique, and then spend some time trying to fix that," Weston says. "Obviously that's not ideal when the stakes are very high."
[...] Together, the red teamers spend their days attacking Windows. Every year, they develop a zero-day exploit to test their defensive blue-team counterparts. And when emergencies like Spectre or EternalBlue happen, they're among the first to get the call. Again, red teams aren't novel; companies that can afford them -- and that are aware they could be targeted -- tend to use them. If anything, it may come as a surprise that Microsoft hadn't sicced one on Windows until so recently. Microsoft as a company already had several other red teams in place by the time Weston built one for Windows, though those focused more on operational issues like unpatched machines. "Windows is still the central repository of malware and exploits. Practically, there's so much business done around the world on Windows. The attacker mentality is to get the biggest return on investment in what you develop in terms of code and exploits," says Aaron Lint, who regularly works with red teams in his role as chief scientist at application protection provider Arxan. "Windows is the obvious target."
[...] Together, the red teamers spend their days attacking Windows. Every year, they develop a zero-day exploit to test their defensive blue-team counterparts. And when emergencies like Spectre or EternalBlue happen, they're among the first to get the call. Again, red teams aren't novel; companies that can afford them -- and that are aware they could be targeted -- tend to use them. If anything, it may come as a surprise that Microsoft hadn't sicced one on Windows until so recently. Microsoft as a company already had several other red teams in place by the time Weston built one for Windows, though those focused more on operational issues like unpatched machines. "Windows is still the central repository of malware and exploits. Practically, there's so much business done around the world on Windows. The attacker mentality is to get the biggest return on investment in what you develop in terms of code and exploits," says Aaron Lint, who regularly works with red teams in his role as chief scientist at application protection provider Arxan. "Windows is the obvious target."
Let me guess - "not very well". Wait, is that a trick question?
Are these the nice people that call me all the time from Microsoft who want to help fix my computer?
I would have thought Cisco was the obvious target given how often Cisco is used in major internet infrastructure and that there are CVEs for hard coded credentials in Cisco products just about every month.
Said my PC was infected, and PROVED it to me! Now that is service. The phone person showed me how my PC was infected and he fixed it! He could even move my mouse! Amazing.!
The article is part of a rebranding exercise from Microsoft.
Not since DOS time M$ could keep our PCs safe.
You are sorely mistaken.
Good Good
Vikas Sahu
The only way the blue team can beat the red team is to turn off their computers...
how demoralising would it be to work on either team!!!
You just can't polish a turd like windows to a high gloss finish...
It's bandaids all the way down to a festering infected herpies cluster that should have been cut out long long ago!!
so the NSA can collect on you.
All that effort kept the very best security experts guessing at what PRISM was for years.
MS kept NSA collection safe on your PC.
Domestic spying is now "Benign Information Gathering"
Microsoft, our savior for Microsoft security... oh wait!
Oh I feel safe knowing that my corporate data is protected by some 0-day gameboy hackers.
I went out to *BSD's grave on Decoration Day. The old forgotten cemetery is by the dark woods beyond the edge of town. There within olfactory distance of the municipal treatment plant you will find *BSD's final resting place.
*BSD's tombstone was shrouded by thick mosses and knots of noxious ivy. I gently pulled aside the tangled twists of thorns, and cleaned the decaying marker the best I could. My melancholy thoughts pondered that this indeed was *BSDs figurative charnel house of which so many have plaintively spoken.
Nothing is so sad as an untended grave, a loved one now forgotten. The short sad life of a doomed and fated OS makes us realize that there but for the grace of God go all of us.
I planted some wilting marigolds which I had found discarded behind Bud's Garden Center. By some miracle perhaps they will take root and bring a modicum of cheer to that God forsaken plot. My freverant hope is that the torpid colored boy who carelessly mows the cemetery doesn't slice them down, mirroring *BSD own fate against death's irresistible scythe.
Funny how things work out. Linux, that brilliant novam stellam, now runs the Internet and the world's fastest computers, while *BSD lies moldering within its forgotten grave. Let the barren silence of *BSD's tomb be a mute reminder that hubris and braggadocio were no defense when the Angel of Death's bleak umbra fell upon *BSD.
Lots of holes.
Yet electronic voting machines are still running Windows 98 and XP. Fixing modern OS's won't mean a damn because of all the crap old OS's out there.
US mid terms are being hacked again, Russia again:
https://gcn.com/articles/2018/06/01/voting-security.aspx
https://www.theatlantic.com/politics/archive/2018/05/republicans-reticent-over-use-of-hacked-documents-in-midterms/559346/
And our favorite puppet in chief is trying to get Russian into the G7, while trying to stir nationalism by attacking Canada over its trade deficit.... US has a $12.5 billion *surplus* with Canada, not a deficit.
But that's OK, because Trump can pardon any hacker. He's already pardoning a foreign man who gave an illegal campaign donation (i.e. Trump has received illegal foreign donations and knows it), wanted to pardon Ali for draft dodging (he's a draft dodger). Wants to pardon Martha Stewart (i.e. he's done insider trading), pardon Scooter Libby (obstruction of justice, perjury.... both Trump crimes), ... you get the drift, he's saying to his co-defendants that he can pardon *their* crimes, so don't turn states evidence. /rant
Microsoft cannot secure its OS, because USA cannot secure its democracy.
Are the members of the Red and Blue teams sure they're actually doing what they've been told that they're doing? Is the head of Red team a super gung-ho moron? Is there a Spanish-speaking robot somewhere in the mix?
#DeleteChrome
This trojan wreaks havoc on our systems twice a year.
HAAAA, nice one :]
The Microsoft cyber attack DW Documentary
Let me guess too :
"Red Team" - also known as, the team at Microsoft with the highest stress-related burnout and suicide rates ?
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
>> How Microsoft's Windows Red Team Keeps PCs Safe
Windows.
Safe.
Yeah, right.
aaaaaaa
They found the "off" switch?
Confucius say, "Find worm in apple - bad. Find half a worm - worse."
There are by now more Android/Linux devices out there than Windows computer. Still they don't get infected at the rate of Windows computers.
So: useless Progaganda.
Microsoft still views bugs as a nuisance which do not create revenue.
Boycott MSFT operating systems. That is a major step towards securing your intellectual property.
Whoever needs a top security server won't use the corporate-infected/NSA pwned alternatives to OpenBSD.
The Kremlin uses BSD to run their email servers. They have NSA moles and they know what they must do.
The only way the blue team can beat the red team is to turn off their computers...
Nope, thanks to the Intel IME bullshit, not even turning off will help
Most used desktop operating system
Is that still Windows 7, or did OSX take over the position?
I mean, "desktop operating system" specifically excludes OSes targeting touch-devices, e.g. IOS, Android and Windows 10.
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
(APK's work), I've flat out said it's good by BronsCon February 11 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
I do use APK's host file on all my systems at home by OrangeTide December 01 2017
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* See subject: Best part is this Linux 64-bit model is 10x faster & more efficient (does 2x the work in 1/2 the time, literally)
APK
P.S.=> Enjoy a faster/safer/more reliable internet... apk
Windows 10 actually was the security loophole. Thatâ(TM)s how it feels when I boot into it at least (on a very rare occasion).
because that's what Microsoft is known for. Microsoft = Untrustworthy.
Windows, which has been around for over 20 years, has only been internally pentested for the past four years? ... what the actual fuck. What the actual fucking fuck. So now they're four years into fixing exploits on a system that's been around for over two decades. Yeah, good luck with that!
This has got to be one of the most negligent tech companies in the world. Why anyone ever trusts them is a complete mystery to me. In any sane society they'd be sued into bankruptcy for their negligence. Imagine if this was ADT or Brinks or some other company you pay with the expectations of making your workplace secure. Holy shit.
Now I'm going to sit back and wait for the flood of morons to respond to this, saying that this is all part of the "new Microsoft" and I need to get over "the past".
and they ride skateboards too !!
Y'know, I've been thinking for a while now that it might be time to switch to BSD...
Nope. Your software is reactive not proactive. The MS team is actually preventing attacks, your work only tries to deal with problems in an indirect way long after the attacks have happened. You are the jizz mopper of security.
an exploit a day? they've been awefully quit about it, all big vulnerabilities on windows i read about are found by other teams outside MS.
right now, i got the impression Google is doing a better job finding vuls in Windows, and i can assume the 'red team' has access to the source code!
On a long enough timeline, the survival rate for everyone drops to zero.
My ware blocks attack by script/bad links blocking them before they get you (does your non-existentware?) https://tech.slashdot.org/comments.pl?sid=12213976&cid=56763942/ & even registered /.ers know that (you aren't smart enough to know it OR skilled enough to have done better yourself).
* You're just an UNIDENTIFIABLE Jealous JOWIE "ne'er-do-well" DO-NOTHING ZERO waste of life, & you know it...
(See subject - The only this I MOP is the FLOORS w/ "your kind", everytime, & you make it SO easy to do - lol!)
APK
P.S.=> ... & thanks again for proving it as you & "your kind" ALWAYS does (it's all you do, FAIL - It's all you've done in this life, lol)... apk
You're in luck then (I have a port to BSD too from the same codebase for Linux, Windows & even MacOS X).
* It's NOT easy being "World-Class" & MULTIPLATFORM (like me).
APK
P.S.=> "Onwards & UPWARDS"... apk
See subject & APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between characters & download)
Created in FreePascal/Lazarus 1.8.2 using GTK3 on OpenGL 3.1 via KDE Plasma desktop on Kubuntu 18.04 plus patches.
(Yields more security/speed/reliability/anonymity vs. any SINGLE solution (99% of threats = hostnames vs. IP address (that most firewalls use)) more efficiently/FASTER + NATIVELY 4 less!)
Vs. "Bolt on 'MoAr' illogic-logic" competitors slowing you, hosts speed you up 2 ways (adblocks + hardcodes u spend most time @) vs. competition loaded w/ bugs (DNS/AntiVir) + their overheads (messagepass ('souled-out' to advertiser addons) + filtering drivers) & their complexity leads to exploitation.
APK
P.S.=> Enjoy - it's even better vs. the Windows model on many fronts (speed & efficiency, mostly (plus a new merge feature))... apk
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
(APK's work), I've flat out said it's good by BronsCon February 11 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
I do use APK's host file on all my systems at home by OrangeTide December 01 2017
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* See subject: Best part is the Linux 64-bit model is faster & more efficient (does 2x the work in 1/2 the time, literally)
APK
P.S.=> Enjoy a faster/safer/more reliable internet... apk
Ess Pee Aitch
Ess Pee Aitch
See subject & NO AMOUNT OF YOUR BS works vs. it https://tech.slashdot.org/comments.pl?sid=12213976&cid=56765030/ scumbag... lol!
* It is ALWAYS A PLEASURE showing how WEAK you & yours are "hiding" behind UNIDENTIFIABLE "weezil" not-men posts, lol!
APK
P.S.=> QUESTION: What is it LIKE being a no good "ne'er-do-well" FAIL in this life that you are? Seriously, lol... apk
I thought you were not going to reply for a while there. SPH.