Showing posts with label microsoft. Show all posts
Showing posts with label microsoft. Show all posts

Thursday, July 13, 2023

The patches that never end

from here and here

Maybe you thought Internet Explorer would be ancient history by now, but unfortunately Microsoft is still making security updates for it.

Friday, May 12, 2023

What are the chances hackers will take the year off?

from here and here

There's a security vulnerability in the secure boot feature of modern computers. While the patch for this 0-day was already released, it won't be enabled by default until Q1 2024. That's a long time to wait for a fix. In theory you can probably enable this fix sooner than that, but most people aren't even going to be aware of it, so most of the vulnerable computer population will remain vulnerable for basically a year, giving attackers ample opportunity to take advantage of it.

Wednesday, March 15, 2023

A digital snow day

from here and here

I imagine if you can still get Internet on your phone, a digital snow day while you wait for 83 patches to be applied to your PC might actually be a good thing. No work and all play. It's almost enough to make me wish I had a phone.

Friday, December 9, 2022

Microsoft's IE, they put that shit in everything

from here and here

Thanks to Microsoft's misguided efforts to make their inferior browser an integral part of the Windows platform, the IE rendering engine was stuck into all sorts of things - and now, even though the browser has long since been deprecated, governmental hackers are still using IE exploits to break into systems because IE is embedded into MS Office products. Thanks for nothing, Microsoft.

Wednesday, November 9, 2022

Maybe they have too many products

from here and here

Look, I know all software needs to be patched on occasion, and I know it's better that it gets patched than if it doesn't, but there are just soooooo many Microsoft patches! I can't be the only person who tires of hearing about them.

Monday, October 17, 2022

Flunking Cryptography 101

from here and here

The revelation that Microsoft Office uses ECB (electronic codebook) mode for it's encryption (not just now but as far back as 2010) is stunning. If you've read a book on cryptography then you would know better than to use ECB mode. If you haven't read a book on cryptography then what the heck are you doing writing the crypto code in something as important as Microsoft Office? 

How do you put someone so green in such a position? Alternatively, if it wasn't a mistake, if it wasn't a matter of a lack of experience (because the failings of ECB were widely known long, long before the creation of Office 2010 - I knew about it in university in the 90s) then could this have actually been a kind of backdoor?

Friday, October 14, 2022

No location tracking data for you!

from here and here

The newest thing that's supposed to be the end of passwords is the passkey, and colour me shocked but it requires a cell phone. Now cell phone based authentication has been misused for tracking so many times now I'm not even going to pretend to believe there was any other motive involved in that particular design decision.

Monday, July 11, 2022

We're never going to have trustworthy computing at this rate

from here and here

Not that I trust Microsoft's vision of "trustworthy computing", but people have been sounding the alarm about office macro malware literally since the macro feature was invented. To have macros finally disabled after all these years and then almost immediately re-enabled again is a huge disappointment.

Friday, June 17, 2022

Clean your own house first

from here and here

I realize that Microsoft Defender is a lot better than MSAV was, and that it may even be good enough for PCs, but I don't think it's reached the point of making PCs safer than Macs yet.

In addition to that, I have difficulty imagining most Mac owners using an antivirus at all, never mind one by the makers of Windows. Many Mac owners joke that Windows IS a virus.

Maybe some day MS Defender for Macs will make sense, but not before they clean up their reputation and their own platform.

Monday, June 6, 2022

Tick Tock, Microsoft

from here and here

While I realize it can be tough when all supported versions of Windows are affected, I would still expect Microsoft to move a little faster to deal with a zero-day that's actively being exploited.

Tuesday, April 26, 2022

What is xyz.exe?

from here and here

Never mind the annoyance at seeing these new binaries popping up at regular intervals, there's also the issue of investigative fatigue and the diminishing value skepticism has when most of the new binaries your security software alerts you to are just additional Microsoft detritus that came in on the most recent Windows Update.

Tuesday, March 15, 2022

So much for trustworthy computing

from here and here

Windows 11 Pornado Edition seems like the obvious conclusion to Microsoft's experiments with putting ads into the operating system. I wonder if they had that in mind.

Thursday, February 3, 2022

How not to put your own house in order

from here and here

I know that Macs get malware, and I know it's important to highlight that fact in order to combat the false impression (that Apple actively nurtured for years) that Macs don't get malware, however... When Microsoft draws attention to Mac malware it, it feels like it has a different meaning - like they're trying make themselves look better by making a competitor look worse.

Friday, October 8, 2021

Don't make me use the force shutdown

found on Reddit

Do you think Microsoft realizes Windows Update is being compared to a villain now? Do you think they care? Maybe they're the real villains in all this.

Tuesday, August 31, 2021

Bot herders are going to love all the unpatched systems

from here

I'm not sure if Microsoft realizes how unpopular Windows Updates are, but threatening to withhold them isn't going to get them the response they want. If anything some people are going to avoid upgrading their hardware just so they can have an unobtrusive computing experience.

Monday, August 30, 2021

Somebody set us up the vuln

from here and here

If you use Cosmos DB in Microsoft Azure, you should probably change your keys, even if Microsoft didn't warn you to, because everyone's keys were up for grab at some point.

Wednesday, March 10, 2021

Disclosure Pitfalls

from here and here (image source, article)

The problem with informing the public of vulnerabilities is that the bad guys get included and then they do this sort of thing. It could be a long time before everyone is patched, but it certainly not a long time before everyone's a target (everyone with a vulnerable exchange server, that is).

Friday, December 18, 2020

Where would you like to crash today?

from here and here (image source)

Hard to imagine anyone thought this was a good idea. Personally I find it terrifying. I don't ever want to be in a car that's powered by Microsoft.

Wednesday, September 16, 2020

Blank IVs - Not Even Once

from here

This may go over a lot of people's heads, but as someone who has encountered crypto code that ignores initialization vectors because the programmer was just following examples in MSDN, the fact that Microsoft themselves have mishandled IVs in their own code just fills me with such schadenfreude.