Shadow Brokers exploits are patched or inactive on supported Windows platforms
blogs.technet.microsoft.com
blogs.technet.microsoft.com
Looks like some amateur security researchers forgot to patch their test VMs.
Also, I see a lot of green accounts in this thread...
I built and updated two servers on spinning rust last week and it took six separate reboot cycles and nine total hours.
It probably isn't about "forgetting", as much as considering that there was indication patches were relevant and you wanted to start this research today.
Edit: It's easy to call people "amateurs" in hindsight, and not necessarily fair.
If/when Microsoft do call out the NSA, I imagine it'll a) be filtered through their press/PR teams and b) be after they've had time to verify the source (it seem overwhelmingly likely to be NSA-originated, but I'd guess MS will do their own investigation and not just take it at face value).
Where do you get that conclusion from? I don't read any such claim from this advisory. MS seems at least for now to stay silent how they got info about those exploits.
There are various ways this could've happened. NSA could've warned them. Shadowbrokers could've warned them. Someone else with inside knowledge could've given them anonymous tips. From the current available information we don't know that.
This probably explains why MS skipped February's patch day. They were extremely busy fixing all of these and wanted to do them all at once.
So none of the exploits should be a problem if you're on somewhat recent versions of Windows and Exchange (as applicable). If you're still on Windows Vista, XP, 2000 or NT, you likely have bigger problems already.
Windows 7 was released in 2009, eight years ago. I wouldn't call that "somewhat recent"
That's a very polite way to say "fuck you, pay me".
Seems like you're arguing MS should switch to a subscription-based model for Windows like most "continuously updated" software has because otherwise I don't see how you can expect them to provide you with free updates perpetually year-after-year after you paid them exactly once for software delivered as-is.
Personally, I avoid everything Microsoft, but I think their support horizon is fair. Tying telemetry to security isn't in my opinion, but it's a different discussion.
So you can expect 3 years from Google for an Android device. Microsoft are already stretching well beyond that. They deserve their props.
https://en.wikipedia.org/wiki/Red_Hat_Enterprise_Linux#Versi...
Windows Vista was released in 2007, so I'd say it's fine.
I don't use their products (except vscode/typescript) but I appreciate the work they do anyway since windows botnets etc are an ever present threat to the fabric of services running on the internet.
They really threw resources at it with a top down driven focus to fix their security issues.
It worked.
Still seem abusive towards their customers, but that's most huge software companies, and doesn't bother me concretely, since I'm not one.
There's not a whole lot you can blame MS for here, except for the bugs existing in the first place (which is all but inevitable given the size of the codebase and the amount of scrutiny under which various groups put it).
A cheap 1GB video card can be had for $25.[0][1] And it is currently supported for the Windows 10 platform.[2]
Which is not to say that Linux and/or an Android tablet wouldn't be the best solution, just that the purchase and installation of a new video card is maybe not as expensive as would seem.
[0] - https://www.newegg.com/Product/Product.aspx?Item=N82E1681413...
[1] - https://www.newegg.com/Product/ProductList.aspx?Submit=ENE&N...
[2] - http://www.nvidia.com/download/driverResults.aspx/112596/en-...
http://www.pcworld.com/article/3189990/windows/microsoft-blo...
One thing is a bug, another one is a backdoor. Are these good faith bugs or willful backdoors? Most likely they're bugs, but it is hard to know.
If I was Microsoft and I wanted to willfully plant a backdoor, I would take precautions to be able to get away with it if caught. Because security researchers can analyze them, and foreign governments have Windows source code, leaving intentional bugs as the only choice.
Now, the reasons I am suspicious of Microsoft:
- PRISM. Which is unequivocally mass surveillance.
- The Flame malware was able to install itself via Windows Update: http://www.computerworld.com/article/2503916/malware-vulnera... . The means by which the Flame authors achieved this are easier to explain if they received help from Microsoft.
- When Windows NT SP5 was released, the build accidentally came with debugging symbols (i.e: variable names were visible in binaries). A researcher found a variable called "_NSAKEY" containing a key which could be used to forge signatures. https://en.wikipedia.org/wiki/NSAKEY. Microsoft's explanation was that it wasn't related to the NSA, and that NSA in that context meant something else.
It's enough if the NSA has people working at MS on their payroll.
But true, it's not right to assume any particular vuln is from spies.
Oh, and a new account, too. I should hope that few people here would be so naive as to not see through you.
> Are these good faith bugs or willful backdoors? Most likely they're bugs, but it is hard to know.
My suspicion on Microsoft has more to do with the latter facts I mentioned.
Then, you need to understand this happens within the framework of espionage, which is by nature concealed and discrete, and not necessarily with consent (e.g: infiltration).
...trying to hide in plain sight, implemented by a major corporation so nation states cold exploit customers.
> This idea that Microsoft is deliberately introducing bugs into its software so nation states can exploit them is so absurd, it really is tinfoil hat conspiracy theory ludicrousness
Replace Microsoft with AT&T and suddenly it makes sense?
give us a fucking break from such dangerous naivety.