Microsoft fixed critical vulnerabilities in uncredited update released in March
arstechnica.com
arstechnica.com
Kind of how in the WW2 they used to allow one or two or five of their own ships to be sunk by the enemy just so they don't reveal that they intercepted their communications (which I guess the argument was the intelligence would've been more useful against more of the enemies' ships).
Also, this was a large batch of exploits, and the NSA knew eventually they would get released. So they might as well be the "heroes of the day" and get companies to fix them, especially if they can get the publicity for it. But for every one of these they fix there are probably dozens of others they don't want fixed, like for instance all the vulnerabilities in Chinese routers and smartphones and smart TVs and other electronics.
It's not that hard to verify that this is their logic. Look how they want to push backdoors and how they fight encryption, just to catch a few people, even if that harms everyone else. From their point of view "more security" is a bad thing. And I'm not even sure you can expect much else from a spy agency. When you have a hammer, you want every problem to be a nail. It should be up to everyone else to push back on that logic.
But it also spies on US citizen to be sure to control dissent and shut people down.
Yups. Shut dissents down, in an undemocratic way, to keep an undemocratic gov't from receiving public scrutiny. In the mean time keep up the appearance you're fighting (inter)national terrorism. Yeah for "National Security".
Do you have a source for that claim? Because I saw now multiple people indicate that.
From what I can see Microsoft hasn't said where they got the info from. They gave a statement to the intercept that indicates it wasn't NSA, but the statement isn't entirely clear, it may be up for misinterpretation.
I think it'd be really good if someone would shed light on how things unfolded here, but from what I can see right now we don't know where Microsoft got the info about these vulns - and probably only Microsoft can clarify.
That's the bit that should really worry you. After all, if the NSA can't keep its goodies under lock and key then that means that others, possibly including your enemies have those goodies too.
It's one thing to be active in the weapons research domain, it's another to give that research away.
I could understand them hoarding their own research but this essentially confirms that the NSA doesn't care about the security of the home country as much as they care about being able to infiltrate elsewhere and to me that seems to be a badly chosen priority.
After all they can't know for sure who also has access to that vulnerability.
[1]: http://www.cgpgrey.com/blog/rules-for-rulers [2]: http://citizenactionmonitor.files.wordpress.com/2011/06/amus...
It's all just "security" or "reliability" and possibly a link to a KB which says the same.
Some large organisations still have stalwart IT managers who insist not to apply updates unless they know it affects a specific issue that they have. And now that this information is unpublished they apply nothing. It's lost on me how they keep their jobs.
Oh well.
IT managers keep their jobs by caring about stability and not applying changes without clear reason.
What if you are a bank, an airline or a hospital, with thousands of networked Windows machines, and one update breaks a specific networking feature (remember [1]) and that crashes your most vital piece of software?
1- https://support.microsoft.com/en-us/help/968920/windows-vist...
https://www.quora.com/Is-there-any-evidence-for-backdoors-in...
The responder prefaces most of their comment with "it is widely believed that" and "it is likely that", states without any explanation that the Malicious Software Removal Tool is somehow a backdoor, and that "everyone who knows about [the backdoors] is under NDA", with no evidence to support that statement either.
The fact that it got 1.5k upvotes is a great reminder that voting systems aren't a magic wand for solving quality issues. People just love conspiracy theories too much to think critically…
http://www.blackhat.com/presentations/bh-usa-09/OH/BHUSA09-O...
http://www.phreedom.org/presentations/reverse-engineering-an...
People built businesses around this.
With so many eyeballs on release diffs, undisclosed vulnerable were often discovered (and still are). With the number of experts on file observing this it should not be controversial at all.
I was responding to the Quora link (where the question was "is there any evidence for backdoors in Windows or other client software for the NSA/CIA?")
If 9/11 == inside job is say 2/10 plausible this Quora speculation like 7/10 plausible IMO.
My favorite part was when it cited "natural security".