Security Update for Microsoft Malware Protection Engine
technet.microsoft.com
technet.microsoft.com
This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how this could have 'helped the bad guys'.
But Graham and others (https://twitter.com/taviso/status/861575086632968192) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes users more insecure.
Surely it is better to alert people (and especially organisations) that a major security issue has been found so that they can be prepared to patch their systems as soon as a fix is released?
If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit?
My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.
"There is an RCE in Windows" is not helping anyone.
I'm not calling you out -- quite the opposite. I like your comment because it admits to being uninformed. But for every comment like yours, there are dozens of tweets and HN comments that conceal their lay status while also having strong opinions.
In the tech world, this seems unique to security. For example, none of us would feel like we should have a say in how Rust rolls forward unless we're experts in Rust, or at least involved in Rust in some way. Yet there are many who feel they should have a say in whether Project Zero ought to do X or Y even without any experience. I wonder why?
You see the same thing with physics and mathematics here fairly often: every time quantum computing comes up some people ask some good questions, and then a bunch of people give them confident and embarrassingly wrong answers. Finally others (including me sometimes) shout them down. It's just less noticeable because those subjects are rare here compared to information security; tptacek and others are constantly fighting the good fight.
Its just something you learn real fast if you Dev. Producing something, like a Ming-Vase is really hard. Shooting a Ming-vase to smithereens is really easy (ask your Son/Daughter for indoor soccer-practice).
So yeah, you are allowed to have a opinion on things you dont know about, but that your live/livestock depends on. Everyone gets to vote on police work without ever doing a degree in CSI.
Even if you are a seasoned security researcher, saying "I know how to get into any Windows PC by sending someone to a website" paints a huge target on you.
Although the danger is kind of abstract, there is no security gain from tweeting about this, so I'd say he shouldn't have done it.
I just checked this morning, and I have the updated version already, and took no action.
Those millions would have had to have disabled windows defender updates in order to not get this update before next week.
That's a much more frequent schedule.
Windows 10 especially has a nasty streak with updates, and while security updates are smart, forcing new content updates, advertisements, and spyware into the Tuesday fast track teaches users that the only way to be safe from Microsoft is to not take software from them automatically.
Idiots like this are why Windows updates are completely forced in the first place. A couple generations of "experts" knew better and refused to let Windows update. Then billions of dollars were lost cleaning up worms that had already been patched, but people kept canceling the update dialog. See SqlSlammer, CodeRed, etc.
You had your chance to handle your own updates and proved that you cannot be trusted to do so. This is the next logical step.
One could of course get tarred and feathered until one looks like a penguin - but hey, who is that desperate. Lets ask that question again, the day such a exploit is rolled out world wide with a patch on his back.
Funny times.
Microsoft recommends for all HN Readers: Spam musubi - buy the delicious Hawaian delacay now. In a store near you! Get a free sample with this Coupon-Code: 0xDEADBEEF
Personally, I would describe the user voluntarily allowing their computer to become infested with first party adware and spyware as winning the stupid prize, but your mileage may vary.
Now you could argue that a personal twitter account is not the best medium for this warning (maybe it should come directly from Google Project Zero or Microsoft), but Tavis does have a large sphere of influence, and I invariably hear about these things through him than via other sources so it is an effective medium.
Edit: Note, the argument here is whether his initial tweet (https://twitter.com/taviso/status/860679110728622080) constitutes disclosure - I don't think it does. The actual disclosure was handled according to Google Project Zero's policies.
You want to announce upcoming vulnerabilities, fine, do that. Be up front about it and make an argument for it so people see your motivations. Don't leave people guessing what's going to happen based on the mood of the day.
Much less desirable.
It's not a secret worth millions and nobody does any of that stuff for Windows RCE vulnerabilities.
If mere knowledge of the existence of a vulnerability in a particular product is enough for the 'bad guys' to find it, well, they were going to find it anyway.
A remote zero day in Windows is worth millions on the black market, and in skilled hands the amount of damage or money you can make is nearly limitless.
People not playing these games don't see his tweet as being controversial. It almost had no details, what exactly is there to argue here? Your average copy of Windows probably has tens of thousads of unfound zero days. Its rational that they will be continued to be found.
I think the narrative of "but people on twitter are talking" is fairly bullshitty. Twitter is not reputable, anyone can reply to anyone, and unless you start naming the names of respected security researchers then these replies are from just kids and a trolls looking for attention.
https://twitter.com/taviso/status/860679110728622080
The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind the fact that there's no details in the tweet relating to the actual vulnerability or exploit.
To be clear: I don't know what relationship (if any) Graham Cluley has to the people being jerks to Tavis, and it's possible that this quote was taken out of context. However, given the backlash Tavis's tweet summoned from some Twitter users with inflexible opinions about disclosure ethics, and this alien remark in the article, I'd hedge on the two being related.
What many people have the problem with, is with Tavis' tone and his approach to announcing his findings. No reasonable security researchers find a bug, announce it first to Twitter or other mass public postings and then inform affected vendor(s) with the disclosures. That's not it should be done and it is not a responsible discourse policy, this is what people have problems with Tavis.
Tavis is doing amazing work, work that we need but he has to be careful with how he announce his findings to the public.
I can see an argument that it's unprofessional to call out a company when you need them on your side. But is anyone making that argument? All the negative replies I saw to that tweet, for example, are along the lines of "omg you ruined my weekend why couldn't you wait until Monday?"
Like this one: https://mobile.twitter.com/taviso/status/760231214812844032
Or https://mobile.twitter.com/taviso/status/845717082717114368
You don't think it is reasonable to at least tell a vendor there is a security problem first before telling the rest of the world?
Maybe responsible disclosure is the wrong name for this, I like the coordinated disclosure idea better.
Maybe I am using the wrong terms but I cannot edit my post anymore.
The mere announcement of the existence of a bug, with little enough detail that it won't help anyone find it (i.e. "RCE in Windows" is useless), does no practical harm. It might be a bit rude.
It's the announcement of details that help people find the bug that hurts. If the original announcement was "RCE in Windows due to type error in malware protection JavaScript interpreter" then that would potentially help bad guys put together an exploit before good guys can release a patch.
Stuff like responsible disclosure (coordinated disclosure would be a fine term too) is about the second one, only, as far as I understand it. It's about mitigating the practical effects of the vulnerability as much as possible, not about protecting the reputation of the company or avoiding rudeness.
I dont believe it is "responsible" to leave people exposed for 90+ days while the vendor attempts to whitewash and cover up their vulnerabilities as it so often the case.
While some software vendors might respond the vulnerabilities properly, most do not often wanting to blame shit, or even file legal action against anyone discovering vulnerabilities.
TL;DR "coordinated disclosure" is preferred.
If the vendor refuses to do anything, then yes, the 90 days should be waived.
I'm not saying we shouldn't disclose at all, I'm saying the vendors have the right to have the info first and react before the said announcements start.
I just think the tone rubbed people up the wrong way.
However, that is just my personal opinion about the reason for Travis' tweets (which happen every time a large vulnerability is discovered), and I have no security background. I trust that people like Travis, who have done a lot of work to improve security, to know how to minimize the damage from the vulnerabilities.
What a surprise! Self-importance in an security industry that relies on reputation for consulting gigs?[1] You might have missed the ominous, grandiose vulnerability names, fancy logos and the PR-blitz now associated with any vulnerability worth a damn.
I'm an outsider, but even I know NetSec twittersphere is that last place to expect 'sober' communication.
1. I don't agree with your assessment that there was self-service in Tavis' tweet. To my knowledge Google Zero doesn't consult for anyone, he was probably excited and very surprised by what he saw and he needed to get it off his chest.
but as a researcher you to have to be careful with details sometimes. i've been able to reverse engineer java exploits from security explorations full disclosure posts in the past but these contained significantly more details than tavis's tweet.
Perhaps they should wait for a few days to allow it to roll out organically before releasing the details?
The immediate effect is worse. You will have people making use of the vulnerability as soon as the information is out the door. But what about the secondary (and tertiary, etc.) impacts? Will companies be more likely to spend more on security because they will have lost the chance of having 90 days to fix an issue before it goes public? Will consumers who see the damage done in the immediate end up searching for more secure options?
It seems weird (and very very beneficial to the corporations making these security vulnerabilities) that we blame the researcher for releasing the details more than the entity who made the insecure software, sometimes even more than we blame the ones exploiting the vulnerability.
Think of it this way, we already have a given window before we go public. 90 days, which you mention in your post. Why do we have 90 days? Why not 180? If you get to the 90th day with no fix in sight, going public exposes all users to the same damage. If it were 180 days, or something much longer like 10 years, is there a chance that entities behind the software in question will just ignore the bug because patching bugs doesn't generate income like new features? Does the reasoning we have for having a 90 day clock instead of a longer maybe justify a shorter than 90 day clock?
The post published today contains information on how to exploit the bug with a working code for POC, confirmed to work.
The windows patch is published today. It's gonna take weeks to propagate to the windows computers around the world.
IIRC, they're also not disabled by the UI switch that disables other Windows updates. A user would have to go pretty far out of their way in mucking around with things that shouldn't be mucked around with in order for this update to take "weeks" to propagate to them.
Even if they patched this one bug in the interpreter, how many more are there that are not yet discovered / only known by dark market exploit vendors?
If I'm understanding correctly Defender runs with high privilege and has a very large security footprint; as such I don't think it's something I want to run.
All antivirus operate like rootkits. It's basically a rootkit trying to block other rootkits to install.
Microsoft has the advantage to have access to all windows API and they put a ton of efforts in testing/compatibility. It is the least worst of all evil.
https://technet.microsoft.com/en-us/library/security/4022344
> For more information on how to verify the version number for the Microsoft Malware Protection Engine that your software is currently using, see the section, "Verifying Update Installation", in Microsoft Knowledge Base Article 2510781.
But the link points to https://technet.microsoft.com/en-us/library/security/4022344 which doesn't include Windows 10.
Edit: guessed and found it: Start -> Windows Defender Security Centre -> (cog icon in bottom left) -> About -> Engine Version
(Get-MpComputerStatus).AmEngineVersion
Also, from powershell:
Update-MpSignature
to just go ahead and run the update process
Get-MpComputerStatus | select 'AmEngineVersion'
Than read a longwinded set of commands. PS. Cool technique with the parens.Thant screen gives you the version numbers in the place you're most likely to want to update.