tplacek's point isn't that source is worse than disassembler output, it's that governments already have and have had access to source for a while (by design as Microsoft does provide source access to many customers, partners, etc). The tooling to dissemble built versions and craft exploits has also existed for a long while.
If source access enabled a rash of zero days, that point in time would have come long in the past.
Not that alternative means were likely employed for a number of years before that.
Nation state hackers with Microsoft source code 'on my'.
Even commercial-wise I doubt it's much concern for making products. Source code doesn't equal a software business, every business knows that. Unless there's some unreleased AI source code sort of thing.
Good question. I have zero insight to the matter.
However, I have worked at a vendor when they decided to open source their code. It was a much smaller code base than what Windows probably is. It is quite a big effort. There can be all kind of dirty stuff in the code that you need to clean up. Either for legal reasons because you have purchased the code many years ago, but you are not allowed to publish it. So you need to dig out old contracts and have legal to check what was written when nobody even remotely thought that you could ever open source. And there might be engineering reasons that some code is so bad that you can just not show it.
Wasn't there this story some years ago that Microsoft had some odd DLL in Windows(?) that they couldn't even rebuild themselves anymore, because it required a compiler that has gone out of support years ago. I don't remember the details, but I am sure a code base with the history and size of Windows has some dark spots. Unless someone can tell me convincingly that Microsoft nowadays has a CI this that builds really everything from source in a fully reproducibly manner. I guess if they do they would have proudly reported at a software conference about it. I am not aware that they would have done that, but I am not actively following that field.
In my opinion the smooth operation of our infrastructure relies less on its security as it does on the discretion of the hackers that have already compromised it.
This works...until you go against a target that's heard of fuzzing before and has the time and money to do it to their own code.
The really interesting Windows exploits require a combination of "throwing stuff that will flummox the software" and a deep level understanding of structures hidden to the average developer. Look at Yardin Shafir's really wonderful blog post about developing a kernel bug to a PoC - there's a lot of moving parts and security checks in modern windows, and having the source is a HUGE help.
I also found another hint about their findings in this PDF written by Yarden's co-researcher Alex Ionescu: https://www.usenix.org/system/files/woot20_slides_ionescu.pd.... One of the slides specifically mentions the use of fuzzing tools to find these issues.
If there are other, better links I don't know about, please kindly share. :)
Here's a tweet from the original finder: https://twitter.com/gabe_k/status/1330966182543777792?s=20
Yarden & Ionescu's work are both really top notch. Also anything by Google Project Zero if you want to do a deep dive on the subject.
Umm sir, have you somehow missed seeing the quality of Microsoft products in the last few decades.