Microsoft Teams: 1 feature, 4 vulnerabilities
positive.security
positive.security
This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management.
This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leave a room password unprotected bad people will enter". The level of press coverage was off the scale compared to what Teams got for far worse issues.
The vulnerabilities werent nothing but they werent even in the same ballpark as the MS teams vulnerabilities foisted on us for "security reasons" like this howler they tried to cover up https://www.techradar.com/news/microsoft-may-have-downplayed...
Zoom had and continues to have a significant developer presence in China. Those individuals are subject to CCP coercion. There was also a time when they routed American calls through the mainland [1]. That has been fixed. But it remains excessive to cast all past criticism of Zoom as Microsoft's work.
[1] https://techcrunch.com/2020/04/03/zoom-calls-routed-china/
Security flaws in a product are part of the life cycle, unavoidable and might be accepted as long as proper and timely response is taken. That's due diligence. But lying about security? That's not even negligence.
I figured that it was done by a big party that had a trusted relationship with tech journalists because they bigged up vulnerabilities that were relatively minor to journalists who didnt seem to be aware of it.
It's possible it wasnt Microsoft but the pattern of stories indicated Zoom was a public relations target of someone who freaked out after seeing how fast they were growing and MS certainly took full advantage.
I remember we knew about Zoom vulnerabilities in 2018 as well but I rarely used video conferencing and definitely not for "daily stand ups" however, I wouldn't discount Microsoft tried its best to "educate" reporters.
Zoom went from interesting tool to de facto worldwide standard in about two months. I'm pretty sure that in the offices of Microsoft, webex, goto meeting etc there was a collective WTF from leadership and people were instructed to find weaknesses. It doesn't follow that there was collusion or an evil conspiracy.
For all my harsh criticism of both Microsoft and Google I wish them well: I want them to tidy up and become trustworthy.
Because the alternative where China becomes world leading is actually worse.
For all their warts Americans and American companies have done much good and gotten way more criticism for their faults compared to others.
That doesn't however mean that they should get off the hook easily, only that we should work to put them in an position were we can actually trust each other.
So whats worse: a backdoor for China, or a giant hole for anyone interested?
I guess the latter gives us esual opportunity...
At work we were briefed in detail by spy from CSIS to avoid Zoom. I trust the Canadian spy before a trust I company with CCP ties.
The only thing I can add from that briefing is avoid Zoom, Huawei and product from Facebook, use Telegram if you can and Teams or Google current messaging solution if you can't.
also from CSIS briefing?
And vulnerabilities occur in all mainstream software.
what about zoom-calls in other countries?
Would you happen to have any actual evidence to back this up with?
Another plausible explanation, at least in my humble opinion, but one without evidence either: Everybody and their kids (for school) were using some kind of video conferencing software for the first time in this kind of professional/educational setting and Zoom led the pack, which led to more interest by white hat researchers (and probably blackhats) as well as journalists. This newfound scrutiny lead to some first stories, and then people kept digging, because "Man exposes himself in virtual class room"[0] or "Does China spy on your business" or "New security problem uncovered. Is your kid safe in the virtual class room?" kind of stories generate a lot of impressions, and zoom had a lot of problems to uncover. Maybe it took some time to uncover the various problems, leading to a continuous stream of stories, maybe some outlets delayed publishing some stories, so they could milk a story at a time before coming out with the next one. Maybe Microsoft tried to capitalize on it, but that doesn't mean they were driving the news.
[0] https://www.bbc.com/news/uk-england-south-yorkshire-55998557
The comment came from a banned account whose comments are dead by default and need to be vouched. Discussing that is as off-topic as discussing voting, and not surprisingly it’s just noise now.
HN is an anti-MS echo chamber, so comments like this become popular quickly. It's been this way for a few years now.
Which is probably why it’s so high up, because the HN algorithm probably can’t distinguish between replies agreeing with or disagreeing with a parent comment.
MS is really aggressive with Teams marketing (specially for large bureaucratic enterprise) and I could totally see them doing what you mention.
I'm sure Google Meet is used in most of K-12, I don't know about higher ed. The university I work for licensed Zoom pre-pandemic because it was superior to other videoconferencing systems like WebEx and GoToMeeting.
The city council uses Zoom and my impression online is a lot of other local government functions that are now at least partially online do too.
Don't Teams and Google Meet both require everyone to have an account just to join a meeting? Being able to join a Zoom meeting just by clicking a link, no account needed, is very good for user experience.
Google Meet, and this may have changed recently, lacked basic features like being able to quickly identify what window you are sharing. I've also seen far more call issues with Google and Teams than I have Zoom.
As for Teams, I don't have a ton of quarrels with the video meeting system itself but it's desire to jam 20 other critical workflow pieces into the software made it a huge mess, at least from my experience with it on Mac:
1) The calendar sort of works, but not really, and most features you'd expect to accomplish with a calendar actually need to be done in Outlook and not teams.
2) The chat UI is really cumbersome compared to Slack and it quickly becomes difficult to find anything if you interact with a lot of people
3) The document file system is a total cluster. Let's say someone chats me a file to look at. I click the link and the file opens in my Teams window. I review it partially and have a question for the person who sent it. I go back to chat, send a message, and then try and go back to my document. Guess what? It's gone and I have to load it again. What fun! You just have to get into the habit of forcing the files to open in their native app or load them in a browser. I'm sure there is a way to prevent this from happening but what I've found with Microsoft applications (at least on Mac) is that basic functionality like this is completely unintuitive compared to any other productivity software I've seen.
Zoom did it right and that's why it's popular.
It's a stretch to attribute to malice what can be attributable to other environmental factors. Could it be that Zoom was/is the dominant player in the video conferencing space in 2020/2021, so media outlets were keen to cover stories around Zoom? WebEx and Google Hangouts vulnerabilities have also not received as much coverage as Zoom.
You’re literally describing a thing that exists which is called public relations. I’ll admit it is unlikely for the call to be coming from inside the house, but this would be the exact kind of thing done by an agency contracted by Microsoft — for among other reasons, plausible deniability should anything become public. “Microsoft would never badmouth Zoom.”
> media outlets were keen to cover stories around Zoom
Hmmm, I wonder if there’s a field of professionals who make media outlets more keen to cover stories around a certain topic?
The logic appears to be: I saw a lot of news stories about X, therefore X was caused by Y, without recognizing that Z is just as likely a cause for X.
Perhaps it was driven by Zoom's poor security and privacy record?
Zoom banned from New York City schools due to privacy and security flaws https://www.fastcompany.com/90486586/zoom-banned-from-new-yo...
Google Told Its Workers That They Can’t Use Zoom On Their Laptops Anymore https://www.buzzfeednews.com/article/pranavdixit/google-bans...
Elon Musk's SpaceX bans Zoom over privacy concerns https://www.reuters.com/article/us-spacex-zoom-video-commn/e...
Apple pushes silent macOS update to remove web server secretly installed by Zoom https://9to5mac.com/2019/07/10/zoom-apple-macos-update/
Taiwan joins Canada in banning Zoom for government video conferencing https://www.cbc.ca/news/science/taiwan-zoom-video-conference...
Is Zoom the Next Huawei? ‘Puppet of Chinese,’ Say Critics https://securityboulevard.com/2020/06/is-zoom-the-next-huawe...
Zoom lied to users about end-to-end encryption for years, FTC says https://arstechnica.com/tech-policy/2020/11/zoom-lied-to-use...
DOJ charges highlight Zoom's China problem https://www.axios.com/china-zoom-charges-influence-1906e8e5-...
Zoom needs to clean up its privacy act https://blogs.harvard.edu/doc/2020/03/27/zoom/
Zoom security issues: Here's everything that's gone wrong (so far) https://www.tomsguide.com/news/zoom-security-privacy-woes
Mass move to work from home in coronavirus crisis creates opening for hackers: cyber experts https://www.reuters.com/article/us-health-coronavirus-cyber/...
Security and Privacy Implications of Zoom https://www.schneier.com/blog/archives/2020/04/security_and_...
‘Zoom is malware’: why experts worry about the video conferencing platform https://www.theguardian.com/technology/2020/apr/02/zoom-tech...
Ex-NSA hacker drops new zero-day doom for Zoom https://finance.yahoo.com/news/ex-nsa-hacker-drops-zero-1400...
Maybe we shouldn’t use Zoom after all https://techcrunch.com/2020/03/31/zoom-at-your-own-risk/
Attackers can use Zoom to steal users’ Windows credentials with no warning https://arstechnica.com/information-technology/2020/04/unpat...
The Zoom Privacy Backlash Is Only Getting Started https://www.wired.com/story/zoom-backlash-zero-days/
Hackers Are Selling a Critical Zoom Zero-Day Exploit for $500,000 https://www.vice.com/en_us/article/qjdqgv/hackers-selling-cr...
Researchers found and bought more than 500,000 Zoom passwords on the dark web for less than a cent each https://www.businessinsider.com/500000-zoom-accounts-sale-da...
Beware of ‘ZoomBombing:’ screensharing filth to video calls https://techcrunch.com/2020/03/17/zoombombing/
The security issues like end-to-end encryption not actually being end-to-end encryption (unless you consider the man in the middle to be two ends, forwarding messages between the other two ends) were not propaganda - they really existed. It isn't even propaganda to say Zoom published very questionable statements (or if I allow myself to be slightly less charitable: the occasional outright lie) about those issues, because it is demonstrably true that this happened.
> that I'm almost certain was driven by Microsoft
You might need to present some evidence for that rather bold claim.
> [comparison with past MS security issues]
Teams is far from perfect, I am not a fan of it at all, and that security issue was real too IIRC, but you are using some very selective reasoning bringing it up at the same time as downplaying the serious flaws present in Zoom in the same period.
Assuming you are a US citizen and were using zoom from a US location at the time.
And it strongly indicated not just technical flaws, but a company and product that did not actually care about their users’ privacy.
And that’s even without bringing the China stuff into the picture.
It was not propaganda. There was no privacy protection. I work for a K-12 and there was literally no way to configure Zoom such that it wasn't a massive FERPA violation waiting to happen. There was originally no way to gatekeep entrants to a virtual Zoom classroom. It even earned it's own term: Zoombombing [0]. It was completely unsuitable for use. It's like it was designed for the Internet of the 1990s.
The only way we figure that so many districts were using it was:
1. It was free when basically nothing else was.
2. There was no time to evaluate alternatives when the pandemic started.
3. They were hoping nobody was looking too closely.
4. They didn't properly evaluate Zoom or they just didn't tell anyone how Zoom didn't ensure privacy.
Also Teams/SfB, despite years and years of their users complaining about the limit to concurrent video feeds, never progressed past about four until Zoom came on the scene. They didn't just exceed Teams by a few, but like an order of magnitude.
I use Teams every day but thank God for Zoom driving improvement. Just underscores the value of market competition.
As a firm their ethics seem to have improved since the 90s but a few bad apples…
Zoom put a backdoor (like, a full web server) in their Mac version and didn't even remove it when outed until Apple pushed an update that killed it for them. Which was a big unprecedented step.
Mistakes happen. Total lack of action when it happens shows at the very least a total disinterest. They definitely did lack a focus on security and privacy at that time.
I agree Microsoft is pretty aggressive and teams is a pig of an app in my opinion (slow and bloated) but zoom really dug their own grave too IMO.
For what it's worth I find Jitsi delightful and super performant. I use teams a lot with work and Jitsi with our makerspace and it's just so much better at the video conferencing role.
[0] https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s...
Teams was half baked at best, and lacked a vast majority of the features that made Zoom useful. For example, it was only well into the pandemic that Teams gained the ability to have virtual backgrounds. You couldn’t have meetings with more than 10 or so people until very recently. Pretty much none of the features that made Zoom popular were even possible on Teams.
The real beneficiary should have been Google Hangouts, but Google moved too slowly (actually, it would probably be more accurate to say that Google didn’t move at all…or if they did they moved backwards).
In every instance, the previous solution (Slack/Zoom/Discord) was replaced by Teams following higher management making the switch for reasons like "it's included in Office 365" or a new hire influencing the migration to Microsoft solutions.
In every instance, the application was/is not well received by the employees - it's slow, buggy, crazy complicated and generally doesn't feel "right".
Microsoft is good at channeling security topics for their PR, but at the end of the day they make software, just like everybody else (and this software is subject to bugs, just like everybody else).
It's really disappointing that the vulnerabilities have not yet been addressed...
That said, yeah, leaving vulns and/or the irritating bugs open for as long as they have is silly.
I had a chat with an outside org, and now it is forever in my Teams history, and I cannot get rid of it.
which has the potential to be pretty embarrassing (if the chat was not work-related) or a violation (if the chat was under i.e. an NDA and the relationship ended thus "you have to delete all notes etc").
I'm sure the creative can think of additional ways this could be awkward.
The cons of Teams search is it is almost useless when you can only view the single message in the result list, e.g. a single chat message without any surrounding messages for context, and also no possible way to jump to the conversation for that message.
Unless you have a very specific detail keyword I find it useless. And indeed not being able to jump to the timeline makes it even size.
teams calling is not, they do not even share the contacts, they only sync and sometimes they do not.
Microsoft should (but won't) reconsider the idea that one chatbox to rule many underlying types of software is a good idea.
How do you know what's supposed to be in the viewport, especially if the font isn't monospaced? You have to 'render' the entire thing at least once - at least to the point of measuring the dimensions of text (not a cheap thing) and figuring out where you have to force linebreaks. And whenever the user resizes their window horizontally or does various other things, you have to do it again.
Your typical browser is already pretty good at this - not to the point some dedicated text viewers/editors are, but pretty good.
You can do so for sure. But can you do all these platform specific optimisations in Electron?
And even if you could, the reason companies go for electron is that they don't want to bother with platform specific stuff so they're really likely not to bother.
A agree a mere few megabytes of text should not bother any computer made this decade by the way and that teams is a pig of an app.
But the problem is not what's possible, it's them prioritising new features over performance and with that all the technology decisions they made.
Monkeys could barely create software if at all. That means you have set a low badness bar for Teams to surpass.
And why there isn't the ability to just delete the rich text formatting and write markdown I do not know. They can't build a bug free rich text editor or one with intuitive controls. It's the same problem I have with Jira, the rich text editor just does not work like it should.
This changed, as in broke, around a week ago. At least for me, on Win 11.
Edit: Just remembered another Teams bug from a few days ago: cut text from the middle of paragraph, paste it back in earlier in the same paragraph, ... and it appears in a smaller font.
But yeah, it's really silly how they manage to break things like this. One would think they have a test-suite specifically for their shitty editor to prevent things like this - apparently not the case. Welp.
It's not yet skype-levels of bad, where doing _anything_ beyond simple text was impossible, but it seems they're slowly getting their, update by update.
My Android client randomly signs me out, sometimes multiple times per day.
This can be remidiated by using the editor mode, albeit I found it frustrating still.
Teams put a nobreak space or something in the code that looked like a ordinary space in the diff. I am still abit mad :)
Looks like all commercial chat-software is destined to become terrible garbage, one A/B-test at a time.
If I remember correctly, there is some difference between voice call chat rooms and the instant messaging chat rooms. I don't remember which messed up whitespace. Or if I copied between chats etc.
Can't trust the text anyhow.
At least the audio is consistently good, though.
Video call on Teams is actually pretty good, but everything else just seems half-baked, thrown together without a plan. The GUI is non-intuitive, basic features are unstable, absent or hidden away. Work for a company that doesn’t use ActiveDirectory and Exchange… well now your in for at really bad time.
Another way to think of it is that the deep integration to AD and Exchange is the major reason IT departments like Teams. The video and audio calling is fine, the chat works, although it seems to annoy Slack users. The meeting calendar syncs with Exchange. Planner boards give a simple Kanban setup. File storage with Sharepoint and Onedrive integration mean that the stored files work almost like they are on my computer.
- some times the left arrow to move the cursor doesn't work
- some times images are displayed and others not
- can't have more than 4 people on screen in a video call
- the scroll is completely broken
- can't get out of the immersive mode without closing the process (the back arrow doesn't work)
And the list goes on and on...
There is jack, pulse, alsa and now pipewire for sound. On the system you can have multiple sound devices some available fully working only through pipewire, others fully working only through pulse.
If you want your app to integrate into your desktop nicely (basic thing like using tray icons) you can have completely different behaviors on different distros because there is so much variability.
Pipewire is now taking over a lot of things regarding audio/video. With fedora already fully on it. Great but the documentation is in a miserable state. Very few examples. Some distros while have pipewire running, using it for audio will just not work.
A/V issues, navigation, inability to find an existing conversation / conference (happening now on another computer) on a GNU/Linux machine, etc are almost secondary.
This also makes it impossible to resize the window. Well, sometimes. There are times when it works, and I have no idea what makes it work.
Thankfully, I usually use Qubes OS which doesn't let programs do these user-hostile things.
As a workaround, I'm pretty sure that KDE supports Alt (or meta) + right click for resizing.
I wouldn't even try running Teams on Linux, as I'm sure it's an endless source of frustration (much more intense than on Windows or on the browser). But the one nice thing of Linux is that you can force apps to behave.
I needed to change my work password twice already because I accidentally sent it to somebody when Teams suddenly popped up and took focus away from my VPN client and I hit enter.
You can if you use it in Chrome. I thought Teams was an Electron application, which makes this even more strange.
We used this prior to Teams, and in comparison, Teams is great. I'm guessing a lot of Teams users come from Skype for Business, so they are really happy with the improvements.
The server infrastructure was a bit of a shitshow, if you ever had to maintain an on-premise deployment, and it must have been a complete clusterfuck to run the Skype for Business Online SAAS service they were offering. So I can understand why they did away with it, but I'm still very irritated that this many years into Teams, it's such an unfinished mess...
Everything else is horrible - note taking is useless, the chat is full of visual noise and slow, the calendar is mostly useless and takes too long to update, file sharing is infamously convoluted etc.
We currently use Slack for chat and Teams for audio/video calls and I quite like this setup. Slack is absolutely horrible for audio/video calls, so moving to it entirely is a no-go, hope the company will keep being ok to pay for both.
Both have great sound quality other than that.
The only good thing about it is video calling. Without testing this, I always feel it's much faster/smoother and has better screen sharing quality. Also the launch screen does a great job (in comparison to Zoom for example)
Given the alternative for us would be slack+zoom+gsuite, which all have impressively daunting privacy concerns as well as pretty crappy usability themselves, I (and the people I am collaborating with regularly) am really happy with Teams.
The endless branching feature list also results in broken spaghetti code that creates a horrible subjective and inconsistent experience.
Teams is not great, but for an enterprise-tier collaboration solution that can do chat, voice, telephony, and video, it's better than its alternatives. It's far better than its predecessor, Skype for Business (fka Lync).
I feel that I read something like this almost every single time Microsoft is mentioned in a vulnerability disclosure. What makes the company so bad at dealing with security reports? I don't expect it to be a lack of talents or resources, or is it?
The micro update also tend to break something. For example a November patch broke list in chat, a futher one broke list in general. I have to enter the edit mode every time I want to enter a list.
I think the ability to use ''' to enter code snippets was also broken a while ago, and in another patch the indentation of such code block was gone as well.
I think they are trying to force us to use the editor mode.
The way Microsoft handles Teams annoys the crap out of me the MacOS and Linux versions are left to die basically.
I had to force myself to have it in clamshell mode to avoid crazy stuff going on.
Of course, sometimes you then get the "Your browser is unsupported -- please use Microsoft Edge or Google Chrome" message, whilst using Chrome...
And then when I talk about this with colleagues, they seem to be just fine with it...
Anyway, sorry about the rant. But it is just so nice to see that there are other people also dissatisfied with it, and that is not just me.
If your benchmark is Skype for Business or email then I guess Teams is indeed an upgrade, and Microsoft is betting on that.
No it really isn't! At least shouldn't be forced as a replacement for Skype.
Audio works in every other application, but sometimes Teams just decides it can't find any audio interface. Or worse, it finds one but decides "It's not working" and refuses to use it.
Using Teams in the browser is then a possible solution.
I hate Teams as much as the next guy, but I'm not sure what you mean by this. On Linux, I have version 1.4.00.26453, vs 1.4.00.32771 on Windows 11 (installed fresh today).
Also, the Windows experience is just as atrocious as on Linux, so for once I don't get the feeling that Linux is a second-class citizen. If anything, all citizens are last-class.
To me, the main missing feature on Linux is the "native notifications" feature (as opposed to the bespoke window that pops up).
Yes, and it has for a while. I don't use it that often, though, so I can't comment since when it works.
The exact same setup worked perfectly in Teams, Zoom and OBS.
Absolutely worthless piece of software.
After tracing the HTTP requests received from the link-preview generation on the server (logging the network packets) I found that the "Host" header wasn't the expected/configured xn--test--ova.de (IDNA to ASCII).
To "work around it" I needed to add an extra VHost in Nginx with the server_name "test-\xFC.de" (that just redirected to a non-Umlaut domain).
I didn't bother or even know where to report it (to MS). But apparently not using proper tooling for URL handling / HTTP requests makes one wonder about the quality of the product or even possible security implications.
MS clearly thinks Teams is "good enough" - enough of the feature checkboxes ticked that they can focus mostly on aggressively marketing it, making it seem crazy to use a separate third-party chat platform instead of Teams if you're using Azure.. even if does happen to be a buggy bloated beast, with almost unusably wretched mobile apps.
If there's just one area I wish we hadn't switched to MS-brand dogfood after making the move to Azure, it's chat/calling. It's a deceptively tricky domain to get it right in, and one where you really want as little friction as possible for all users.
"We should have stuck with Slack." - every team that ever switched to MS Teams.
More and more I wish I could work in some company that doesn't use any MS tools. VSCode seems to be the exception here.
Also sad to see how Microsoft is treating security researchers, instead of thanking them with a small bug bounty. Especially for the one (or maybe two) DoS vulns
A private discourse forum (actually any forum software, sometimes spam bots post gifs for usercounting!) does this to great effect with media too - it just allows embedding everything it seems. And then there is a university rocket-chat instance - with a big general-channel: And link-previews (enabled by default) somehow don't cache the images serverside, but let every client get them, because that's probably what works easiest with k8s, because who has a harddisk.
Of course there are concerns, especially on mobile where you may be able to do some location tracking.
Really the biggest place where IP leaking is a problem is gaming communities where people like to hammer IP addresses yo DoS people.
Also funny: if people bookmark your website in iOS safari and you don't have a favicon, safari will regularly visit your page :). Found out that my father had bookmarked my empty blog that way, because suddenly an IP from his workplace showed up in the log... Yes, in the face of the other abuse this is minor, but I think it illustrates the total disregard for privacy nicely.
Smells a bit like someone in MS saw VS Code's success and drew the conclusion that it must be because it was built with Electron, and if only all the other bits of MS who churn out crappy gunk would use Electron then they'd churn out flawless gold instead.
Well, they churned out Teams, make up your own mind I guess.
With Teams, on the other hand, they've got nothing to "prove", they just need to show up. Enterprises eat it up automatically because they already use Office, so "it's free".
I also don't think they have any hope of attracting people from outside the MS ecosystem, so they don't even try. I'm actually quite surprised they've put out a Linux version which isn't any worse than the Windows one.
The target market for Teams however is one that’s often non-technical and has never used anything better, so for them Teams is an upgrade.
It has to look good at first sight and has to have features higher management needs. But, it is is complete crap for rest of us, it does not matter.
Nowadays trying to search in the start menu or trying to log in under heavy load you just have to hope it recognizes all keystrokes.
Microsoft wrote a not officially supported Powershell script to hack this in, noting this might be needed "perhaps for a critical security release".
BTW the picture issue is still there.
What do you mean by that exactly?
Teams is dog slow, VS code is probably the fastest electron app in existence.
Teams is full of bugs, and it seems they are unwilling to fix even security vulns (from TFA). VS code is free of bugs, even though I use it way more than Teams.
Teams is not fixing even security bugs, and VS code's update cycle is so frequent that it is annoying. I am surprised how long their version notes are.
Really strange.
My organization is considering restructuring teams from 1-3 horizontal teams (full stack) for a given product to 1-3 teams that focus only on one slice of the product. Seeing articles like this makes me contemplate if there’s more security risk with this approach.
For example, it’s not clear to me why an IP address leak is considered problematic. And breaking chat or crashing on reload seems more akin to a bug a la iMessage link bugs like https://www.theverge.com/2018/1/18/16904774/ios-iphone-bug-c.... That type of issue should be fixed, but it’s not a vulnerability that’s meaningfully exploitable for either remote code execution, stealing client credentials, or stealing client data.
https://github.com/wireapp/wire-desktop/security/advisories/...
Design wise I’d much prefer the vulnerabilities listed upon clicking security, instead of a page that basically has 2 links.
It would increase the barrier to releasing software massively (possibly killing the startup scene altogether), but it doesn't mean software development would end.
Good.
It won't take years. We will have to train developers and create better tools. Then you will libraries and apps sandboxed, like we would not allow an IDE full access to the internet, or to the entire hard drive without permissions.
Say you get the task to build an RSS reader, you will have to choose:
1 use a language+standard library that is safe and the vendor offers some warranty
2 use an unsafe language or some unsafe libraries but you will have to take the risks and do the work to review and evaluate
3 in case you prefer open source you find a language and ecosystem where there is some foundation that even if it can't offer some warranty it accepts donations and contributions that are directly targeted on security, so you would have packages that would have a checkmark that was reviewed by a team.
So I would use a safe language(a GC one) with a trusted standard library, so now I can do the network requests to grab the XML files , parse them with the secure XML library and render the content in the safe Web View provided.
This means that the guys that give or sell me the XML library and the Web View will take the risk, but they can charge for their work. We would probably get smart developers using some extremely safe languages like math safe not Rust(safer then C safe) and this guys can write a maybe slower but 100% web view (maybe with less shiny animations).
Capitalism would be forced to invest in this safer tools and in training the developers, Microsoft ,Apple, Google will have to secure their unsafe OS and libraries but for sure it would not take 1 guy years to build an RSS reader that would not take over your data and send it to some hacker somewhere.
The fact that doctors are relatively frequently sued in the US is one of the reasons why US has very expensive healthcare. If you are rich that's fine, but almost everybody else would prefer more available (cheaper) healthcare with doctors who don't need to spend money on liability insurance.
"I'll have some Beware-of-the-Leopard signs printed up."
If anything, freeware (whether open source or proprietary) should be exempt from costs. You get what you pay for, after all.
(Side rant, the fact that academic computer science is so far away from real life is yet another can of worms)
The solution is simple: similar in thought to GDPR, make vendors of proprietary products above a certain size (e.g. market share, net worth, # of employees) liable for security issues even if they do not result in privacy breaches.
Vendors will then either have to release their software as open source or need to carry insurance for security issues, and the insurance companies will only provide insurance if company processes are following industry standards - e.g. code reviews, security audits during concept and development, appropriate staffing of developer teams or requiring certifications/training for developers.
I have no security education, but I care about stuff because I will be held responsible if we get pwned at some point.
IMO the biggest issue is that SWEs very rarely have long term skin in the game in the projects they are committing to.
Many have strong incentives to not care about security, day 2 ops, etc... When shit hits the fan bonuses were already paid and said professionals often moved on.
I think that tends to be lessened by having small projects with clear owners that don't jump around all the time. Companies with smaller turnover win big here.
I find it helpful to have standard low cost (certainly no monetary cost, but also little in the way of bureaucratical cost) solutions which remove the need.
E.G.
"I need to access this device's webpage from everywhere"
"Fine, go via this proxy which has oidc integration with our corporate identity, Here's the URL, let me know if there's any problems"
Doesn't always work, but it certainly reduces the fights.
How to create this incentive is an open question but more laws and regulation doesn't look like a good answer to me.
I think ultimately PM takes care of which fix/feature to be worked on?
Could Microsoft expose an API and allow third party clients to be developed?
At least with the old Lync/Skype clients, you could flip them into UI-suppression mode and drive them with COM, to replace their UI with a custom application, if you wanted to make that investment.
Potentially you could cobble together enough Graph API calls to make a lackluster restricted-feature client, but it would be a mess.