Microsoft has released software updates to plug at least 570 security holes
krebsonsecurity.com
krebsonsecurity.com
Maybe a way to find tons of high impact bugs would be to let MS developers access those bug reports?
To my astonishment, 3-4 months later they fixed the errors and rolled out the feature I asked about.
WTH, people read those reports?
I know people do, I often get in touch with support for various services, knowing that in the sea of people not giving feedback, your comments mean a lot. But up until recently both the Oura App and their support was very mediocre.
Where's my enshittification?
It is also true that Copilot is currently in use developing Bitlocker and Sharepoint. So I wouldn't be confident saying it was one or the other.
Some of these threads make me think every line of code written pre-LLMs was apparently perfect in all ways. Feels like romanticizing the past.
That is the issue with vibe coding. Increased output but reduced understanding. So if something does go wrong, one has to hope that there is still enough understanding to address it quickly.
But a separate code review agent does much better, in my experience.
The code review agent usually has feedback to be resolved before committing, which includes bugs and unhandled edge cases. Sometimes the primary context is understandably embarrassed.
Sometimes it truly be your own people.
I use Claude to build me a small web app I needed for ages, I'm using its superpowers to discuss/talk about architecture /brainstorm/build plans, and always a fresh context with the built plans.
A few times the plan implementer (subagent writing a code assigned to the task) found something lacking (more often it was test issue related to the code, not the actual flaw of the implementation plan), fixed it on the fly, or found something in the review (last step of each task). Also there's always a technical review for each "slice" (set of tasks), consisting of code review and e2e tests.
Only when it passes I do the fresh code review of the changes with the Opus or Fable again. Happens rarely rarely, but it did found a few issues.
Code works every time, I have yet to find the fault myself.
Of course there are issues and I need to read the output especially in the planning phase very carefully and yes, Opus disappointed me many times trying to weasel out from something it "agreed with me" (and entered into architecture + todos)...
Of course right after agreeing to use devcontainers it proceeded to attempt installing a handful of node modules in my os, so intended up running it in the bwrap (pain in the ass in itself).
But it works, it's fascinating, and I have the app I actually needed.
Not magical but useful.
I suppose you're a cake enjoyer, miss Marie Antoinette?
You have transferred all the skills and knowledge to the AI. When the skills are gone, who's going to teach you to do any non-trivial job? What will give you any sense of accomplishment when all you do is ask the AI but have no capability yourself?
Even if you have a guaranteed income, because "your AI" is getting paid for the work, where will you be with close to 0 contribution to anything? Maybe we're overreacting and this will never be an issue. I know we shouldn't take cues from fiction to predict reality but it's hard not to picture a world with a combination of Idiocracy and Wall-e (or the famous "Paradise" Matrix) where we decay because the change is so fundamental that we aren't ready to adapt.
Basically what is left is internal politics and cross company dynamics until we get to the point where a company is self autonomous.
Perhaps it has always been the case that people would be happy if they shared the benefits, but that is not how the world run by billionaires works.
Probably, but just proves people can ignore bad things when they benefit them.
Not what it pretends to prove, that the thing isn't bad.
Sure there are _worse_ guys, but the supposed good ones aren't.
We even have companies implementing solutions for ffmpeg vulnerabilities themselves instead of just handing them the vulns to fix themselves.
It's very possible the tide reverses if it's not in people's interest to advocate for AI anymore, so we better not get too used to it just in case.
It's nice that we currently have an alignment of AI advocacy and infosec, though. Maybe Microsoft can even point their AI to their questionable UX and UI practices next.
It this is true and Microsoft devs are using agents it means that AI is doing a shitty job and is introducing more bugs/vulns per month than it fixes them. Otherwise you would have had a lot of bugs/vulns fixed in the first 2 security updates then a steady and significant reduction every month because any new code would have been scanned and fixed before release.
:^)
Installs Windows 7 with new patches
But if I'm wrong, please do point us in the direction of known issues with the registry.
That was a long time ago though, it’s pretty solid now and has some benefits over storing settings in a bunch of text files such as more granular permissions.
Running queries on the registry like SQLite? Nope. The Windows registry internally from what I've been able to read is a weird reimplementation of a file system (a trivial database I guess but a real database lets you index on things other than name). It's compact but as far as I know completely unofficially documented.
(Most data structures with unique names or ids for each data item could trivially be considered databases, but generally if you say something is a database, you typically expect to create queries more sophisticated than "select data where name is X" and also expect to be able to create or use separate indexes to support those queries.)
The reputation of brittleness and danger of the registry is because Windows stores a lot of configuration parameters there that the kernel uses as boot, but because it's not a plain text file, comments explaining what the settings do can't be right there in the same place you're editing.
As one door closes, another opens
"Features"
"Fixes"
Job security
Security holes
The threat model is Microsoft
[0] https://www.neowin.net/news/it-admins-feel-overwhelmingly-si...
There used to be a brilliant weather app here in Oz back in the early days of iOS. I always loved the update notes the author provided. One was "Fixed one grammatical error and introduced another one, can you find it?"
But jumping to assumptions that fixes introduce bugs is a bit rash and assumes incompetence / unprofessionality / unmonitored AI usage / kneejerk bugfix processes.
If 20 years ago you told me a single piece of software had 428 vulnerabilities I wouldn't have believed it.
If Chromium has that many security bugs, perhaps the move fast and break things approach of spraying diarrhea masquerading as code into a keyboard — in a rush to add new features no one asked for — needs to be reexamined.
For something as complex as an operating system or a web browser, even one from 20 years ago (say, Windows XP or IE/Firefox) I wouldn't have believed there were 428 vulnerabilities either, I would have assumed there were much more than that.
Actually I don't need to think / assume, it's an open source project.
That said, sure, it had a fraction of the features back then, and only a fraction of the world population was connected to the internet.
And the world was better for it. Connectivity and internet are not inherent goods. They can be used for good purposes but it is hard to argue that has been the mean.
Google asked for them. That's all that matters.
If it has 1 vulnerability in every 10k loc of code we'd be talking about 3,000 vulns (with no churn) - we used to care about defect density, and most software wouldn't go more than a few hundred lines without SOME bug, whether that's a "vulnerability" is often a layered question.
I mean we've gone full circle and are now deploying browser interfaces as full blown applications to get around the bit where you give a browser system access, but still.
> It would be nice if microsoft had windows update for .net, visual c++, office, windows, edge ... just all their software in one updater...
The pattern moved to packaging in all your dependencies.
Winget/Microsoft Store etc could auto-update your apps even with packaged .NET DLLs, though.
For example, Mariner (now branded Azure Linux) is a Microsoft-supported Linux distribution. So in this list of 570 vulnerabilities, Microsoft have reported 100 vulnerabilities inherited from all sorts of open source software projects included in their Azure Linux distribution. The OpenSSH vulnerabilities are described in better detail at https://www.openssh.org/releasenotes.html where it implies 2 vulnerabilities were detected with Swival Security Scanner (using LLMs) and another 6 by other researchers/companies (using undisclosed methods).
As an example of one of the OpenSSH vulnerabilites CVE-2026-59996 which is attributed to Swival Security Scanner, Swival have published the output of their automated vulnerability detection report at https://github.com/Swival/security-audits/blob/main/openssh/...
https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-fram...
Releases without cve patches used to be quite common, max ive seen before were 3
Windows (like Linux or macos) contains an enormous amount of code, and with large code-bases you're certain to have security issues.
Finding these security issues and fixing them seems like a good idea, no matter how much you love or hate Windows.
If only real intelligence found the fucking things instead.
As ye sew, so shall ye reap!
Not sure what the biblical quote is about either.
Probably working as intended...