Microsoft responds to IE mouse tracking vulnerability
blogs.msdn.com
blogs.msdn.com
ORLY? The imagination of a Microsoft engineer quite clearly is no equal to the imagination of a creative exploiter. After all, nobody could imagine the Morris Worm, or Word Macro viruses, or even SQL Slammer.
Attacks come through exploitable vectors. Lining up those exploitable vectors may seem tricky, but that hasn't stopped this from happening. And frankly, this particular attack vector seems to be one of the more exploitable ones.
At least in Firefox on Linux, the mousemoves are only triggered when the mouse is directly over the page itself, not even when over the tab-bar etc, nor when over the Gnome 3 on-screen keyboard (which overlaps the page).
It's an x, y position, what possible use is it? Two integers.
MS are right about this, this is just spider.io being alarmist for free publicity.
Someone should just make a program that does that, and this will all be settled. Maybe even make it guess what kind of virtual keyboard was used.
Panic and tarring and feathering of Microsoft's security team is only justified if the risk is severe.
If MS had come out and said "We're working on fixing it, but we don't think it's a critical vulnerability" - that would be understandable. What needs to be called out is if they come and say "This isn't an issue at all".
If some website was leaking password hashes, would "well the hashes are so strong that this isn't really an issue" be an acceptable response?
While the risk may not be severe, and not of the scale of tarring let alone feathering, it is a risk that must be addressed. As the article says, We take these risks very seriously.
"We take these risks very seriously. We analised it, and concluded that we shouldn't take this risk seriously."
Interesting wording of the message. Microsoft tries to lead the attention from the real problem to an analytics company that can't stand the heat of competition.
We learn something new every day.
"There are similar capabilities available in other browsers. Analytics firms can expect to do viewpoint detection in IE similarly to how they do this in other browsers."
Aren't they just throwing their hands up in defense and telling us "We're not the only ones! Everyone else is doing it too!" That's slimy.
I think you are stuck in the past. Microsoft has dramatically improved the security of their system. I've been using Windows as my primary OS since 3.11 days, and I hated Microsoft guts for cutting corners and shipping crap. Not anymore. They really pulled their act together in last couple of years. From Windows Updates, to mitigation tools like EMET, to much improved MSDN documentation - I really can't be believe that I'm saying this - they did a great job. So please if you feel like bashing M$, there's a dedicated website for that... it's called Slashdot :)
yes they did, but their perceived image is still badly damaged
Really, it sounds more like something one might write on an internal mailing list than a message intended for general consumption. Rolling your eyes about seemingly overblown theoretical worries is fine, but one should be a bit more contrite in public.
* "Fires when the behavior property of the marquee object is set to "alternate" and the contents of the marquee reach one side of the window." -- http://msdn.microsoft.com/en-us/library/ie/ms536910(v=vs.85)...
"Whilst the Microsoft Security Research Center has acknowledged the vulnerability in Internet Explorer, they have also stated that there are no immediate plans to patch this vulnerability in existing versions of the browser."
http://spider.io/blog/2012/12/internet-explorer-data-leakage...
So, instead of fixing it:
- receive vulnerability report
- don't fix it and wait until there's PR disaster
- issue statement that now "we're working actively to fix it"
- [future] fix the issue
My question, again -- why the hell they didn't fix it in the first place? Why go though this? Do you have to be a psychic to figure out that any Microsoft's non-response to vulnerability (even if its effect is overblown) is a PR disaster?
More concretely: If, hypothetically, on October 1 2012, two security issues were reported, and this is one of them, which one do you think they should have fixed first and rushed an out-of-band patch for? Do you think it should have been this one specifically because it's a PR disaster?
I agree that faster action is always better, and that better communication is always better. But you have to understand that teams working on products this large do not move quickly. In the time since this issue was reported to Microsoft, we have only passed through roughly one release cycle of Firefox and Chrome. So, assuming an identical issue was found and reported in Firefox or Chrome on the same date, would the fix even be in customers' hands? Most likely only if it were considered important enough to rush a fix.
It is certainly information that COULD be useful as part of an attack, but it seems utterly ridiculous that just mouse information would somehow enable you to compromise the security of someone's bank account.
Private information should certainly remain private, and I don't doubt that this leakage will be fixed one way or another, but this really seems more like paranoia than anything else unless there's at least a concrete description of how the data provided is enough to actually inflict harm. Lots of potentially useful data is exposed by browsers (and browser plugins) every day; this isn't the only bit.
This could be used to potentially track entropy of encryption key generation(such as trucrypt or, the new MEGA sites implementation, any site or program that employs mouse-movement/key binding for entropy.)
Mega Screenshot: http://cdn.thenextweb.com/wp-content/blogs.dir/1/files/2012/...
Security Thread on Bank Login virtual keyboard: http://security.stackexchange.com/questions/22774/my-bank-ma...
Just something an idiot can think of so, any black-hat is just having fun @ this point.
In addition, the ubiquity of IE makes the collection of analyzable data from which patterns may be extracted practical, e.g. one could probably learn to identify specific virtual keyboard layouts.
Finally, given the degree to which persons are identifiable while browsing, and the persistence of tracking data, finding whales is perhaps more likely than many people might imagine.
In "spear" or "whale" phishing, the attack is targeted at specific individuals; whales are high-value targets such as corporate executives. In such cases, the attacker might e-mail a personally-addressed fake subpoena, invoice, or memo using another exec's name.