Microsoft Threatens Bountii for Exposing Bing Cashback Flaw
bountii.com
bountii.com
If you're not a pro, it's easy to lose track of best practices.
In this case the exploit was apparently self-evident to nearly any technical mind -- I think that even I understood how simple and naive the bug was -- so you could safely assume that loads of fraudsters would've been milking the system while the bug report would slowly snake through the internal organs of Microsoft before eventually landing on some engineer's table.
It's only saddening that the first reaction is through legal department. Or did Microsoft say somewhere they fixed this already? Or take down the Bing Cashback until the issue is resolved?
http://74.125.155.132/search?q=cache:3hxOgSPu460J:bountii.co...
If that doesn't work, the text has also mysteriously made its way into this EtherPad:
Feels like that episode of family guy (post-apocalypse) when the town destroys all weapons only to be destroyed by mutated stewies.
Because their only important clients - those responsible for about 90% of their revenue (Acer, Lenovo, HP, IBM and Dell) - are still buying lots of licenses.
I doubt they loose much revenue from OS vulnerabilities.
I joined the Windows Update team at Microsoft around two months ago. While I can't give exact figures, a standard non-SSIRP update costs Microsoft around 6 figures to code, test, and ship. October was our biggest release in history with something like 44 updates released (you can do the math).
Security incidents that are SSIRPs (effectively vulnerabilities that start actively being exploited, in particular with potential global impact) cost a lot more. Conficker.b was costing Microsoft over a million dollars a day for weeks in support calls alone.
Security flaws cost Microsoft a ton of money directly and through things like damaging their brand. They invested insane amounts of money improving security for Win 7, we'll see how it works out (as best as I can tell, it should be pretty effective).
disclaimer: this is my opinion, not my employer's
"damaging their brand."
How can you damage Microsofts brand any more than it already is? I don't think most people buying Microsoft buy it because of the brand. Which is why I don't think OS vulnerabilities particularly cost them in lost revenue.
I'm not sure what that has to do with whether it costs Microsoft money to handle Vista zero-day. It clearly does.
Like I said elsewhere, "Management by manager". It's when you put decisions in the hands of the least prepared to make them.
A good acid test for whether someone is talking out their ass about security: they make smart-ass comments about Microsoft. It's getting harder and harder to find reputable security researchers who haven't done work for Microsoft.
A straw man compounded to your ad hominem is not up to the usual standards here.
It is possible for you to hire people to secure an open platform from the ground up. It is up to Microsoft to secure Windows from top to wherever they think the cost exceeds the benefit for them. That's a key difference - it doesn't matter how much effort you spend securing Windows, if you are not Microsoft, you can never be sure of the results until you find them out the hard way.
Yes. I do like Free Software and I use it extensively. I also use Sun, Oracle, IBM, SAP, PeopleSoft and, from time to time, even recommend MS SQL Server when it makes sense. It would, however, be insane to simply disregard Microsoft's software appalling security record or to oversimplify it as a Free vs Evil dichotomy. It's not.
It's just that Microsoft seems to spend more money promoting their wares than properly checking and securing them. Security seems to be grafted on instead of built into.
And, for the other argument, of security issues arising only from adversarial conditions and not bugs, that's simply incorrect. Software that's correct should not have holes like unchecked buffers that allow code injections. And it's not only Microsoft who's guilty here - just about every product I use seems to have fallen for this one in a given point in its history. Still, the fact others face it does not make Microsoft's products more secure. Like I said, it's a more complex issue than this false dichotomy.
As for more sophisticated attacks that rely on memory access patterns, memory protection mishandling, improper erasure and so on, well... If the processor is not, itself, correct, you can't really expect the software to cover all the holes - only the possible ones.
Suffice it to say that I'm not a Microsoft "astro-turfer", and you're just flat out wrong --- and not only wrong, but actually making things up out of whole cloth. "More money promoting their wares than properly securing them". I'm surprised you feel comfortable making claims like that. In any case, I'm sure you'll never be convinced either way, so, enjoy the last word.
There are two statements you can try to falsify: "It is possible for you to hire people to secure an open platform from the ground up" and "It is up to Microsoft to secure Windows from top to wherever they think the cost exceeds the benefit for them". As for the third, "Microsoft seems to spend more money promoting their wares than properly checking and securing them", it's an impression and, as such, subjective. The "seems" is there because they do spend a whole lot of money in promoting their software and the "properly" is there because it doesn't matter how much they spend, the results are still pitiful, as the mountain of spam in my inbox and the constant onslaught of botnets on my clients (no - my trade is software, but my code has passed more security audits than I can remember) demonstrate so eloquently. Their programs seem to be improving with every release, true, but there is still a long way until I would entrust my data to them.
But that's just my opinion.
While I don't doubt what you say, isn't there something to be said about the fact that more attacks are targeted at Microsoft's platform than, say, OS X? While Vista may be more secure, isn't there still a higher chance of getting nailed by a security flaw in Vista than OS X purely because more people are attacking the former?
For Bank of America, no way. As soon as Bank of America standardizes on OS X, we'll have Summer '03 all over again.
It was not Conficker that cost Microsoft a million a day - it was the support to their customers that bought software that had uncorrected bugs that should have been detected earlier and that made Conficker possible. Shipping bugs costs a lot of money. Unless they cost more than getting rid of them, they are never corrected.
And if it did cost Microsoft a million a day, it cost a lot more to their customers.
If baffles me they are still customers.
Let's move the example from software to aerospace.
Someone builds planes that, when an engine inhales a bird, explode, killing all passengers and crew. They do not know the problem exists and did as little testing as required by regulations. Knowing the problem, a kid decides to release pigeons in the path of the plane, creating a quite spectacular accident. Who will you blame? Just the kid, just the manufacturer or both?
Until executive bonuses get cut, you will see no improvement over there. Unfortunately, lots of bonuses get calculated on limited scopes and don't reflect the complete lifetime of a product. This way, it's easy to close sales, pocket huge bonuses right now, get promoted, and to let the support cost bomb explode in the hands of your successor while you capitalize on your success and head up the corporate ladder.
If you look them closely, big corporations are rarely more intelligent than a sponge or a coral reef.
See my reply to axod: http://news.ycombinator.com/item?id=928267
Given the relative weights on MSFT's balance sheets of Windows vs Live Cash Back, I'd say any serious OS problem probably costs them orders of magnitude more than this.
As for a reputation... Well... There is a PHB graduated every minute.
Sometimes, software QA is a gamble. You don't spend all the money you need to make 100% perfect software, expecting to pay for the correction of all bugs that are discovered and that cost you money in support calls, lost business and lawsuits. Mind you - most of the support calls are to their OEMs.
It seems the architecture of Windows and its backward compatibility are a growing burden on Microsoft's shoulders.
The sad truth in software business is that you don't have to make your product robust enough to last forever, just long enough for you to pocket your bonus and retire.
I also have a problem with the idea that security bugs are not ordinary bugs. Bugs are parts of the program that don't do what should be done, be it about crashing, corrupting data or handing over the keys to your kingdom, they are still bugs and should be detected and corrected.
You just said absolutely nothing about security flaws OR QA. You want to try again? Because I think all you've got here is, "bugs should get fixed". Yeah, you got me there.
If their QA can't find security bugs, then, perhaps, they should rethink what software quality means to them. Remember: even if bugs costs them millions of dollars, they cost even more to their customers.
Your claims about QA and security are so wildly outside my own experience and the general understanding of my field that I'm wondering where you get the confidence to make them so forcefully. I've never met a QA team anywhere that could reasonably be left responsible for testing software security.
Still, none of the security problems I wrote into my code could be blamed on highly adversarial conditions - all of them were plain bugs, places I forgot to do something or when I trusted something one should never trust.
The fact you never met a QA team that could uncover security problems possibly stem from them not looking into the code itself and never having the responsibility of finding such problems. Validating compliance, correctness of observed behavior and even user overall experience is also called quality assurance, but it is, by no means, defining of the whole software quality concept.
Because I'm telling you that you're wrong about the relationship between QA and security in the real world.
I've called a few UK ISPs on behalf of friends when setting up their internet connections - 35p x 10mins to get a password reset.
Just doing a quick check now and Dell UK have "no fix no fee" for £19 minimum phone support. So OEMs probably like there to be some bugs in there ...
If I someone started posting info on how to create valid but fake mail-in rebate vouchers how long do you think they'd last.
Seriously though guys, glad to see you're doing well. I hope the publicity nets you a traffic spike that results in more revenue than the $2k you could have kept.