4/ The lesson is that by not doing a "full disclosure with PoC", Microsoft delayed exploitation by only a few hours.
-
-
Replying to @ErrataRob
5/ I point this out because those ignorant of 30 years of lessons in "disclosure" keep claiming that we should hide the details of patches.
3 replies 41 retweets 84 likes -
Replying to @ErrataRob
It might also be that some with 15 years of vuln response see it as valuable to give time to patch, and still provide info to defenders
2 replies 0 retweets 0 likes -
Replying to @hsultan75 @ErrataRob
there's a spectrum between "disclose nothing to no one" and "disclose everything to everyone". The truth is not specifically at any extreme
2 replies 0 retweets 1 like -
Replying to @hsultan75 @ErrataRob
The point of the story is that there *isn't* a spectrum, it's effectively binary.
1 reply 0 retweets 3 likes -
Replying to @taviso @ErrataRob
It's not. MS has created its approach, which is a middle-ground, for a reason. It proved useful to stave off attacks while patches deploy.
2 replies 0 retweets 0 likes -
MS doesn't publicly post info, but has channels to inform defenders. Result is that upon release, most big AV/detection engines are ready
1 reply 0 retweets 0 likes -
may be a bit unfair to some defenders that don't have the relationship ? Likely. But in the end it protects the vast majority of users.
2 replies 0 retweets 0 likes -
Replying to @hsultan75 @ErrataRob
Yes, the point of the story is that MS is wrong. You can turn a patch with zero information into an exploit easily.
3 replies 5 retweets 4 likes -
I want to talk to you about that "easily" part ;) I generally find it considerably non-easy to back-track from patch to input point.
1 reply 0 retweets 0 likes
It's a practiced skill, just like programming. The fact that you can find someone who can't program doesn't mean "hello world" is non-easy.
-
-
Looking forward to learning any tricks and tools I don't yet know that would make my writing patch-reversing "hello world" easier ;)
0 replies 0 retweets 2 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.