Google Engineer Finds Microsoft Security Flaw, Says Company is Hostile About It
May 23, 2013 10:51 AM
comment(s) - last by
Tavis Ormandy said Microsoft is difficult to work with regarding these issues
A Google engineer has called Microsoft out on a recent security flaw in the Windows operating system, and even said that the Windows creator is hostile toward third-party vulnerability researchers.
Tavis Ormandy, a Google security engineer, exposed the flaw on Full Disclosure. The Microsoft vulnerability, which was in the Windows kernel driver "Win32k.sys," was featured in a Full Disclosure mailing list on May 17.
Before that, Ormandy revealed the flaw on GitHub back in March in hopes of bringing other security researchers on board to investigate.
Ormandy said on Full Disclosure, "I don't have much free time to work on silly Microsoft code, so I'm looking for ideas on how to fix the final obstacle for exploitation."
Ormandy posted on Full Disclosure yet again on Monday, saying "I have a working exploit that grants SYSTEM on all currently supported versions of Windows. Code is available on request to students from reputable schools."
Ormandy also insulted Microsoft on Full Disclosure, saying "As far as I can tell, this code is pre-NT (20+ years) old, so remember to thank the SDL for solving security and reminding us that old code doesn't need to be reviewed ;-)."
Microsoft has been annoyed with Ormandy for publicly discussing vulnerabilities before they could be patched. Microsoft prefers "responsible disclosure," where security experts are asked to report flaws privately to the company.
"Note that Microsoft treat[s] vulnerability researchers with great hostility, and are often very difficult to work with," said Ormandy. "I would advise only speaking to them under a pseudonym, using Tor and anonymous email to protect yourself."
This article is over a month old, voting and posting comments is disabled
5/23/2013 12:09:38 PM
Dear Tavis Ormandy we apologize for for not responding sooner as the developer has a date with a girl.
We realize this may require additional explaining by your subsequent e-mails and your need to share this with others that are also not equally interested in the female species.
We highly recommend doing this sometime instead of staying home looking for code issues and thinking this is a higher priority than going outside once in a while.
“And I don't know why [Apple is] acting like it’s superior. I don't even get it. What are they trying to say?” -- Bill Gates on the Mac ads
Quick Note: Amazon UK Offers £10 Back on Any Order £50 or Over
August 3, 2015, 12:05 PM
Editorial: Reddit Allows Itself to be Hijacked as a Hate Platform For Racist Bigots
July 21, 2015, 6:32 PM
Mozilla and Facebook to Adobe: It's Time to Kill Flash
July 20, 2015, 6:30 PM
Instagram Bans "Curvy" From Hashtag Searches, Provokes "Plus Sized" Outrage
July 16, 2015, 1:20 PM
Mozilla Promise Punctual Windows 10 Firefox Release, Teases at iOS Arrival
July 7, 2015, 3:08 PM
Netflix Announces 7-to-1 Stock Split, Eyes Explosive Overseas Growth
June 23, 2015, 8:18 PM
Most Popular Articles
Exclusive: Google's "New" Search Icon Was Created in 2008 by Russian Designer
September 2, 2015, 6:45 PM
Kentucky Man Faces up to 10 Years in Prison for Shooting Drone Trespasser
August 13, 2015, 2:58 PM
Windows 10 Hits 75 Million Users; Grows Nearly 4x as Fast as Windows 7
August 28, 2015, 10:22 PM
Microsoft's Flagship Windows10 Lumias Rumored to Pack 25 Minute Charge Times
August 31, 2015, 8:13 PM
"KeyRaider" Hits 225,000+ iPhones, Mobile Malware no Longer Just a Droid Thing
September 1, 2015, 11:50 PM
Latest Blog Posts
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
More Blog Posts
Copyright 2015 DailyTech LLC. -
Terms, Conditions & Privacy Information