Google Engineer Finds Microsoft Security Flaw, Says Company is Hostile About It
May 23, 2013 10:51 AM
comment(s) - last by
Tavis Ormandy said Microsoft is difficult to work with regarding these issues
A Google engineer has called Microsoft out on a recent security flaw in the Windows operating system, and even said that the Windows creator is hostile toward third-party vulnerability researchers.
Tavis Ormandy, a Google security engineer, exposed the flaw on Full Disclosure. The Microsoft vulnerability, which was in the Windows kernel driver "Win32k.sys," was featured in a Full Disclosure mailing list on May 17.
Before that, Ormandy revealed the flaw on GitHub back in March in hopes of bringing other security researchers on board to investigate.
Ormandy said on Full Disclosure, "I don't have much free time to work on silly Microsoft code, so I'm looking for ideas on how to fix the final obstacle for exploitation."
Ormandy posted on Full Disclosure yet again on Monday, saying "I have a working exploit that grants SYSTEM on all currently supported versions of Windows. Code is available on request to students from reputable schools."
Ormandy also insulted Microsoft on Full Disclosure, saying "As far as I can tell, this code is pre-NT (20+ years) old, so remember to thank the SDL for solving security and reminding us that old code doesn't need to be reviewed ;-)."
Microsoft has been annoyed with Ormandy for publicly discussing vulnerabilities before they could be patched. Microsoft prefers "responsible disclosure," where security experts are asked to report flaws privately to the company.
"Note that Microsoft treat[s] vulnerability researchers with great hostility, and are often very difficult to work with," said Ormandy. "I would advise only speaking to them under a pseudonym, using Tor and anonymous email to protect yourself."
This article is over a month old, voting and posting comments is disabled
5/23/2013 1:39:50 PM
Well i would buy that if Google software was sooo perfect as to not have security flaws. There is a big Karma trap in running down a competitor in this fashion.
"What would I do? I'd shut it down and give the money back to the shareholders." -- Michael Dell, after being asked what to do with Apple Computer in 1997
Twitter Senior VP: "Diversity is Important, But We Can’t Lower the Bar"
November 9, 2015, 9:59 AM
CNN Resorts to Internet Censorship to Promote Clinton Over Senator Sanders
October 15, 2015, 2:47 PM
Breaking Bad: How to Crash Google's Chrome Browser With Just 8 Characters
September 23, 2015, 11:08 AM
Quick Note: Amazon UK Offers £10 Back on Any Order £50 or Over
August 3, 2015, 12:05 PM
Editorial: Reddit Allows Itself to be Hijacked as a Hate Platform For Racist Bigots
July 21, 2015, 6:32 PM
Mozilla and Facebook to Adobe: It's Time to Kill Flash
July 20, 2015, 6:30 PM
Most Popular Articles
Say Goodbye to Data Plans - Sprint and T-Mobile offer Unlimited Data
August 22, 2016, 6:12 AM
Lenovo vs. Asus vs. HP - Best Laptop Under $500.00
August 19, 2016, 4:00 AM
Get Ready to wait in line – iPhone 7 due September.
August 18, 2016, 7:15 AM
5 Healthy and Creative ways to add Fiber to your Diet By Monique C. Bethell, Ph.D.
August 18, 2016, 7:43 AM
Uber - Everyone's Autonomous Car Driver?
August 20, 2016, 6:01 AM
Latest Blog Posts
SolarCity’s Gigafactory: A Milesone in Emerging Technology by Lily Emamian - 15 August 2016
Aug 15, 2016, 6:30 AM
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
More Blog Posts
Copyright 2016 DailyTech LLC. -
Terms, Conditions & Privacy Information