Google Engineer Finds Microsoft Security Flaw, Says Company is Hostile About It
May 23, 2013 10:51 AM
comment(s) - last by
Tavis Ormandy said Microsoft is difficult to work with regarding these issues
A Google engineer has called Microsoft out on a recent security flaw in the Windows operating system, and even said that the Windows creator is hostile toward third-party vulnerability researchers.
Tavis Ormandy, a Google security engineer, exposed the flaw on Full Disclosure. The Microsoft vulnerability, which was in the Windows kernel driver "Win32k.sys," was featured in a Full Disclosure mailing list on May 17.
Before that, Ormandy revealed the flaw on GitHub back in March in hopes of bringing other security researchers on board to investigate.
Ormandy said on Full Disclosure, "I don't have much free time to work on silly Microsoft code, so I'm looking for ideas on how to fix the final obstacle for exploitation."
Ormandy posted on Full Disclosure yet again on Monday, saying "I have a working exploit that grants SYSTEM on all currently supported versions of Windows. Code is available on request to students from reputable schools."
Ormandy also insulted Microsoft on Full Disclosure, saying "As far as I can tell, this code is pre-NT (20+ years) old, so remember to thank the SDL for solving security and reminding us that old code doesn't need to be reviewed ;-)."
Microsoft has been annoyed with Ormandy for publicly discussing vulnerabilities before they could be patched. Microsoft prefers "responsible disclosure," where security experts are asked to report flaws privately to the company.
"Note that Microsoft treat[s] vulnerability researchers with great hostility, and are often very difficult to work with," said Ormandy. "I would advise only speaking to them under a pseudonym, using Tor and anonymous email to protect yourself."
This article is over a month old, voting and posting comments is disabled
Microsoft is a lazy SOB!!!
5/24/2013 12:27:54 AM
Tavis Ormandy should not have posted his program that exploits the Windows Kernel driver on GitHub. Posting on GitHub gives everybody to access the program.
Microsoft should not always use its PR speak to third-party security researchers. Microsoft should acknowledge third-party security researcher skills and figure out how severe the security threat is. An exploit that makes the kernel vulnerable is a huge major security risk. The kernel in an operating system is the main engine. This means Microsoft is not taking the exploit serious enough. Microsoft should stop what they are doing with other projects and fix it ASAP. Who cares Microsoft programmers have to work 24 hours to fix the issue. The issue is an absolute severity.
"Nowadays you can buy a CPU cheaper than the CPU fan." -- Unnamed AMD executive
Facebook Adds Satire Tags to Its Auto-Generated "Related News" Posts
August 18, 2014, 10:43 AM
Comcast, TWC Pull Dinner Gift for FCC Commissioner... Sort Of
August 15, 2014, 1:10 PM
Comcast Accused of Wooing FCC Commissioner w/ $110K Dinner
August 13, 2014, 8:20 PM
Quick Note: Nokia’s Lumia 520 Available for $39.99 Off Contract Today Only
August 13, 2014, 10:37 AM
Wikipedia Scores $140,000 in Bitcoin Donations in One Week
August 11, 2014, 9:32 AM
China to Require Real Names for Chat Apps
August 8, 2014, 8:28 PM
Most Popular Articles
Lumia 830 Gets Major Upgrades Including New 20.1 Megapixel Toshiba Sensor
August 15, 2014, 6:00 PM
Windows Phone, BlackBerry Smartphone Market Share Falls to 2.5%, 0.5% Respectively
August 15, 2014, 9:44 AM
GM Concedes That the Cadillac ELR Doesn’t Really Compete with the Tesla Model S
August 15, 2014, 5:42 PM
Report: Windows 9 “Threshold” Tech Preview Coming Next Month
August 15, 2014, 11:29 AM
Apple Scores Patents, Preps New Reversible USB Plug for iPhone 6 Connector
August 18, 2014, 1:32 PM
Latest Blog Posts
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information