Attack demoed less than 24 hours after disclosure of bug-breaking certificate validation.
Read the whole story
Read the whole story
Linux which would just happen to use OpenSSL, right?Another example of why, for the past nearly 20 years, I use GNU/Linux, not Windows, as my OS - Though it has lots of shinies, Windows has never been secure, and it will likely never be secure. My files, my privacy, and my state of mind are worth too much to trust them to an insecure platform such as Windows.
Another example of why, for the past nearly 20 years, I use GNU/Linux, not Windows, as my OS - Though it has lots of shinies, Windows has never been secure, and it will likely never be secure. My files, my privacy, and my state of mind are worth too much to trust them to an insecure platform such as Windows.
Another example of why, for the past nearly 20 years, I use GNU/Linux, not Windows, as my OS - Though it has lots of shinies, Windows has never been secure, and it will likely never be secure. My files, my privacy, and my state of mind are worth too much to trust them to an insecure platform such as Windows.
"What Saleem just demonstrated is: with [a short] script you can generate a cert for any website, and it's fully trusted on IE and Edge with just the default settings for Windows," Kenn White, a researcher and security principal at MongoDB, said. That's fairly horrifying. It affects VPN gateways, VoIP, basically anything that uses network communications." (I spoke with White before Rashid had demonstrated the attack against Chrome.)
TFW by "Siri" you meant "Cortana". You fake-ass Apple poser, you...I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
When i dont need to manually go into the update package, check its contents, verify it doesnt contain bloatware, do a quick internet check to verify it wont brick my pc, activate Siri for the 25th time, or make me opt-out of all Microsoft marketing stuff again due to a "new feature" introduced.
I mean, updating is always good (and i DO update) but they do need to iron the process.
This is likely to be in the wild if the NSA have disclosed it; as others surmised, they have been aware of it for over a decade (this bug was used in TUTELAGE'S "INTERCEPT" "BLOCK" and other operational modes) but made it public now. Why? The benefits it provides now are outweighed by an unannounced risk.
If this sounds a bit hindsight, but in cryptography there is an algorithm called ECDSA, Elliptic Curve DSA. The base point parameter is critical of course, but it is well known that failure to validate this can cause false signature matches during digital certificate validation.
The base point validation is critical in ALL elliptic curve cryptography, otherwise it is trivial to generate a private key which will sign a certificate to produce a signature with the same value as any other certificate of choice when parameter G is neglected. Again in hindsight, this sounds like the precise scenario we find ourselves in so I would hazard a guess that this is where the Microsoft implementation of ECC falls down; failure to validate the base point in given domain parameters.
So SO tired of Microsoft completely breaking my computers with every other update. People would not whine about updates if MS had any kind of quality control or testing.I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
With comments like that you are just demonstrating your ignorance.Another example of why, for the past nearly 20 years, I use GNU/Linux, not Windows, as my OS - Though it has lots of shinies, Windows has never been secure, and it will likely never be secure. My files, my privacy, and my state of mind are worth too much to trust them to an insecure platform such as Windows.
Do you read the news?.. Ever?.. Because if you did, you'd know very well what I mean.So SO tired of Microsoft completely breaking my computers with every other update. People would not whine about updates if MS had any kind of quality control or testing.I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
Microsoft breaks your computers with every other update? So that's every two months? That's really impressive. Weird how most Windows users don't need to replace their computer every two months? Maybe, just maybe, you're either (a) wildly exaggerating because you think talking shit about Microsoft is good for your geek cred, or (b) you're doing something you shouldn't to your computers?
Seriously dude, just chill out. Microsoft isn't breaking your computers every two months. They're just not. You're making it up. Getting angry over made-up issues is only cool while you're a teenager.
Microsoft has definitely released some updates that broke stuff, sure. Apple has released updates that bricked people's phones. And my Linux distro certainly doesn't have a perfect track record either. So effing what? Software is hard. But the internet has enough faux outrage and vitriol as it is.
Do you read the news?.. Ever?.. Because if you did, you'd know very well what I mean.So SO tired of Microsoft completely breaking my computers with every other update. People would not whine about updates if MS had any kind of quality control or testing.I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
Microsoft breaks your computers with every other update? So that's every two months? That's really impressive. Weird how most Windows users don't need to replace their computer every two months? Maybe, just maybe, you're either (a) wildly exaggerating because you think talking shit about Microsoft is good for your geek cred, or (b) you're doing something you shouldn't to your computers?
Seriously dude, just chill out. Microsoft isn't breaking your computers every two months. They're just not. You're making it up. Getting angry over made-up issues is only cool while you're a teenager.
Microsoft has definitely released some updates that broke stuff, sure. Apple has released updates that bricked people's phones. And my Linux distro certainly doesn't have a perfect track record either. So effing what? Software is hard. But the internet has enough faux outrage and vitriol as it is.
Somehow, software wasn't that hard with Windows 7, or Windws XP. Those rarely broke because of updates. But suddenly, with Windows 10 it became oh so difficult... Could it be this has something to do with MS laying off almost all their testers? No?..
Do you read the news?.. Ever?.. Because if you did, you'd know very well what I mean.So SO tired of Microsoft completely breaking my computers with every other update. People would not whine about updates if MS had any kind of quality control or testing.I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
Microsoft breaks your computers with every other update? So that's every two months? That's really impressive. Weird how most Windows users don't need to replace their computer every two months? Maybe, just maybe, you're either (a) wildly exaggerating because you think talking shit about Microsoft is good for your geek cred, or (b) you're doing something you shouldn't to your computers?
Seriously dude, just chill out. Microsoft isn't breaking your computers every two months. They're just not. You're making it up. Getting angry over made-up issues is only cool while you're a teenager.
Microsoft has definitely released some updates that broke stuff, sure. Apple has released updates that bricked people's phones. And my Linux distro certainly doesn't have a perfect track record either. So effing what? Software is hard. But the internet has enough faux outrage and vitriol as it is.
Somehow, software wasn't that hard with Windows 7, or Windws XP. Those rarely broke because of updates. But suddenly, with Windows 10 it became oh so difficult... Could it be this has something to do with MS laying off almost all their testers? No?..
I think you're remembering XP and 7 with a bit of nostalgia, my friend. It's human nature to remember the past as being better than it actually was. Sometimes it's important to review the primary sources in order to see things clearly, such as this database of Windows XP security vulnerabilities, for example.
Always remember that most of the decisions made in the world, with our progress and our failures, are made by normal people just doing our best. There are certainly reasons be angry. There are systemic problems that must be addressed. There are people benefitting from human suffering - people enriching themselves at others expense. Unless you believe that Microsoft bungling some development falls into that category, I recommend you save your indignation for something more worthwhile.![]()
Well, apparently, I do. Could it be that I'm the only such person in the world?Your personal experience is your own but I'm not sure how anyone could have lived through XP service packs and yet compare it favourably to Windows 10 updates...
The behavior is tantamount to a law enforcement officer who checks someone's ID to make sure it properly describes the person's height, address, birthday, and face but fails to notice that the weight is listed as 250 pounds when the person clearly weighs less than half that.
Do you read the news?.. Ever?.. Because if you did, you'd know very well what I mean.So SO tired of Microsoft completely breaking my computers with every other update. People would not whine about updates if MS had any kind of quality control or testing.I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
Microsoft breaks your computers with every other update? So that's every two months? That's really impressive. Weird how most Windows users don't need to replace their computer every two months? Maybe, just maybe, you're either (a) wildly exaggerating because you think talking shit about Microsoft is good for your geek cred, or (b) you're doing something you shouldn't to your computers?
Seriously dude, just chill out. Microsoft isn't breaking your computers every two months. They're just not. You're making it up. Getting angry over made-up issues is only cool while you're a teenager.
Microsoft has definitely released some updates that broke stuff, sure. Apple has released updates that bricked people's phones. And my Linux distro certainly doesn't have a perfect track record either. So effing what? Software is hard. But the internet has enough faux outrage and vitriol as it is.
Somehow, software wasn't that hard with Windows 7, or Windws XP. Those rarely broke because of updates. But suddenly, with Windows 10 it became oh so difficult... Could it be this has something to do with MS laying off almost all their testers? No?..
Do you read the news?.. Ever?.. Because if you did, you'd know very well what I mean.So SO tired of Microsoft completely breaking my computers with every other update. People would not whine about updates if MS had any kind of quality control or testing.I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
Microsoft breaks your computers with every other update? So that's every two months? That's really impressive. Weird how most Windows users don't need to replace their computer every two months? Maybe, just maybe, you're either (a) wildly exaggerating because you think talking shit about Microsoft is good for your geek cred, or (b) you're doing something you shouldn't to your computers?
Seriously dude, just chill out. Microsoft isn't breaking your computers every two months. They're just not. You're making it up. Getting angry over made-up issues is only cool while you're a teenager.
Microsoft has definitely released some updates that broke stuff, sure. Apple has released updates that bricked people's phones. And my Linux distro certainly doesn't have a perfect track record either. So effing what? Software is hard. But the internet has enough faux outrage and vitriol as it is.
Somehow, software wasn't that hard with Windows 7, or Windws XP. Those rarely broke because of updates. But suddenly, with Windows 10 it became oh so difficult... Could it be this has something to do with MS laying off almost all their testers? No?..
How much is too much though?I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
New type of ransomware: Give us 1 million dollars, or we leave video incessantly playing for eternity!
Its an odd day when the NSA is the reporter of backdoor...
This is actually how it is *supposed* to work.It's hard for me to process the Ars front page today.
NSA: There's one critical vulnerability in a Windows crypto library. Everyone drop everything and patch immediately.
FBI: Let's break all encryption on purpose.
So SO tired of Microsoft completely breaking my computers with every other update. People would not whine about updates if MS had any kind of quality control or testing.I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
TFW by "Siri" you meant "Cortana". You fake-ass Apple poser, you...I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
When i dont need to manually go into the update package, check its contents, verify it doesnt contain bloatware, do a quick internet check to verify it wont brick my pc, activate Siri for the 25th time, or make me opt-out of all Microsoft marketing stuff again due to a "new feature" introduced.
I mean, updating is always good (and i DO update) but they do need to iron the process.![]()
Here's the problem with .gov and computer updates:
I work for a large defense contractor on a military base. I have two computers on my desk, one is corporate owned and other is military owned.
The corp computer updated this morning at like 2 AM.
The .mil computer? As of when I left work at 5pm, still not updated. I have low expectations that it will be updated by the time I get to work in the morning.
These are your words, not mine. I never said anything remotely like that.Do you read the news?.. Ever?.. Because if you did, you'd know very well what I mean.So SO tired of Microsoft completely breaking my computers with every other update. People would not whine about updates if MS had any kind of quality control or testing.I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
Microsoft breaks your computers with every other update? So that's every two months? That's really impressive. Weird how most Windows users don't need to replace their computer every two months? Maybe, just maybe, you're either (a) wildly exaggerating because you think talking shit about Microsoft is good for your geek cred, or (b) you're doing something you shouldn't to your computers?
Seriously dude, just chill out. Microsoft isn't breaking your computers every two months. They're just not. You're making it up. Getting angry over made-up issues is only cool while you're a teenager.
Microsoft has definitely released some updates that broke stuff, sure. Apple has released updates that bricked people's phones. And my Linux distro certainly doesn't have a perfect track record either. So effing what? Software is hard. But the internet has enough faux outrage and vitriol as it is.
Somehow, software wasn't that hard with Windows 7, or Windws XP. Those rarely broke because of updates. But suddenly, with Windows 10 it became oh so difficult... Could it be this has something to do with MS laying off almost all their testers? No?..
Yeah XP was glorious. Never had vulnerabilities, never had a BSOD, never had bad updates. Just 100% perfect code all the time. Then mean ole Microsoft got rid of it because it was too perfect and stuff.
Seriously what universe have you been living in because I want to go to there?
To be honest, testing with unit tests is more of a modern thing that arose in the last decade or two and a half. The idea of unit tests for code was still actively opposed by developers in the 90’s and 2000’s.Given the nature of the bug one wonders how rigorously MS tests their code, especially critical parts like this. Also, time for NIST to update their X.509 test suite perhaps.
As we've seen over the last few years, Microsoft's testing seems to largely consist of getting the broad public to test things via their Insider program, and then . . . not noticing the bugs pointed out by members of that program until they ship.
I don't know. Apple's aptly named goto fail was in both iOS and macOS, for years, if I remember right.
And the GnuTLS library had its own crypto disaster that threatened Red Hat, Ubuntu, Debian and hundreds of other open-source packages.
So I'm not sure sloppy testing is endemic to Microsoft.
And how is that PEBKAC if Windows 10 LTSB/LTSC has been running flawlessly for me on all of my personal machines for 3 years now?.. I am only complaining about regular/consumer versions here...So SO tired of Microsoft completely breaking my computers with every other update. People would not whine about updates if MS had any kind of quality control or testing.I’m usually very much against my computer telling me when to reboot and update, but this is pretty damn serious. Really hope this update is applied globally asap.
So SO tired of people whining about updates. JFC.
Been using Windows 10 since it's release, not once has MS broken something with an update. The only inconvenience to me was that NVidia's Instant Replay feature stopped working for about 2 months after 1709. Other than that, not a single issue.
Oddly enough, I've had less crashes and blue screens on Windows 10 than I had on Windows 7. And Windows 7 rebooted me more times for updates than 10 ever did. So... maybe PEBKAC is the error code you should be looking into?
Couldn't someone just use ECC on an impersonated trusted CA?Here's the problem with .gov and computer updates:
I work for a large defense contractor on a military base. I have two computers on my desk, one is corporate owned and other is military owned.
The corp computer updated this morning at like 2 AM.
The .mil computer? As of when I left work at 5pm, still not updated. I have low expectations that it will be updated by the time I get to work in the morning.
When I was at DISA many mil systems opt out of Windows root updates so they might be fine if they have no ECC root CAs trusted.
This really shows that security is difficult to implement correctly. The underlying code that makes this exploit possible was vetted by MANY software and security experts and is only just now being found out. It's a tough business and there are always more vulnerabilities that haven't yet been discovered... or are not yet disclosed because, as another commenter mentioned, the benefits do not yet "outweigh the risks".