information security, the outdoors and me RSS 2.0
# Monday, January 02, 2006

Recently a vulnerability was uncovered related to WMF files on Windows OS's.  This vulnerability has yet to have a functional workaround or patch from Microsoft.  The security community has taken it upon theeselves to issue a workaround that alleviates the issue.  This is a good sign that the community is willing to spend effort to protect Microsoft's customers at no value to themselves except credibility.

Various credible companies and groups have supported this code development level workaround.  This is better then Microsoft's response which has included a workaround which breaks functionality and a couple of useless blog postings

It seems that Microsoft has taken the CYA (cover your a--) path - contacting law enforcement and publishing a bulletin, but not actually protecting their users.  WTF?  Isn't that out of order in the list of priorities?

I have submitted a plea to Microsoft to work with the security community to provide and approve such workarounds.  Clearly they don't have the manpower or time to devote to this problem as lots of people are being attacked due to this vulnerability.  So the next best thing for Microsoft to do is accept the community based efforts and support them.

This clearly isn't about open source or providing free protection services, its all about protecting the customers.  Microsoft consistently has placed its company above the customer during these security issues.  It is a disgusting trend that has had impact on lots of their customers.  I hope their customers vote with their wallets.

Monday, January 02, 2006 12:11:48 PM (Eastern Standard Time, UTC-05:00)  #    Comments [2] -
tech
Sunday, January 22, 2006 5:56:28 AM (Eastern Standard Time, UTC-05:00)
Re: The title, (wow, look, no one using linux is affected by this...huh...)

Actually the people on Linux who use Wine are affected, Wine will run the exploits as it emulates the WMF code exactly.
Sunday, January 22, 2006 12:41:16 PM (Eastern Standard Time, UTC-05:00)
Yes, I agree completely. This blog entry was never updated to point this out.

I am called Mr Microsoft at work, so don't take this to mean I'm a linux zealot, I just was pointing out the (known) scope of the issue. It was huge at the time and fortunately there was little damage from this vulnerability.

In the future I'll try to keep the posts updated upon changes that clearly change the situation such as this. Thanks for the comment!
Comments are closed.
Categories
Archive
<October 2008>
SunMonTueWedThuFriSat
2829301234
567891011
12131415161718
19202122232425
2627282930311
2345678
Blogroll
About the author/Disclaimer

Disclaimer
The opinions expressed herein are my own personal opinions and do not represent my employer's view in any way.

© Copyright 2008
ydns
Sign In
Statistics
Total Posts: 67
This Year: 0
This Month: 0
This Week: 0
Comments: 3
Themes
Pick a theme:
All Content © 2008, ydns
DasBlog theme 'Business' created by Christoph De Baene (delarou)