Stories
Slash Boxes
Comments

SoylentNews is people

posted by n1 on Tuesday June 10 2014, @02:50AM   Printer-friendly
from the incomplete-updates-are-available dept.

Darren Pauli writes at the Register that researchers who scanned 900 Windows libraries have uncovered a variety of security functions that were updated in Windows 8 but not in Windows 7. Researcher Moti Joseph speculates Microsoft had not applied fixes to Win 7 to save money. "Why is it that Microsoft inserted a safe function into Windows 8 [but not] Windows 7? The answer is money. Microsoft does not want to waste development time on older operating systems ... and they want people to move to higher operating systems," Joseph said in a presentation at the Troopers14 conference.

Joseph along with Marion Marschalek developed a diffing (comparison) tool dubbed DiffRay which compares Windows 8 with 7, and logs any safe functions absent in the older platform. In a demonstration of DiffRay, the researchers found four missing safe functions in Windows 7 that were present in 8 (Youtube). Future work will extend DiffRay's capabilities to find potential vulnerabilities in Windows 8.1 (PDF), add intelligence to trace input values for functions and incorporate more intelligent signatures used to find potential holes. "If we get one zero-day from this project, it's worth it," says Joseph.

Editor's update: For those who prefer, the Presentation Slides (PDF) are also available.

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Interesting) by mcgrew on Tuesday June 10 2014, @02:52PM

    by mcgrew (701) <publish@mcgrewbooks.com> on Tuesday June 10 2014, @02:52PM (#53781) Homepage Journal

    Bullshit. Do owners of ten year old GM cars with defective ignition switches have to pay to get the switches replaced? Patches and security updates are actually recalls of defective products. Microsoft is flipping its paying customers the bird.

    SOFTWARE IS NOT A SERVICE! Neither is a product recall. This is almost as irresponsible as their dropping support for 25% of the computers on the internet.

    If Joe Sixpack gets a trojan, then he needs to take it to someone like Hairyfeet and pay for service. If he gets a drive-by virus or worm without having to click "I agree" than Microsoft should fix it free; it's their fault Joe got infected. And when all those XP computers are a giant botnet that takes the whole internet down, the irresponsibility belongs solely to Microsoft.

    BTW, I ran across a hack [pcworld.com] that makes Microsoft think your XP computer is an ATM will happily supply upgrades.

    There is no excuse whatever for hardware outliving its software.

    --
    mcgrewbooks.com mcgrew.info nooze.org
    Starting Score:    1  point
    Moderation   +1  
       Interesting=1, Total=1
    Extra 'Interesting' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   3  
  • (Score: 2) by tangomargarine on Tuesday June 10 2014, @04:07PM

    by tangomargarine (667) on Tuesday June 10 2014, @04:07PM (#53829)

    SOFTWARE IS NOT A SERVICE!

    *cough* [wikipedia.org]

    (yay caps filter blah blah blah)

    --
    "Is that really true?" "I just spent the last hour telling you to think for yourself! Didn't you hear anything I said?"
  • (Score: 2) by EvilJim on Friday June 13 2014, @05:27AM

    by EvilJim (2501) on Friday June 13 2014, @05:27AM (#54826) Journal

    oooh... it pretends to be an ATM... smart move. I didn't bother reading the articles about the hack as they made it sound like they were repurposing win7 updates to use in XP, this makes a hell of a lot more sense.
    sweet, I'll be installing ~50 ATM's at work tomorrow.

    • (Score: 2) by mcgrew on Friday June 13 2014, @04:04PM

      by mcgrew (701) <publish@mcgrewbooks.com> on Friday June 13 2014, @04:04PM (#55021) Homepage Journal

      I don't think I'll do that to my XP computer (but of course, you won't have the luxury I do since they're company computers). I'll just install Linux dual-boot and remove all the Windows networking components. Then I can use the one program I have that needs XP, and Linux can read and write to the Windows partition, so for moving files I'll just boot into Linux.

      Right now it's seldom turned on. When I need to move a file I just disconnect the cable feed to the router first, turn on the XP PC, move the file, shut the XP PC down and reconnect the cable.

      --
      mcgrewbooks.com mcgrew.info nooze.org
      • (Score: 2) by EvilJim on Saturday June 14 2014, @01:07AM

        by EvilJim (2501) on Saturday June 14 2014, @01:07AM (#55163) Journal

        haha, we've got an upgrade plan for win7 but if there's delays and some threat looms we'll investigate it. our new database system appears to have an RDP connection for the front end, as soon as we get rid of the last two (that require IE7) I want to get the office on linux, that would make me so proud, and possibly close to redundant :)