SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Microsoft Patches Windows 8 But Leaves Flaws in W7
Date    Tuesday June 10 2014, @02:50AM
Author    n1
Topic   
from the incomplete-updates-are-available dept.
https://soylentnews.org/article.pl?sid=14/06/09/2237256

Hugh Pickens writes:

Darren Pauli writes at the Register that researchers who scanned 900 Windows libraries have uncovered a variety of security functions that were updated in Windows 8 but not in Windows 7. Researcher Moti Joseph speculates Microsoft had not applied fixes to Win 7 to save money. "Why is it that Microsoft inserted a safe function into Windows 8 [but not] Windows 7? The answer is money. Microsoft does not want to waste development time on older operating systems ... and they want people to move to higher operating systems," Joseph said in a presentation at the Troopers14 conference.

Joseph along with Marion Marschalek developed a diffing (comparison) tool dubbed DiffRay which compares Windows 8 with 7, and logs any safe functions absent in the older platform. In a demonstration of DiffRay, the researchers found four missing safe functions in Windows 7 that were present in 8 (Youtube). Future work will extend DiffRay's capabilities to find potential vulnerabilities in Windows 8.1 (PDF), add intelligence to trace input values for functions and incorporate more intelligent signatures used to find potential holes. "If we get one zero-day from this project, it's worth it," says Joseph.

Editor's update: For those who prefer, the Presentation Slides (PDF) are also available.

Links

  1. "Hugh Pickens" - http://poncacityweloveyou.com/
  2. "security functions that were updated in Windows 8 but not in Windows 7" - http://www.theregister.co.uk/2014/06/06/patch_piker_redmond_means_win_8_fixes_skip_7_researchers_say/
  3. "DiffRay" - https://github.com/pinkflawd/DiffRay
  4. "found four missing safe functions in Windows 7 that were present in 8" - https://www.youtube.com/watch?v=s_7Cy2w2dCw#t=1598
  5. "find potential vulnerabilities in Windows 8.1" - https://www.troopers.de/wp-content/uploads/2013/11/TROOPERS14-What_Happens_In_Windows_7_Stays_In_Windows_7-Marion_Marschalek+Joseph_Moti.pdf
  6. "Presentation Slides" - https://soylentnews.org/:https://www.troopers.de/wp-content/uploads/2013/11/TROOPERS14-What_Happens_In_Windows_7_Stays_In_Windows_7-Marion_Marschalek+Joseph_Moti.pdf

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Microsoft Patches Windows 8 But Leaves Flaws in W7 on 2024-04-25 07:52:58