You may have read that at a recent black hat conference a paper was presented which exposed some flaws in Vista security. Many blogs have been posted about this such as this one by Adrian Kingsly Hughes http://blogs.zdnet.com/hardware/?p=2387 which are saying in effect that Vista's much touted security is now busted and useless. This blog is written by a guy who knows little about the details of security himself and who is reporting what someone else said about a paper that that person admits to not having read himself. It's the usual blog sensationalism where a few page views are happily exchanged for any semblance of the truth.
Thanks for your blog post about our research. I was horrified by the lack of understanding displayed by the tech press when they covered the paper Mark and I presented at BlackHat. You rightly point out that the sky is not falling and the flaws are not unfixable. In fact, the next versions of Flash and Java will contain specific measures that limit the impact of the techniques we presented. We expect Microsoft to follow suit as well.
Exploitation is a cat and mouse game. The paper we presented puts the offensive side at a slight advantage, but it won’t take long for the defenses to catch up. Our intention was always to nudge the software vendors into improving their defenses and I hope we will succeed.
It's amazing how this blog phenomenon works. You can blog anything you like, because it's not 'journalism' - other tech people read the headlines and report them, often as quickly as humanly possible while the BS is still hot, such as Leo Leporte did about this story, not exactly endorsing it but subtly propagating it, and before you know it the blogosphere is ablaze with BS. The quality of tech writing and blogging is atrocious - it's woefully inaccurate, sensationalized and agenda driven. Everybody and his mother is jumping on the bandwagon and I'd wager not even 10% of them are even qualified to speak jack about the suibject. It's TECH!
Message edited by notherdude on 08-12-2008 at 03:27:51 PM
------------------------------tehhardpro wrote :
notherdude u have an old hand. Having an old hand doesnt make sence. Cuz its old. get a new one.. seems like ur hand doesnt understand what it is writing. So placve it in ur rig instead of vista human orgnoids will amke more sense
I'm not surprised. That's not the problem. The problem is people trust internet 100%. We can fabricate anything on the web. I trust no one. not even me. I take news with a grain of salt.
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.