• azuth@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    38
    arrow-down
    1
    ·
    10 hours ago

    They will be patched. There is also no indication that they 'be been known and exploited till recently.

    This was allegedly deliberately non patched to be exploited.

    Getting a system without bugs and security issues is impossible, you can at least avoid intentional compromise.

    • Alaknár@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      12
      ·
      8 hours ago

      They will be patched. There is also no indication that they 'be been known and exploited till recently.

      Two of the three are being used in the wild, with Copy Fail being retroactively found at least 9 days before the disclosure.

      What are the indications that the BitLocker vulnerability is already being utilised?

      This was allegedly deliberately non patched to be exploited.

      Alleged by a guy who was fired from Microsoft. I’d take that with a pinch of salt.

      Getting a system without bugs and security issues is impossible, you can at least avoid intentional compromise.

      I agree! But other than one angry dude, not much else is pointing towards this being intentional - so far! Let’s see how things go.

      That being said, open source repos are being attacked constantly with attempts at intentional malicious code injection - I’m sure you’ve heard of XZ Utils? How many others went through and are being exploited without anyone noticing?

      • azuth@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        What are the indications that the BitLocker vulnerability is already being utilized?

        Microsoft shipping a vulnerable version of the recovery environment. It is the ‘exploit’.

        Alleged by a guy who was fired from Microsoft. I’d take that with a pinch of salt.

        Such is the nature of closed source software. You select people who will remain complicit till they have a grievance against you. Even if they don’t and talked for moral reasons do you think they would not been fired for it?

        That being said, open source repos are being attacked constantly with attempts at intentional malicious code injection - I’m sure you’ve heard of XZ Utils? How many others went through and are being exploited without anyone noticing?

        Who knows. How many more went through at closed source software a limited amount of people can test in the same way?

      • youmaynotknow@lemmy.zip
        link
        fedilink
        English
        arrow-up
        11
        arrow-down
        2
        ·
        7 hours ago

        Dude, enjoy your Windows then. This is not Twitter (or X or whatever) where you can go do your master’s bidding of creating noise to try and control the normies. Here most of us know how to do research and have the ability to differentiate bots (human or otherwise) from actual thinking individuals with a modicum of common sense and more than 2 functioning brain cells.

        Look at your down-votes and take a hint. That bullshit has no effect here.

        • Alaknár@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          6
          ·
          5 hours ago

          Dude, enjoy your Windows then.

          Well, I’m a Linux user so I can’t.

          This is not Twitter (or X or whatever) where you can go do your master’s bidding of creating noise to try and control the normies

          Of course you can! Just like on every other social media! What are you even talking about? :D

          Here most of us know how to do research and have the ability to differentiate bots (human or otherwise) from actual thinking individuals with a modicum of common sense and more than 2 functioning brain cells.

          You’d think that, but if you actually know a bit about tech, this community is hilariously ignorant most of the time - on all the matters you mentioned. :D

          Look at your down-votes and take a hint. That bullshit has no effect here.

          The hint is that this community is extremely aggressive towards language that goes against the hive-mind. The bullshit has no effect because people can’t differentiate what’s bullshit and what isn’t, so they just automatically assume any statement that isn’t violently anti-MS is bullshit spewed by bots at their master’s bidding.

          Take your comment as example…