Voyons voir ce que contient ce FUDcommunique de presse de la FSFE (pour laquelle travaille Hugo, histoire de faire du full disclosure comme le recommande la FSFE):
Microsoft's latest operating system, Windows 7, is currently shipping with a potentially serious defect. Ahead of the product's global launch on Thursday, Germany's federal IT security agency (BSI) has issued a warning [1] about a high-risk vulnerability in the SMB2 protocol. This can be exploited over the network to shut down a computer with a Denial of Service (DoS) attack.
Pour l'instant rien a dire. Ils ont bien fait de mettre "currently" parce que MS risque de tout faire pour avoir un patch sur Windows Update le jour de la sortie.
This incident illustrates how proprietary software often poses a security risk. "Only Microsoft can fix the problem. But they have apparently closed their eyes to this vulnerability for a long time, hoping that it wouldn't spoil the retail launch of Windows 7 this Thursday," says Karsten Gerloff, President of the Free Software Foundation Europe (FSFE).
"apparently"? Il a des raisons de croire que MS a voulu cacher la faille? Il a des sources en interne pour nous dire que ca fait longtemps qu'ils sont au courant?
Following responsible disclosure practices, the BSI has not published details in its announcement (English translation below) from October 6. While it is generally a good strategy to give vendors time to repair vulnerabilities before announcing them publicly, in this case the BSI should consider publishing the full details of the problem to put more pressure on Microsoft.
100% foutage de gueule... Si c'est pas corrige quelques temps apres la sortie, ok pour publier les details, mais la, je vois pas trop bien pourquoi ils reclament ca, a par pour passer pour des kekes.
The agency says that the security hole affects Windows 7 and Windows Vista in both their 32-bit and 64-bit versions, as well as Windows Server 2008. This vulnerability is different from an earlier SMB2 issue [2] for which Microsoft published the patch MS09-050 in September.
OK, factuel.
FSFE's Gerloff explains: "Microsoft's software locks its users in, so they have to stay even if the company knowingly exposes them to a security risk like this. With Free Software like GNU/Linux - software that you can study, share and improve - several independent entities can fix the problem. Consumers should not support Microsoft's negligent behaviour by buying its products. Free Software offers an alternative, and is available from many independent vendors."
Bon, c'est du discours standard pour la FSF, sauf que le "knowingly exposes" pour un systeme qui n'est pas encore dispo et dont on ne sait meme pas si un patch sera la le jour de la sortie, c'est du FUD grossier.
Microsoft has not yet responded to the BSI's warning. There is no indication that the company will manage to fix the gaping hole in its flagship operating system before the global launch of Windows 7 this Thursday. The vulnerability remains open even after Microsoft's October patch day.
FUD FUD FUD. There is no indication that RMS isn't a child killer.
The company's security practices have long been a cause for concern. In just one recent incident [3], Microsoft knew about another vulnerability in SMB2 since July 2009. While it did fix the problem in the final version of Windows 7 in early August, it did nothing to repair the same problem in Windows Vista or Windows Server 2008 until an independent security researcher went public about the issue.
La dessus, meme si la presentation est super tendencieuse et enrichie en mauvaise foi, gros ratage de MS pour ne pas avoir publie d'advisory plus tot. Cela dit, ca n'a rien d'extraordinaire. Tant que les patchs sont toujours en phase de test, ils vont pas s'amuser a publier des infos alors que la faille n'est pas publique et ne semble pas etre activement exploitee.
German IT news site Heise speculates that the issue ended up on a Microsoft-internal list of low-priority bugs which the company tries to fix silently, in order to avoid negative publicity.
Et on finit par du FUD, comme c'est surprenant... Il y a tellement de conditionnels dans ce communique de presse, on se demande pourquoi...
Et puis a la place de la FSF, j'en rajouterais pas trop sur les fix silencieux pour eviter le pub negative, ca risque de lui revenir rapidement en pleine figure (c'est pas les commit qui manquent dans le repository git du kernel ou la description du bug a ete nettoye pour la rendre anodine alors que l'original decrivait le trou de secu en detail). Sur ce terrain, Linux n'a pas une historique beaucoup plus glorieux que Windows.
# Etude du communique de presse
Posté par Littleboy . En réponse au journal Windows 7 va être vendu avec une faille de sécurité importante et ignorée. Évalué à 4.
Microsoft's latest operating system, Windows 7, is currently shipping with a potentially serious defect. Ahead of the product's global launch on Thursday, Germany's federal IT security agency (BSI) has issued a warning [1] about a high-risk vulnerability in the SMB2 protocol. This can be exploited over the network to shut down a computer with a Denial of Service (DoS) attack.
Pour l'instant rien a dire. Ils ont bien fait de mettre "currently" parce que MS risque de tout faire pour avoir un patch sur Windows Update le jour de la sortie.
This incident illustrates how proprietary software often poses a security risk. "Only Microsoft can fix the problem. But they have apparently closed their eyes to this vulnerability for a long time, hoping that it wouldn't spoil the retail launch of Windows 7 this Thursday," says Karsten Gerloff, President of the Free Software Foundation Europe (FSFE).
"apparently"? Il a des raisons de croire que MS a voulu cacher la faille? Il a des sources en interne pour nous dire que ca fait longtemps qu'ils sont au courant?
Following responsible disclosure practices, the BSI has not published details in its announcement (English translation below) from October 6. While it is generally a good strategy to give vendors time to repair vulnerabilities before announcing them publicly, in this case the BSI should consider publishing the full details of the problem to put more pressure on Microsoft.
100% foutage de gueule... Si c'est pas corrige quelques temps apres la sortie, ok pour publier les details, mais la, je vois pas trop bien pourquoi ils reclament ca, a par pour passer pour des kekes.
The agency says that the security hole affects Windows 7 and Windows Vista in both their 32-bit and 64-bit versions, as well as Windows Server 2008. This vulnerability is different from an earlier SMB2 issue [2] for which Microsoft published the patch MS09-050 in September.
OK, factuel.
FSFE's Gerloff explains: "Microsoft's software locks its users in, so they have to stay even if the company knowingly exposes them to a security risk like this. With Free Software like GNU/Linux - software that you can study, share and improve - several independent entities can fix the problem. Consumers should not support Microsoft's negligent behaviour by buying its products. Free Software offers an alternative, and is available from many independent vendors."
Bon, c'est du discours standard pour la FSF, sauf que le "knowingly exposes" pour un systeme qui n'est pas encore dispo et dont on ne sait meme pas si un patch sera la le jour de la sortie, c'est du FUD grossier.
Microsoft has not yet responded to the BSI's warning. There is no indication that the company will manage to fix the gaping hole in its flagship operating system before the global launch of Windows 7 this Thursday. The vulnerability remains open even after Microsoft's October patch day.
FUD FUD FUD. There is no indication that RMS isn't a child killer.
The company's security practices have long been a cause for concern. In just one recent incident [3], Microsoft knew about another vulnerability in SMB2 since July 2009. While it did fix the problem in the final version of Windows 7 in early August, it did nothing to repair the same problem in Windows Vista or Windows Server 2008 until an independent security researcher went public about the issue.
La dessus, meme si la presentation est super tendencieuse et enrichie en mauvaise foi, gros ratage de MS pour ne pas avoir publie d'advisory plus tot. Cela dit, ca n'a rien d'extraordinaire. Tant que les patchs sont toujours en phase de test, ils vont pas s'amuser a publier des infos alors que la faille n'est pas publique et ne semble pas etre activement exploitee.
German IT news site Heise speculates that the issue ended up on a Microsoft-internal list of low-priority bugs which the company tries to fix silently, in order to avoid negative publicity.
Et on finit par du FUD, comme c'est surprenant... Il y a tellement de conditionnels dans ce communique de presse, on se demande pourquoi...
Et puis a la place de la FSF, j'en rajouterais pas trop sur les fix silencieux pour eviter le pub negative, ca risque de lui revenir rapidement en pleine figure (c'est pas les commit qui manquent dans le repository git du kernel ou la description du bug a ete nettoye pour la rendre anodine alors que l'original decrivait le trou de secu en detail). Sur ce terrain, Linux n'a pas une historique beaucoup plus glorieux que Windows.