https://twitter.com/AskWoody/status/1187048132124794880
[See the full post at: So where are all those horrible zero-days?]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
So where are all those horrible zero-days?
Home » Forums » Newsletter and Homepage topics » So where are all those horrible zero-days?
- This topic has 10 replies, 8 voices, and was last updated 5 years, 6 months ago.
AuthorTopicViewing 5 reply threadsAuthorReplies-
mn–
AskWoody LoungerOctober 23, 2019 at 4:45 pm #1989704It’s the usual thing with spy games, including the corporate version.
We have various high-level entities making noise about those – Microsoft, various government-level entities on various continents, etc… and I note that the warnings say something to the effect of “used in targeted attacks”…
Given that other security professionals also tell me that targeted and tailored attacks have been on the rise recently… and that’s about all I get without a NDA…
So yeah. These would be sort of consistent with having an active international espionage arms race where all sides try to keep hidden with varying success and everyone’s also spreading disinformation.
And assuming that’s true – unless you’re already involved in the spy games you’re not likely to be targeted… in the current phase of the game, or unless some of the tools leak to common criminals.
Or it could all be disinformation. Pass me the tinfoil, will you?
-
Noel Carboni
AskWoody_MVPOctober 23, 2019 at 8:25 pm #1989922Didn’t you get the memo?
“Security” is really not about protecting anyone from bad things.
It’s about manipulating them through fear and threats. Somehow that’s become an acceptable marketing tactic.
It stinks on ice.
-Noel
-
anonymous
GuestOctober 23, 2019 at 8:33 pm #1989933If MS thinks that I’m going to be more worried about some outside entities hacking my laptops that I’ll overlook that Telemetry surreptitiously slipped into the W7 Security only updates then MS is not getting any traction as far as I’m concerned.
I’ll take the Zero Day potential over some assured MS nefariousness any day and I’ll happily install a from a 8 year old windows 7 recovery image and go with that sans any updates, if needed, before all accept any MS Telemetry where it does not belong if I need to clear up any infections after 2020. I can very well scrub my windows 7 laptops of any personal information and go from there and not care one little bit about any Zero Days and avoid doing any security essential business on any laptop that’s running any Windows OS.
I can very well install some security oriented Linux Distro on one of the laptops dedicated to secure transactions and only secure transactions. And that leaves 3 laptops for any sorts of non security essential Internet Browsing and not much to worry about personal information wise from any Zero Days that may or may not be targeting those systems.
-
_Reassigned Account
AskWoody LoungerOctober 24, 2019 at 9:03 am #1990424Well after the Chicken littles over hyped the Spectre and a Meltdown stuff. I figure the media has become obsessed with reporting these exploits. Hysteria sells clicks these days, the whole tech world is rather bland otherwise. Much of these things never make it to mainstream media. Which just proves how little influence these things have.
2 users thanked author for this post.
-
Microfix
AskWoody MVPOctober 24, 2019 at 9:44 am #1990440I’m sure CanadianTech would agree, having stopped patching Windows 7 in May 2017 whilst supporting his clients, who still have no major issues with security or systems and his workload has dropped dramatically.
CVE-M0R3-8ULLWindows - commercial by definition and now function...1 user thanked author for this post.
-
anonymous
GuestOctober 24, 2019 at 1:28 pm #1990665John, I agree with you. If I remember it was the “Google Boys” that brain team that comes up with bright-ideas and want to be congratulated for their insights that caused this whole debacle to happen in the first place. It was an OLD flaw with Intel processors that was known for something like 20 years. The GOOGLE BOYS find this and publish it knowing it could not be fixed except with a new generation of CPU. Now everyone is worried or annoyed at the half way fixes that have come out slowing down of the CPU as a result. All for a threat that has not happened and if I remember Woody saying will probably be in a very long time before it will -if ever- happen. Thanks Google.
-
anonymous
GuestOctober 24, 2019 at 6:55 pm #1991147I can not help but to think that Intel will gladly sell some new CPU hardware with the necessary fixes to anyone wishing for more security in their hardware from Intel without as much of a performance loss. And most consumers are not very smart in matters concerning hardware errata and CVEs and such but those consumers are to a degree more dangerously too much Brand Aware but lacking in computing hardware knowledge.
AMD, even with it’s lesser hardware vulnerability issues and very performant CPU performance since it’s Zen micro-architecture was released and iterated upon for even better CPU performance with Zen+/Zen-2, is still behind in the wider consumer market mind share.
But as far as Spectre/Meltdown mitigations being disabled at the OS environment variable level, there is that option of speeding things up for some. But others will keep the settings to enable the mitigations to avoid any legal ramifications if something does appear that can actually attack via said hardware vulnerabilities.
If I where a security certificate issuing authority I’d maybe do every thing possible to keep the encryption keys to the certificate vault protected including some custom/bespoke hardware that’s not in very wide general usage or even have the CPU’s Hyper-Threading/SMT disabled and even some speculative execution switched off at the micro-code level. That’s going to exact some performance hit for sure but that may be necessary for some essential entities.
The average person is not really having to worry much about all that is Zero Day that’s too difficult to manage without some expensive/sponsored efforts at hacking. Average consumers have more to worry about from the common scripting vulnerabilities that can gain root/administrative level access via privilege escalation attack vectors.
So side channel attack vectors are a more difficult method compared to those script/buffer overflow sorts of steal grandma’s bank account number attacks. Now for grandma’s Bank that’s a more definite target for some properly funded hacking operation where not just grandma’s funds can be drained. And the lawyers that will descend on any Bank that has not taken the upmost steps regarding any zero day/CVE are really something to be worried about as much as some well funded hacking groups sorts of losses.
-
mn–
AskWoody LoungerOctober 25, 2019 at 12:45 am #1991424If I where a security certificate issuing authority I’d maybe do every thing possible to keep the encryption keys to the certificate vault protected including some custom/bespoke hardware that’s not in very wide general usage or even
… you know, according to the publicly available information…
Supposedly, none of those processor side-channel attacks work on Itanium (IA-64) and descendant processor models at all. I wonder what the current price would be for a HPE Integrity rx2800 …
Sparc hardware seems to be only minimally affected and fixed firmware is available. Same with POWER9.
IA-64 and Sparc only seem to be available in rackmount servers these days but that one company is advertising POWER9 workstations.
-
-
-
-
Anonymous
InactiveOctober 24, 2019 at 6:21 pm #1991114I’m still waiting for Wannacry or was it Petya, or Meltdown, or Spectre. Yadda Yadda Yadda, Blah Blah Blah, I’ve lost track of them all. Lost track of all the boogie men that were gonna invade my computer, hit me over the head with the hammer of Thor and carry me off to purgatory.
Yawn.
It was entertaining watching everybody running around having panic attacks clamoring for updates to protect against Wannacry. I think it was Wannacry…
Watched the Linux Mint team bork their kernel rushing out a fix for a theoretical non existent threat. Had to immediately issue a new update to fix the earlier borking.
The thread at the Mint forums was really an eyeful to read. You could feel the panic and despair in the writing of a lot of posters over that “threat’.
Some of the Microsoft/Windows forums weren’t any better.
So I just sit here doing everything wrong. Group W for 2½ years. Waiting…
-
Alex5723
AskWoody PlusOctober 25, 2019 at 1:57 am #1991451Windows 10 1809 Pro. Semi-Annual, Feature Updates = 210, Quality Updates = 21, Yet just received October 3, 2019—KB4524148 (OS Build 17763.775) probably under *we will ask you to download updates, except were updates are required to keep Windows running smoothly….
or, maybe that 21 days has passed for this Sept. 2019 patch ?-
This reply was modified 5 years, 6 months ago by
Alex5723.
-
This reply was modified 5 years, 6 months ago by
Viewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Help with WD usb driver on Windows 11
by
Tex265
1 hour, 29 minutes ago -
hibernate activation
by
e_belmont
2 hours, 19 minutes ago -
Red Hat Enterprise Linux 10 with AI assistant
by
Alex5723
6 hours, 6 minutes ago -
Windows 11 Insider Preview build 26200.5603 released to DEV
by
joep517
9 hours, 11 minutes ago -
Windows 11 Insider Preview build 26120.4151 (24H2) released to BETA
by
joep517
9 hours, 13 minutes ago -
Fixing Windows 24H2 failed KB5058411 install
by
Alex5723
12 hours, 23 minutes ago -
Out of band for Windows 10
by
Susan Bradley
13 hours, 56 minutes ago -
Giving UniGetUi a test run.
by
RetiredGeek
20 hours, 53 minutes ago -
Windows 11 Insider Preview Build 26100.4188 (24H2) released to Release Preview
by
joep517
1 day, 4 hours ago -
Microsoft is now putting quantum encryption in Windows builds
by
Alex5723
1 day, 2 hours ago -
Auto Time Zone Adjustment
by
wadeer
1 day, 9 hours ago -
To download Win 11 Pro 23H2 ISO.
by
Eddieloh
1 day, 6 hours ago -
Manage your browsing experience with Edge
by
Mary Branscombe
11 hours, 15 minutes ago -
Fewer vulnerabilities, larger updates
by
Susan Bradley
22 hours, 11 minutes ago -
Hobbies — There’s free software for that!
by
Deanna McElveen
6 hours, 5 minutes ago -
Apps included with macOS
by
Will Fastie
3 hours, 57 minutes ago -
Xfinity home internet
by
MrJimPhelps
44 minutes ago -
Convert PowerPoint presentation to Impress
by
RetiredGeek
1 day, 1 hour ago -
Debian 12.11 released
by
Alex5723
2 days, 6 hours ago -
Microsoft: Troubleshoot problems updating Windows
by
Alex5723
2 days, 9 hours ago -
Woman Files for Divorce After ChatGPT “Reads” Husband’s Coffee Cup
by
Alex5723
1 day, 13 hours ago -
Moving fwd, Win 11 Pro,, which is best? Lenovo refurb
by
Deo
30 minutes ago -
DBOS Advanced Network Analysis
by
Kathy Stevens
3 days, 2 hours ago -
Microsoft Edge Launching Automatically?
by
healeyinpa
2 days, 17 hours ago -
Google Chrome to block admin-level browser launches for better security
by
Alex5723
14 hours, 52 minutes ago -
iPhone SE2 Stolen Device Protection
by
Rick Corbett
2 days, 21 hours ago -
Some advice for managing my wireless internet gateway
by
LHiggins
2 days, 5 hours ago -
NO POWER IN KEYBOARD OR MOUSE
by
HE48AEEXX77WEN4Edbtm
1 day, 7 hours ago -
A CVE-MITRE-CISA-CNA Extravaganza
by
Nibbled To Death By Ducks
3 days, 14 hours ago -
Sometimes I wonder about these bots
by
Susan Bradley
1 day, 3 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.