<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" media="screen" href="/App_Themes/default/rss.xslt"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:evnet="http://www.mscommunities.com/rssmodule/"><channel><title>Comment Feed for Microsoft may have known about critical IE bug for 18 months (Coffeehouse on Channel 9)</title><atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/forums/coffeehouse/477639-microsoft-may-have-known-about-critical-ie-bug-for-18-months/rss/default.aspx" /><image><url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url><title>Comment Feed for Microsoft may have known about critical IE bug for 18 months (Coffeehouse on Channel 9)</title><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/</link></image><description>Microsoft may have known about critical IE bug for 18 months</description><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/</link><language>en-us</language><pubDate>Fri, 10 Jul 2009 03:30:10 GMT</pubDate><lastBuildDate>Fri, 10 Jul 2009 03:30:10 GMT</lastBuildDate><generator>EvNet (EvNet, Version=1.0.3608.3122, Culture=neutral, PublicKeyToken=null)</generator><item><title>Re: Re: Re: Microsoft may have known about critical IE bug for 18 months</title><description>&lt;p&gt;That's utter nonsense of a reply.&lt;/p&gt;
&lt;p&gt;If a corporate user is not&amp;nbsp;allowed to replace IE&amp;nbsp;with Firefox, it's because the company has decided that they don't want Firefox installed... i.e. Their Choice.&lt;/p&gt;
&lt;p&gt;If an end-user doesn't know enough to be able to obtain FireFox via the net, that's not MS's fault&amp;nbsp;for providing them with IE... it's FireFox's fault for not marketing themselves well enough. In simple terms: They have trouble giving it away for free.&lt;/p&gt;
&lt;p&gt;Nobody is forced to use IE,&amp;nbsp;people have&amp;nbsp;a choice, and it's an easy enough one to make... and yet, people still stay with IE... because it simply does what they need it to do and most people don't care about the areas it's lacking in.&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477843</link><pubDate>Fri, 10 Jul 2009 03:26:18 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477843</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477843/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>That's utter nonsense of a reply.
If a corporate user is not&amp;nbsp;allowed to replace IE&amp;nbsp;with Firefox, it's because the company has decided that they don't want Firefox installed... i.e. Their Choice.
If an end-user doesn't know enough to be able to obtain FireFox via the net, that's not MS's&amp;#8230;</evnet:previewtext><dc:creator>Elmer</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477843/Trackback.aspx</trackback:ping></item><item><title>Re: Microsoft may have known about critical IE bug for 18 months</title><description>&lt;p&gt;Ummm..&amp;nbsp; Actually there's no "may" about it: &lt;a href="http://blogs.technet.com/msrc/archive/2009/07/09/questions-about-timing-and-microsoft-security-advisory-972890.aspx"&gt;http://blogs.technet.com/msrc/archive/2009/07/09/questions-about-timing-and-microsoft-security-advisory-972890.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[blockquote]&lt;/p&gt;
&lt;p&gt;Before I go into the details, the key thing I want customers to understand is that this is an issue that was responsibly reported to us and we have been driving in our standard process towards a security update. While in the middle of that process, attackers found this same vulnerability and began attacks against it. We were far enough in the process that we could provide information that customers can use to protect themselves in the interim while we complete that investigation and deliver a security update that you can deploy broadly with confidence. Like Jerry said, we&amp;rsquo;re targeting next Tuesday to release this update. &lt;/p&gt;
&lt;p&gt;In terms of timeline, we received the original report from Ryan Smith and Alex Wheeler with &lt;a href="http://www.iss.net/" target="_blank"&gt;IBM ISS X-Force&lt;/a&gt; in the early Spring of 2008. The CVE number assigned to this, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0015" target="_blank"&gt;CVE-2008-0015&lt;/a&gt;, can make it look older but that&amp;rsquo;s because IBM (like Microsoft) gets CVE numbers in large blocks and assigned them sequentially to issues.&lt;/p&gt;
&lt;p&gt;...&lt;/p&gt;
&lt;p&gt;We always aim to be thorough in our investigations.&amp;nbsp; For any issue that is reported to us, we strive to address not only the vulnerabilities brought to us but also to find any similar or related issues to ensure the update provides as comprehensive security as possible. And once we confirmed that issue we expanded our investigation to be thorough.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;In the case of this particular issue, part of our investigation showed other interfaces were vulnerable, in this ActiveX Control, not only the one seen used in attacks.&lt;/p&gt;
&lt;p&gt;[/blockquote]&lt;/p&gt;
&lt;p&gt;According to the blog post, even though the vulnerability was disclosed to MSFT in the spring of 2008, attackers only discovered and started using it relatively recently (just before it was scheduled to be released).&lt;/p&gt;
&lt;p&gt;The bottom line is that doing due dilegence takes time.&amp;nbsp;&amp;nbsp; It's far better to take care when making a security fix than it is to break users browsing experience.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://starkravingfinkle.org/blog/2008/03/extension-developers-breaking-news-part-2/"&gt;http://starkravingfinkle.org/blog/2008/03/extension-developers-breaking-news-part-2/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://news.cnet.com/Apple-OS-X-security-fix-busts-64-bit-support/2100-1002_3-5837406.html"&gt;http://news.cnet.com/Apple-OS-X-security-fix-busts-64-bit-support/2100-1002_3-5837406.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;And MSFT has had issues too:&amp;nbsp; &lt;a href="http://www.betanews.com/article/MS-IE-Patch-Causing-Browser-Crashes/1155745873"&gt;http://www.betanews.com/article/MS-IE-Patch-Causing-Browser-Crashes/1155745873&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;That's why you take your time in testing these fixes, especially when there's no evidence that attackers are exploiting the vulnerability.&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477835</link><pubDate>Fri, 10 Jul 2009 02:27:26 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477835</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477835/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Ummm..&amp;nbsp; Actually there's no "may" about it: http://blogs.technet.com/msrc/archive/2009/07/09/questions-about-timing-and-microsoft-security-advisory-972890.aspx
[blockquote]
Before I go into the details, the key thing I want customers to understand is that this is an issue that was responsibly&amp;#8230;</evnet:previewtext><dc:creator>Larry Osterman</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477835/Trackback.aspx</trackback:ping></item><item><title>Re: Re: Microsoft may have known about critical IE bug for 18 months</title><description>&lt;p&gt;Wow.&amp;nbsp;What do you have to smoke&amp;nbsp;before you're allowed to&amp;nbsp;design a feature for Firefox? Who could possibly think that was a good idea?&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477782</link><pubDate>Thu, 09 Jul 2009 21:39:05 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477782</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477782/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Wow.&amp;nbsp;What do you have to smoke&amp;nbsp;before you're allowed to&amp;nbsp;design a feature for Firefox? Who could possibly think that was a good idea?</evnet:previewtext><dc:creator>AndyC</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477782/Trackback.aspx</trackback:ping></item><item><title>Re: Re: Microsoft may have known about critical IE bug for 18 months</title><description>&lt;p&gt;That's weird solution indeed. Why would they advice to clear stuff using IE to solve their performance issues? Not to mention the site is not a secured HTTP connection....... hum....... not sure what that is, but I take best course of action is click NO.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477708</link><pubDate>Thu, 09 Jul 2009 18:48:52 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477708</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477708/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>That's weird solution indeed. Why would they advice to clear stuff using IE to solve their performance issues? Not to mention the site is not a secured HTTP connection....... hum....... not sure what that is, but I take best course of action is click NO.
&amp;nbsp;</evnet:previewtext><dc:creator>magicalclick</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477708/Trackback.aspx</trackback:ping></item><item><title>Re: Microsoft may have known about critical IE bug for 18 months</title><description>&lt;p&gt;Yay! Switch to Firefox 3.5! Where some bright programmer decided it would be a good idea to gather random data for the security subsystem by &lt;strong&gt;scanning all the files in your temp folder and IE cache every time it starts&lt;/strong&gt;!&lt;/p&gt;
&lt;p&gt;&lt;a href="https://support.mozilla.com/tiki-view_forum_thread.php?comments_parentId=381674&amp;amp;forumId=1"&gt;https://support.mozilla.com/tiki-view_forum_thread.php?comments_parentId=381674&amp;amp;forumId=1&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477700</link><pubDate>Thu, 09 Jul 2009 17:52:07 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477700</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477700/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Yay! Switch to Firefox 3.5! Where some bright programmer decided it would be a good idea to gather random data for the security subsystem by scanning all the files in your temp folder and IE cache every time it starts!
https://support.mozilla.com/tiki-view_forum_thread.php?comments_parentId=381674&amp;amp;forumId=1
&amp;nbsp;</evnet:previewtext><dc:creator>DCMonkey</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477700/Trackback.aspx</trackback:ping></item><item><title>Re: Re: Microsoft may have known about critical IE bug for 18 months</title><description>&lt;p&gt;&lt;em&gt;In 11 days it will be &lt;em&gt;24&lt;/em&gt; months and this &lt;em&gt;critical&lt;/em&gt; bug still has not been fixed.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I think there is a more severe Ubuntu bug described &lt;a href="https://bugs.launchpad.net/ubuntu/+bug/1"&gt;here&lt;/a&gt; (which might be related to yours).&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477675</link><pubDate>Thu, 09 Jul 2009 16:44:30 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477675</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477675/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>In 11 days it will be 24 months and this critical bug still has not been fixed.
I think there is a more severe Ubuntu bug described here (which might be related to yours).</evnet:previewtext><dc:creator>Ubuntu</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477675/Trackback.aspx</trackback:ping></item><item><title>Re: Re: Microsoft may have known about critical IE bug for 18 months</title><description>
&lt;p&gt;&lt;em&gt;Could it be that some people don't actually like FireFox ?&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Could it be that IE comes preinstalled with Windows and some people don't have the privileges to install a different browser (corporate environment) or don't know that they could install a different browser (and they still use the OS that came preinstalled when they bought it).&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477674</link><pubDate>Thu, 09 Jul 2009 16:38:41 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477674</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477674/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Could it be that some people don't actually like FireFox ?

Could it be that IE comes preinstalled with Windows and some people don't have the privileges to install a different browser (corporate environment) or don't know that they could install a different browser (and they still use the OS that&amp;#8230;</evnet:previewtext><dc:creator>Ubuntu</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477674/Trackback.aspx</trackback:ping></item><item><title>Re: Re: Microsoft may have known about critical IE bug for 18 months</title><description>&lt;p&gt;&lt;blockquote&gt;&lt;div&gt;Bug: Design flaw&lt;br /&gt;Severity: Security of computers is heavily impacted&lt;br /&gt;Details: Computers are operated and maintained by the user. The user may be dumb or otherwise not pay attention to what is going on.&lt;br /&gt;&lt;br /&gt;Solution: Remove the user interface.&lt;/div&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;I'm just kidding. :)&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477656</link><pubDate>Thu, 09 Jul 2009 14:15:08 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477656</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477656/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Bug: Design flawSeverity: Security of computers is heavily impactedDetails: Computers are operated and maintained by the user. The user may be dumb or otherwise not pay attention to what is going on.Solution: Remove the user interface.I'm just kidding. :)</evnet:previewtext><dc:creator>Dorian Muthig</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477656/Trackback.aspx</trackback:ping></item><item><title>Re: Microsoft may have known about critical IE bug for 18 months</title><description>&lt;p&gt;Yes, Canonical excels Microsoft in everything. In 11 days it will be &lt;em&gt;24&lt;/em&gt; months and this &lt;em&gt;critical&lt;/em&gt; bug still has not been fixed. - &lt;a href="https://bugs.launchpad.net/ubuntu/+bug/127116"&gt;https://bugs.launchpad.net/ubuntu/+bug/127116&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It's unlikely that they are going to fix it, as some niners have pointed out before it's architectural flaw and linux has plenty of them. Just like this one &lt;a href="http://rixstep.com/2/20070201,00.shtml"&gt;http://rixstep.com/2/20070201,00.shtml&lt;/a&gt; . Or how system software don't authenticate origin of password asking dialogs.&lt;/p&gt;
&lt;p&gt;Not saying Windows isn't broken, Linux just surpasses it in brokenness.&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477651</link><pubDate>Thu, 09 Jul 2009 13:04:35 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477651</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477651/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Yes, Canonical excels Microsoft in everything. In 11 days it will be 24 months and this critical bug still has not been fixed. - https://bugs.launchpad.net/ubuntu/+bug/127116
It's unlikely that they are going to fix it, as some niners have pointed out before it's architectural flaw and linux has&amp;#8230;</evnet:previewtext><dc:creator>RoyalSchrubber</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477651/Trackback.aspx</trackback:ping></item><item><title>Re: Microsoft may have known about critical IE bug for 18 months</title><description>&lt;p&gt;&lt;strong&gt;- why should the user pay to upgrade to Vista to be able to have more security on the net when you can switch to Firefox for free (and have a more standards-compliant browser thus web pages look prettier)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;...and yet, they choose not to.&lt;/p&gt;
&lt;p&gt;Could it be that some people don't actually like FireFox ?&lt;/p&gt;</description><comments></comments><link>http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477649</link><pubDate>Thu, 09 Jul 2009 13:01:49 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/forums/Coffeehouse/477639-Microsoft-may-have-known-about-critical-IE-bug-for-18-months/?CommentID=477649</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/477649/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>- why should the user pay to upgrade to Vista to be able to have more security on the net when you can switch to Firefox for free (and have a more standards-compliant browser thus web pages look prettier)
...and yet, they choose not to.
Could it be that some people don't actually like FireFox ?</evnet:previewtext><dc:creator>Elmer</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/477649/Trackback.aspx</trackback:ping></item></channel></rss>