Skip to main content

Security Experts Rally…Against Microsoft

Image used with permission by copyright holder

In the world of computer security, the industry standard best practice is a process called “responsible disclosure:” when a security issue is discovered with a software product, the discoverer reports to the problem to the software vendor and gives them time to develop a patch or workaround. Once a fix is available, then the bug’s discoverer (or the affected software company) can make information about the bug public. The idea is to reduce (or eliminate) the amount of time knowledge about the problem is floating around the Internet with no fix available.

Recommended Videos

Now, an anonymous group of security researchers has become frustrated with the “hostility” displayed by software giant Microsoft to outside security researchers, and has decided to throw responsible disclosure to the wind. Naming themselves the Microsoft-Spurned Researchers Collective—MSRC, a play on Microsoft’s own Microsoft Security Response Center—they have pledged to full disclose any vulnerabilities they uncover, without first reporting the problems to Microsoft so the company can evaluate them and develop a fix. To make good on their charter, the group disclosed a vulnerability in Windows Vista and Server 2008 that could be used to crash systems and, potentially, execute malicious code.

The anonymous group cites Microsoft’s recent treatment of Tavis Ormandy as the inventive for their action; Ormandy found the 17-year-old security problem in WIndows’ Virtual DOS Machine and more recently reported a significant security issue with Windows XP’s Help Center. Microsoft identified Ormandy as a Google employee; Ormandy maintains his reports to Microsoft were independent of Google and the company’s name should not have been used.

If the Microsoft-Spurned Researcher Collective gains momentum—and is able to deliver up significant security vulnerabilities to the general public—the group could be a boon to attackers and malware developers always looking for new ways to break into Windows systems. However, the group’s existence highlights the often contentious relations between software vendors and security researchers: while the vast majority of security issues are reported and patched without public drama, software makers do need to be mindful of how they interact with broader computer security communities.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Google Gemini’s best AI tricks finally land on Microsoft Copilot
Copilot app for Mac

Microsoft’s Copilot had a rather splashy AI upgrade fest at the company’s recent event. Microsoft made a total of nine product announcements, which include the agentic trick called Actions, Memory, Vision, Pages, Shopping, and Copilot Search. 

A healthy few have already appeared on rival AI products such as Google’s Gemini and OpenAI’s ChatGPT, alongside much smaller players like Perplexity and browser-maker Opera. However, two products that have found some vocal fan-following with Gemini and ChatGPT have finally landed on the Copilot platform. 

Read more
I never use my Microsoft Copilot subscription. I still think it’s worth it
Microsoft 356 apps.

If you have a regular subscription, you’re likely well-versed in the dance of paying for something and wondering if it’s worth the value. For many people, that might be a streaming service that hasn’t been used in six or more months or a membership for a gym that hasn’t been visited since before that last holiday. For me, I grapple with what to do with my Microsoft 365 subscription, specifically after the recent price hike due to the addition of Copilot+ features.

Microsoft 365 is one of those interesting computer suites that you don’t realize that you need until you need it. It's likely why I’ve allowed Microsoft to snatch money from my bank account for several years, when I only use one or two programs and one or two features.

Read more
I hope these 3 long-lost Microsoft Windows 8 features stay gone forever
Windows 8 Start screen

If you used a Windows computer in the early 2010s, chances are you experienced Windows 8. Whether it was a good experience is another matter entirely, though. If you ask me, it was a bit of a disaster.

For me, updating to Windows 8 was an unexpected jumpscare. Maybe you had a similar experience; perhaps you just updated your computer one day to discover that the beloved Start Menu vanished without warning. In its place, you saw a full-screen tile interface that probably made you feel like you were using a phone rather than a desktop.

Read more