Windows 8 Security Measures Broken?


Recommended Posts

Last week?s Windows 8 launch wasn?t just a major product release for Microsoft. It seems to have been a banner day for the government-funded hackers who take Microsoft?s software apart, too.

On Tuesday the French firm Vupen, whose researchers develop software hacking techniques and sell them to government agency customers, announced that it had already developed an exploit that could take over a Window 8 machine running Internet Explorer 10, in spite of the many significant security upgrades Microsoft built into the latest version of its operating system.

Source: Forbes

Really interesting read. It's also noted that it'll take other hackers a while before breaking into Windows 8 becomes more common.

Link to comment
https://www.neowin.net/forum/topic/1116295-windows-8-security-measures-broken/
Share on other sites

And this is why I will never buy an RT based tablet as long as the browser restrictions are in place. Even with Microsoft's security improvements IE still seems to be a portal for hackers.

  • Like 2

And this is why I will never buy an RT based tablet as long as the browser restrictions are in place. Even with Microsoft's security improvements IE still seems to be a portal for hackers.

And that and other reasons are why it is advised to avoid IE.

so this was with the desktop version of IE? no surprise there

now if this was with the Metro IE and they had managed to break RTs sandbox THEN I'd be impressed

Well, that depends. A lot of Metro apps use WWAHost for execution, which is an IE renderer. If the bug is in that, then they could potentially breach the sandbox for Metro apps.

And this is why I will never buy an RT based tablet as long as the browser restrictions are in place. Even with Microsoft's security improvements IE still seems to be a portal for hackers.

Actually, IE on Metro has a more restrictive sandbox than IE on desktop. I know you can enable the more secure sandboy in the "normal" desktop IE, but I don't know if you can do it in the ARM version.

But then what do you want to use? Firefox? I like Firefox, but it's nowhere near IE in terms of security.

Actually, IE on Metro has a more restrictive sandbox than IE on desktop. I know you can enable the more secure sandboy in the "normal" desktop IE, but I don't know if you can do it in the ARM version.

But then what do you want to use? Firefox? I like Firefox, but it's nowhere near IE in terms of security.

yeah doesn't IE actually have the strongest sandbox between firefox(which doesn't even have a sandbox) and chrome now?

And this is why I will never buy an RT based tablet as long as the browser restrictions are in place. Even with Microsoft's security improvements IE still seems to be a portal for hackers.

the more reason to not use IE :p

what makes you think Firefox, Chrome or Opera on Windows 8 will be any better? :/

what makes you think Firefox, Chrome or Opera on Windows 8 will be any better? :/

I think it's security wise better because of the way it's written and I'm always pro firefox since they're the only ones that keep themselves to the webstandards which is important to me as a webdesigner.

But yeah every software has/had its security holes except IE a few more :p

You mean hackers have done the possible?! :huh:

All the additional layers of security in Windows 8 and RT make hacking more difficult but not impossible. With enough determination, a hacker can break into any system. Even Google Chrome has been exploited, bypassing the sandbox and all.

This topic is now closed to further replies.
  • Posts

    • If it ain't broke, don't fix it. One Commander Free also available in the Store has been my goto Files Manager for years. It does what I need at a more than reasonable speed. I do occasionally use Files Explorer just because it is there and does what I need without any problems when I use it.
    • I think you missed his point. He wasn't saying that cloud storage isn't possible on GNU/Linux, clearly it is. He was pointing out that you are commenting about your dislike of Windows on an article about OneDrive (not Windows) for Mac (also not Windows). Its about as off topic as coming to an article about Sony improving something on the PlayStation and saying that you hate Sony TVs and prefer LG.
    • Nvidia's GeForce NOW summer sale drops prices for Ultimate and Premium memberships by Pulasthi Ariyasinghe Nvidia has a fresh update for GeForce NOW subscribers today, bringing in more games to add to its ever-growing supported titles list. At the same time, the company announced the kick-off for its summer sale for the streaming subscription service, dropping the prices for both its premium packages for anyone looking to upgrade or join. The offer is for the 12-month membership options that the company offers. This drops the 12-month Performance membership from $99.99 to $64.99, saving members $35. Next, the 12-month Ultimate membership is currently going for $129.99, dropping prices by $70 from the original $199.99. "The Performance membership delivers smooth, high-quality cloud gaming across devices, with streaming up to 1080p at 60 frames per second (fps) and access to RTX-powered servers for supported games," says Nvidia, describing its tiers. "The Ultimate membership steps things up with RTX 4080‑ or 5080‑class performance in the cloud, supporting up to 4K and beyond on ultrawide displays, up to 120 fps, and advanced features like ray tracing, NVIDIA DLSS and NVIDIA Reflex for a more responsive, visually rich experience." With the sales out of the way, here are the games joining GeForce NOW's supported list this week: NBA THE RUN (New release on Steam, available on June 9) Witchspire (New release on Steam, available on June 10) SpaceCraft (New release on Steam, available on June 11) Duet Night Abyss (Launcher) DOOM Eternal (Epic Games Store) The Elder Scrolls Online (Xbox, available on Game Pass) Farever (Steam) World of Tanks: HEAT (Wargaming) Nvidia plans to add support for a bunch of more games during the rest of June. Find the full announcement from last week over here. Keep in mind that, unlike subscription services like Game Pass or EA Play, a copy of a game must be owned by the GeForce NOW member (or at least have a license via PC Game Pass) to start playing via Nvidia's cloud servers. There is also a limit to how many hours subscribers can use the service per month.
    • It's actually shocking how logs filling disks has been a constant issue going back for decades, yet we see very little improvement over the years. Even in the server world, its actually shockingly common for a server to either go totally down, or have a critical alert raised due to logs filling disks.
    • YouTube has finally brought back its DMs feature, but only in these countries by David Uzondu Late last year, YouTube started testing a "new" way to share videos directly with friends, without having to leave the app. Now, the video giant has announced that is now rolling out a revamped direct messaging inbox, which lets you share videos, Shorts, and live streams and have conversations about them, directly on YouTube. The platform limits this feature to 18+ users who are signed in to a verified channel and use the latest mobile app version. Direct messaging on YouTube first became a thing back in 2017 inside the mobile app (later renamed to "Messages"), where users could chat one-on-one and share clips directly, but all that came to an end on September 18, 2019, when Google decided to shut it down after giving users a month to download a .zip file archive of their past chats. No one really knows why YouTube killed the feature, but users were encouraged to migrate to the public Comments section, on Community tab posts, and via YouTube Stories. The previous incarnation suffered from moderation challenges, prompting Google to implement stricter safety guidelines and age verifications for this new iteration. Here's a list of the countries where the re-launched feature is currently available, though note that Brand Accounts do not have access to it, at least for now: Countries American Samoa Austria Belgium Brazil Bulgaria Croatia Cyprus Czech Republic Denmark Estonia Finland France Germany Greece Guam Hungary Iceland Ireland Italy Latvia Liechtenstein Lithuania Luxembourg Malta Netherlands Northern Mariana Islands Norway Poland Portugal Puerto Rico Romania Singapore Slovakia Slovenia Spain Sweden Switzerland U.S. Virgin Islands United Kingdom United States Before you can use the feature, you first have to send an invite link to your contact. Invite links expire exactly seven days after you create them. If the person on the other end accepts the invite, you can exchange videos directly and text back and forth inside the app. To delete a message, just long-press on the message and tap unsend to remove it for both users. You can also delete entire conversations by long-pressing the thread and selecting delete, but the other person will continue to see the chat history on their end. To make sure everything remains safe, YouTube monitors these messages to ensure they follow Community Guidelines.
  • Recent Achievements

    • One Month Later
      Tommi118 earned a badge
      One Month Later
    • One Month Later
      sjbousquet earned a badge
      One Month Later
    • Week One Done
      sjbousquet earned a badge
      Week One Done
    • First Post
      DragonOfMercy earned a badge
      First Post
    • First Post
      bella52 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      PsYcHoKiLLa
      208
    3. 3
      +Edouard
      155
    4. 4
      Steven P.
      83
    5. 5
      FloatingFatMan
      73
  • Tell a friend

    Love Neowin? Tell a friend!