Windows 8 Security Measures Broken?


Recommended Posts

Last week?s Windows 8 launch wasn?t just a major product release for Microsoft. It seems to have been a banner day for the government-funded hackers who take Microsoft?s software apart, too.

On Tuesday the French firm Vupen, whose researchers develop software hacking techniques and sell them to government agency customers, announced that it had already developed an exploit that could take over a Window 8 machine running Internet Explorer 10, in spite of the many significant security upgrades Microsoft built into the latest version of its operating system.

Source: Forbes

Really interesting read. It's also noted that it'll take other hackers a while before breaking into Windows 8 becomes more common.

Link to comment
https://www.neowin.net/forum/topic/1116295-windows-8-security-measures-broken/
Share on other sites

And this is why I will never buy an RT based tablet as long as the browser restrictions are in place. Even with Microsoft's security improvements IE still seems to be a portal for hackers.

  • Like 2

And this is why I will never buy an RT based tablet as long as the browser restrictions are in place. Even with Microsoft's security improvements IE still seems to be a portal for hackers.

And that and other reasons are why it is advised to avoid IE.

so this was with the desktop version of IE? no surprise there

now if this was with the Metro IE and they had managed to break RTs sandbox THEN I'd be impressed

Well, that depends. A lot of Metro apps use WWAHost for execution, which is an IE renderer. If the bug is in that, then they could potentially breach the sandbox for Metro apps.

And this is why I will never buy an RT based tablet as long as the browser restrictions are in place. Even with Microsoft's security improvements IE still seems to be a portal for hackers.

Actually, IE on Metro has a more restrictive sandbox than IE on desktop. I know you can enable the more secure sandboy in the "normal" desktop IE, but I don't know if you can do it in the ARM version.

But then what do you want to use? Firefox? I like Firefox, but it's nowhere near IE in terms of security.

Actually, IE on Metro has a more restrictive sandbox than IE on desktop. I know you can enable the more secure sandboy in the "normal" desktop IE, but I don't know if you can do it in the ARM version.

But then what do you want to use? Firefox? I like Firefox, but it's nowhere near IE in terms of security.

yeah doesn't IE actually have the strongest sandbox between firefox(which doesn't even have a sandbox) and chrome now?

And this is why I will never buy an RT based tablet as long as the browser restrictions are in place. Even with Microsoft's security improvements IE still seems to be a portal for hackers.

the more reason to not use IE :p

what makes you think Firefox, Chrome or Opera on Windows 8 will be any better? :/

what makes you think Firefox, Chrome or Opera on Windows 8 will be any better? :/

I think it's security wise better because of the way it's written and I'm always pro firefox since they're the only ones that keep themselves to the webstandards which is important to me as a webdesigner.

But yeah every software has/had its security holes except IE a few more :p

You mean hackers have done the possible?! :huh:

All the additional layers of security in Windows 8 and RT make hacking more difficult but not impossible. With enough determination, a hacker can break into any system. Even Google Chrome has been exploited, bypassing the sandbox and all.

This topic is now closed to further replies.
  • Posts

    • Because Chrome is doing it. And no one said anyone had to update immediately. That's silly. They could update every day for all I care as long as it's fast, and the next time the browser restarts, you're good. And the basic point is not to tee it up for bigger updates. As it is right now, all the windows I had open reopen anyway except inprivate.
    • Why? Does anybody actually want this? The constant need to close all browser sessions and wait for a new version to install, just so that there’s a integrated coupon manager feels like a waste of everyone’s time
    • I remember when Louis used to just do interesting Mac/iPhone repairs, now he's boring and just launches "crusades" every week
    • A shame it don't allow people to bypass the MS account, I will stick to using Rufus.
    • Microsoft about to radically change how often your Edge browser updates by Paul Hill Microsoft has just announced that starting with Edge 152, it will be moving to a two-week release cycle for faster, smaller updates. This faster release cadence will begin on August 27. This change comes just several months after Microsoft switched Visual Studio Code to weekly updates. The company said that the Extended Stable releases will remain on an eight-week cycle and that no admin changes are needed to experience the faster release cycle on the Stable channel. The new two-week release cycle will enable the faster delivery of security updates and platform improvements, all while reducing the size and complexity of individual updates. Microsoft claims that organizations will benefit from this change as it offers predictable validation cycles. For organizations that prefer a “more deliberate pace”, the Extended Stable channel remains an option. This change will affect Edge Stable releases on Windows, macOS, Linux, and mobile. The Extended Stable channel will continue to be updated every eight weeks, or every fourth Stable release, for example: versions 152, 156, 160, and 164. The Extended Stable could be a good option for organizations that don’t want the latest updates twice a month and don’t want as much hassle constantly updating browsers. In the case of Visual Studio Code, many of the updates being pushed by Microsoft are AI-related. As we all know, Microsoft Edge has a lot of AI features, so we could see Microsoft pushing more AI, thanks to the faster cycles. On the flip side, quicker releases could mean faster security updates, which is beneficial in a world where AI systems are hunting for software exploits. What do you think? Let us know in the comments. For more updates on Edge, be sure to follow Neowin's coverage. In May alone, we reported on Edge offering in-browser pop-ups to assist users with website compatibility issues, that Edge was losing Copilot Mode, and that Microsoft had fixed a plain-text password bug in Edge. Source: Microsoft 365 Admin Center
  • Recent Achievements

    • Week One Done
      davidbazooked earned a badge
      Week One Done
    • One Month Later
      Jamswaz earned a badge
      One Month Later
    • Week One Done
      Jamswaz earned a badge
      Week One Done
    • Rookie
      Marzoid went up a rank
      Rookie
    • Community Regular
      coch went up a rank
      Community Regular
  • Popular Contributors

    1. 1
      +primortal
      514
    2. 2
      PsYcHoKiLLa
      185
    3. 3
      +Edouard
      159
    4. 4
      Steven P.
      83
    5. 5
      ATLien_0
      75
  • Tell a friend

    Love Neowin? Tell a friend!