The Straight Dope

Go Back   Straight Dope Message Board > Main > The BBQ Pit

Reply
 
Thread Tools Display Modes
  #1  
Old 05-08-2003, 09:49 AM
black rabbit black rabbit is offline
Guest
 
Join Date: Aug 2000
Reasn #45657859818874 Microsoft sucks.

They can't tell method="get" from method="post".

This is old news in Slashdot land, but there has apparently been a vulnerability in Passport for who knows how long that allowed anybody to reset and recieve a new password for anybody else's hotmail/passport/.net account.

Hope none of you gave them your CC numbers.

Sorry Dooku, but this is really, really fucking stupid.

Trusted computing my ass.
__________________
The poster formerly known as black455.
Reply With Quote
Advertisements  
  #2  
Old 05-08-2003, 11:53 AM
Hauky Hauky is offline
Guest
 
Join Date: Jul 2002
Wow... that's a pretty basic thing to screw up. Good thing nobody uses Hotmail for anything serious, right?

...Right?
Reply With Quote
  #3  
Old 05-08-2003, 02:09 PM
Mort Furd Mort Furd is offline
Guest
 
Join Date: Apr 2001
Damn straight. Especially since I earn a few bucks in my spare time fixing spontaneous brain farts in people's Windows systems. Four hours last night because windows 2000 on one client decided it didn't want to use its domain server stored user profile for one user any more. Fun was had by all. Sheesh.
Reply With Quote
  #4  
Old 05-08-2003, 02:25 PM
rjung rjung is offline
Guest
 
Join Date: Sep 2000
Flaming Microsoft for stupid software problems is a lot like flaming George W. Bush for not pronouncing "nuclear" correct, ainnit? A bit too easy, don'cha know...
__________________
--R.J.
Electric Escape -- Information superhighway rest area #10,186
Reply With Quote
  #5  
Old 05-08-2003, 03:13 PM
Morbo Morbo is offline
Charter Member
 
Join Date: Jan 2001
Location: 123 Fake Street
Posts: 8,412
Yep. It's stupid alright. We do a bunch of stupid things.

However, it doesn't really have anything to do with me. I appreciate the thought, but I'd prefer to not be the "MS-Guy" around here. I come here to fight ignorance and have a good time, not to be the corporate spokeperson. I only visit threads like this when I'm named, or if I feel I can positively contribute.
Reply With Quote
  #6  
Old 05-08-2003, 03:19 PM
Lobsang Lobsang is offline
Member
 
Join Date: Mar 2002
Location: Douglas, Isle of Man
Posts: 18,184
I didn't know you were the 'MS-Guy' until you stated that you prefer not to be known as such.


Fix my word please.
Reply With Quote
  #7  
Old 05-08-2003, 03:22 PM
Lobsang Lobsang is offline
Member
 
Join Date: Mar 2002
Location: Douglas, Isle of Man
Posts: 18,184
Mind you - If I worked for MS (which would actually be cool) I wouldn't take the mass contempt personally either. The place I do work at does some cum-feltchingly goat-guzzlingly stupid things, things that make me laugh.
Reply With Quote
  #8  
Old 05-08-2003, 03:31 PM
Morbo Morbo is offline
Charter Member
 
Join Date: Jan 2001
Location: 123 Fake Street
Posts: 8,412
Quote:
Originally posted by Lobsang
I didn't know you were the 'MS-Guy' until you stated that you prefer not to be known as such.
So you must have been pretty confused when the OP mentioned me specifically, eh?

Quote:
Fix my Microsoft® Word please.
Done.

I don't take the mass contempt personally. I take misinformed opinions about the way I do my job personally, however. I would expect no less from any Doper.
Reply With Quote
  #9  
Old 05-08-2003, 03:59 PM
Geek Mecha Geek Mecha is offline
Guest
 
Join Date: Feb 2000
There's a follow-up here, saying MS has fixed the flaw.

My favorite part (bolding mine):
Quote:
By 8 a.m. PST Thursday, the company had replaced the service with a more secure version, one that should have been there in the first place, said Adam Sohn, product manager for Microsoft's Passport team.

"It was something that slipped through the reviews," he said. Sohn added that the feature had been around since September 2002 and that Microsoft is currently investigating to what degree the flaw may have been exploited by online vandals to grab user accounts.
'Cause everyone wants a security flaw.

And if I'm reading it correctly, I find it distressing that MS could let a security flaw of this magnitude remain unpublicized and unadressed for eight months. I mean, gosh, I appreciate the investigation and all, but maybe ya think ya coulda investigated a little faster?
Reply With Quote
  #10  
Old 05-09-2003, 12:38 AM
Mikahw Mikahw is offline
Guest
 
Join Date: Sep 2000
Reason #45657859818875: That damn "o" key that doesn't work
Reply With Quote
  #11  
Old 05-09-2003, 01:55 PM
black rabbit black rabbit is offline
Guest
 
Join Date: Aug 2000
Quote:
Originally posted by Mikahw
Reason #45657859818875: That damn "o" key that doesn't work
Actually, that's reason #1 SuSE sucks, 'cuz I (happily) don't run Windows...
Reply With Quote
  #12  
Old 05-09-2003, 02:48 PM
Mort Furd Mort Furd is offline
Guest
 
Join Date: Apr 2001
As of latest reports on www.heise.de, Microsoft still has some spot that aren't fixed. They reference a site with reports from people who report in after trying the exploits in their area.
Reply With Quote
  #13  
Old 05-09-2003, 03:40 PM
istara istara is offline
Guest
 
Join Date: Mar 2000
Part of the reason M$ gets flamed so often/disproportionately is that they're the dominant and most widespread player.

And they suck

(my religion made me type that, GodJobs would strike me down if I failed to include it...)
Reply With Quote
  #14  
Old 05-10-2003, 02:59 AM
rjung rjung is offline
Guest
 
Join Date: Sep 2000
Quote:
Originally posted by istara
Part of the reason M$ gets flamed so often/disproportionately is that they're the dominant and most widespread player.

And they suck

(my religion made me type that, GodJobs would strike me down if I failed to include it...)
Hey, it's the truth, ainnit?

And GodJobs wouldn't strike you down, he'd simply cuss you out for being an idiot and then throw something at you.
__________________
--R.J.
Electric Escape -- Information superhighway rest area #10,186
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 08:11 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

Send questions for Cecil Adams to: cecil@chicagoreader.com

Send comments about this website to: webmaster@straightdope.com

Terms of Use / Privacy Policy

Advertise on the Straight Dope!
(Your direct line to thousands of the smartest, hippest people on the planet, plus a few total dipsticks.)

Publishers - interested in subscribing to the Straight Dope?
Write to: sdsubscriptions@chicagoreader.com.

Copyright © 2013 Sun-Times Media, LLC.