Defense in depth — the Microsoft way (part 34): our developers and our QA still ignore our own security recommendations

Posted by Stefan Kanthak on Sep 10

Hi @ll,

part 16 <http://seclists.org/fulldisclosure/2014/May/211> showed
the about 2000 [*] registry entries of Windows 8.1 where Microsoft’s
developers ignore their companies own security recommendations and
use unqualified pathnames.

Unfortunately they still ignore these recommendations with Windows 10:
see <http://home.arcor.de/skanthak/download/W10_PATH.INF> for the
about 2000 registry entries with unqualified pathnames…

Leave a Reply