Live data from Hacker News

Google's Project Zero exposes unpatched Windows 10 lockdown bypass

zdnet.com

11–20 of 126 posts

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#11
post #3

Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 months to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could've cost Google's customers tens of millions in misplaced ad campaigns. 1: https://bugs.chromium.org/p/project-zero/issues/detail?id=15.…

> that could've cost Google's customers tens of millions in misplaced ad campaigns You're comparing an operating system security bug to advertisers' lives being made inconvenient.

Yeah so? Both involve tons of money.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#12
post #3

Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 months to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could've cost Google's customers tens of millions in misplaced ad campaigns. 1: https://bugs.chromium.org/p/project-zero/issues/detail?id=15.…

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question:

1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all.

So your entire post was completely irrelevant.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#13
post #7

Earlier quoted context omitted.

Nobody has any right to set a deadline. The 90 days is merely Google being courteous.

For something installed on so many devices, 90 days seems like an incredibly tight timeframe to change anything.

3 months is more than enough time if you care about your customer's privacy and security.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#14
post #7

Earlier quoted context omitted.

Nobody has any right to set a deadline. The 90 days is merely Google being courteous.

For something installed on so many devices, 90 days seems like an incredibly tight timeframe to change anything.

Don't forget that these 90 days are also 90 more days where this vulnerability can be exploited by attackers.

Microsoft has set up a patch delivery infrastructure that's pretty effective and comparably fast by industry standards, if not deactivated by the people who got offended by the forced Windows 10 upgrade and feature creep.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#15
post #3

Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 months to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could've cost Google's customers tens of millions in misplaced ad campaigns. 1: https://bugs.chromium.org/p/project-zero/issues/detail?id=15.…

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…

Disclosing unpatched vulnerabilities when the company is asking for an extension of a few weeks to patch is absolutely a dick more and extremely irresponsible.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#16
post #3

Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 months to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could've cost Google's customers tens of millions in misplaced ad campaigns. 1: https://bugs.chromium.org/p/project-zero/issues/detail?id=15.…

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…

> First of all, Google has no responsibility to give any period of time.

Any security researcher has a responsibility to disclose a vulnerability in such a way that it does not cause widespread damage. I don't know why you would think otherwise.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#17
post #13
post #7

Earlier quoted context omitted.

For something installed on so many devices, 90 days seems like an incredibly tight timeframe to change anything.

3 months is more than enough time if you care about your customer's privacy and security.

YOu are talking about a very large, complex, mission critical, and incredibly widely used piece of software.

If they mess up a patch it's a big deal. If they break systems, introduce further bugs, etc...

90 days to understand the problem, fix the bug, verify the fix, plan the release, get it out to customers. There is a lot of work involved in such a thing.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#18
post #3

Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 months to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could've cost Google's customers tens of millions in misplaced ad campaigns. 1: https://bugs.chromium.org/p/project-zero/issues/detail?id=15.…

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…

> First of all, Google has no responsibility to give any period of time. It isn't a "dick move".

The motivation of the project is supposedly to protect Google's users. Being firm on disclosure deadlines helps ensure that vendors take the issue seriously. Did they have any indication that Microsoft wasn't taking this seriously? If not, then it sounds like their true motivation is elsewhere.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#19
To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn't going to help protect customers, what's the point in granting an exception?

https://bugs.chromium.org/p/project-zero/issues/detail?id=15...

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#20
post #7

Earlier quoted context omitted.

Nobody has any right to set a deadline. The 90 days is merely Google being courteous.

For something installed on so many devices, 90 days seems like an incredibly tight timeframe to change anything.

Put another way: For something installed on so many devices, 90 days seems like an incredibly long time to leave so many devices vulnerable. Security fixes aren't a once and done thing. New exploits will be discovered that must be fixed. Missing deadlines for less severe exploits encourages getting better at sending security fixes out. Then, when more severe exploits are discovered, they can be patched in a reasonable amount of time. If extensions are always given, then deadlines become meaningless and "90 days" becomes "eh, 6 months given we can push for extensions."
Post reply on HN