Live data from Hacker News

Google's Project Zero exposes unpatched Windows 10 lockdown bypass

zdnet.com

31–40 of 126 posts

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#31
post #27

Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests

I would pay to see this happen.

"Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now.

Kisses, Microsoft."

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#32
post #29

Earlier quoted context omitted.

Yeah. It's not as severe as the article makes it seem. It's just a bypass in a very insignificant component for which you need 2-3 other vulns to exploit. I presume the editor just wanted to put an article out with Microsoft and Project Zero in the title, rather than analyze the actual flaw in the context of its severity.

A journalist lying. Not particularly noteworthy.

Didn't you get the memo?

It's not lying, it's giving newsworthy events a "spin" and it totes OK and ethical, because everyone else does it and we're the good guys.

/s

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#33
post #27

Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests

I would pay to see this happen. "Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now. Kisses, Microsoft."

I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10.

They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!).

Microsoft has already been found violating previous and less strict EU privacy laws recently. I think Google, Microsoft, Facebook, Amazon - they'll all end-up paying big fines in the EU within 18 months after the GDPR passes, because neither take it seriously enough and they still think they can use "angles" to trick the regulators as well as users into getting that data without real consent. They can't, and they'll learn it the hard way.

Oh, and the Privacy Shield will likely fall by the end of the year, too. So brace yourselves, it's going to be a wild ride for these privacy violators.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#34
post #3

Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 months to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could've cost Google's customers tens of millions in misplaced ad campaigns. 1: https://bugs.chromium.org/p/project-zero/issues/detail?id=15.…

> that could've cost Google's customers tens of millions in misplaced ad campaigns You're comparing an operating system security bug to advertisers' lives being made inconvenient.

[deleted]

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#35
post #11

Earlier quoted context omitted.

> that could've cost Google's customers tens of millions in misplaced ad campaigns You're comparing an operating system security bug to advertisers' lives being made inconvenient.

Yeah so? Both involve tons of money.

One can have a material impact on people's security, and thus everything from financial stability to physical safety. The other results in some companies making less money via advertising than they otherwise would have.

Both involve money, but let's not pretend that the more money involved, the more important something is.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#36

Earlier quoted context omitted.

Nobody has any right to set a deadline. The 90 days is merely Google being courteous.

For a bug that should take no more than a few days to patch and test 90 days seems like more than enough for a product with automatic security updates. For a bug with completely unknown scope and very difficult fixes (such as the recent intel issues) the story might be different. But 90 days here? Why would Microsoft need more than that?

Because of an "unforeseen code relationship", they say. What more could we want to know?

It sounds like some other piece of MS software is relying on .NET not performing the checks that it should have been performing.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#37
post #17
post #13

Earlier quoted context omitted.

3 months is more than enough time if you care about your customer's privacy and security.

YOu are talking about a very large, complex, mission critical, and incredibly widely used piece of software. If they mess up a patch it's a big deal. If they break systems, introduce further bugs, etc... 90 days to understand the problem, fix the bug, verify the fix, plan the release, get it out to customers. There is a lot of work involved in such a thing.

Do you have any experience with complex systems where a security patch could possibly take more than three months to implement?

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#38
post #26
post #4

Why 90 days? Why not 30, 14, or 7? Microsoft might have requested responsible disclosure for exploits affecting Windows, but what gave Google the right to set a deadline? I feel the 2 US companies have a friendly competition with each other which can help secure their systems.

The right to freedom of speech means Google can say what they want when they want about the vulnerability, giving them the right to set a deadline. There are certainly companies doing much worse than setting 90 day deadlines. For example VUPEN, Hacking Team, and GrayKey selling undisclosed vulnerabilities to "good" governments, and other companies servicing the shadier governments[1]. [1] https://www.bloomberg.com/ne…

>The right to freedom of speech means Google ...

Surely it means specific people employed by Google may "speak". Does the right extend to corporations?

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#39
post #15

Earlier quoted context omitted.

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…

Disclosing unpatched vulnerabilities when the company is asking for an extension of a few weeks to patch is absolutely a dick more and extremely irresponsible.

Seems the researcher's response was something like: "Hey, you know how your front and back door are both unlocked and everybody already knows about it? Well, your bathroom window is open too - so if someone gets past the front gate, across the moat, and into the castle - there's a third unlocked way onto the living quarters."

It's not like _this_ bug alone would get anybody RCE - they'd need to chain up some other way in, and if they've done that there are at least two known and unpatched bugs that'd get them the same place as this one already.

It's just as easy to argue that pushing for extensions to disclosures that aren't going to decrease security is the dick move here...

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#40
post #26

Earlier quoted context omitted.

The right to freedom of speech means Google can say what they want when they want about the vulnerability, giving them the right to set a deadline. There are certainly companies doing much worse than setting 90 day deadlines. For example VUPEN, Hacking Team, and GrayKey selling undisclosed vulnerabilities to "good" governments, and other companies servicing the shadier governments[1]. [1] https://www.bloomberg.com/ne…

>The right to freedom of speech means Google ... Surely it means specific people employed by Google may "speak". Does the right extend to corporations?

Corporations are people. https://www.npr.org/2014/07/28/335288388/when-did-companies-...
Post reply on HN