Live data from Hacker News

Google's Project Zero exposes unpatched Windows 10 lockdown bypass

zdnet.com

41–50 of 126 posts

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#41
post #33

Earlier quoted context omitted.

I would pay to see this happen. "Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now. Kisses, Microsoft."

I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…

On an unrelated note, I think that's a really smart move on the part of the EU. Most of these companies do what they can not to pay taxes in Europe, and counteracting it is difficult without hurting other businesses or creating other kinds o bureaucracy. But with the GDPR, the EU can easily put million-dollar fees on these companies easily.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#42
post #3

Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 months to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could've cost Google's customers tens of millions in misplaced ad campaigns. 1: https://bugs.chromium.org/p/project-zero/issues/detail?id=15.…

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…

Bartering on reward money before disclosure can easily look like -or be- blackmail.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#43
post #29

Earlier quoted context omitted.

Yeah. It's not as severe as the article makes it seem. It's just a bypass in a very insignificant component for which you need 2-3 other vulns to exploit. I presume the editor just wanted to put an article out with Microsoft and Project Zero in the title, rather than analyze the actual flaw in the context of its severity.

A journalist lying. Not particularly noteworthy.

The press had many problems, but this isn't close to a lie. Sensationalistic? Maybe. But to accuse the journalist of lying is claiming that the article is (1) false, and (2) that the journalist knows it's false. They're big claims, not to be made as throwaway snark. A functioning (and honest) press matters, and this does it and ourselves no benefit.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#44
post #22

To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn't going to help protect customers, what's the point in granting an exception? https://bugs.chromium.org/p/project-zero/issues/detail?id=15..…

My thinking would be exactly the opposite - severe bugs have to be disclosed sooner while non-severe can be left lingering around.

And Google has actually had a track record of using that reasoning as well, so it's not like their words actually mean much. Great example of a drive-by high-sev exploit getting exposed long before Microsoft could patch: https://www.digitaltrends.com/computing/google-project-zero-...

I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant marketing and recruiting trick.

(It worked well; they stole my favorite pentester from one of my preferred boutique consulting firms.)

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#45
post #33

Earlier quoted context omitted.

I would pay to see this happen. "Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now. Kisses, Microsoft."

I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…

> They can't, and they'll learn it the hard way.

I doubt it. The fines will be completely irrelevant, and they won't even need to notify more than 1% of their lawyers and lobbyists to ensure they can keep it up for the next decade.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#46
post #44
post #22

Earlier quoted context omitted.

My thinking would be exactly the opposite - severe bugs have to be disclosed sooner while non-severe can be left lingering around.

And Google has actually had a track record of using that reasoning as well, so it's not like their words actually mean much. Great example of a drive-by high-sev exploit getting exposed long before Microsoft could patch: https://www.digitaltrends.com/computing/google-project-zero-... I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant…

“Long before Microsoft could patch” meaning when Microsoft decided to cancel a patch Tuesday? If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like?

Also in the bug you’re referring to, Google expresses surprise Microsoft let it get through because of the severity, and declined to comment on details that would only help exploitation. I also don’t see anything on the bug re: will disclose _because_ sev:hi (your core argument AIUI); but I agree that it doesn’t really impact what their policy should be.

You say Google’s words don’t mean anything, but it sounds like you’re advocating for their 90 day disclosure policy to not mean anything whenever a company doesn’t get its act together in time, which I’m sure isn’t your intention. P0 might have some of the best pentesters in the world (it does) but that doesn’t matter much if everyone else gets a ton more time to find and exploit bugs.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#47
post #36

Earlier quoted context omitted.

For a bug that should take no more than a few days to patch and test 90 days seems like more than enough for a product with automatic security updates. For a bug with completely unknown scope and very difficult fixes (such as the recent intel issues) the story might be different. But 90 days here? Why would Microsoft need more than that?

Because of an "unforeseen code relationship", they say. What more could we want to know? It sounds like some other piece of MS software is relying on .NET not performing the checks that it should have been performing.

Windows attempt to always remain backwards compatible has left a huge tangled mess of dependencies. I applaud Microsoft's attempts at this but a slow cycle of breaking changes would allow a much better long-term system. Of course, that also means you have to be committed to some sort of long-term roadmap (something that appeared to be lacking between XP and Longhorn/Vista/7).

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#48
post #45
post #33

Earlier quoted context omitted.

I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…

> They can't, and they'll learn it the hard way. I doubt it. The fines will be completely irrelevant, and they won't even need to notify more than 1% of their lawyers and lobbyists to ensure they can keep it up for the next decade.

GDPR fines can be up to 4% of a company’s turnover (at group level too, not just the turnover of the local subsidiary). Whether the courts will actually use the maximum fine remains to be seen, but on paper it’s enough to give you pause - 4% of revenues is a large chunk of money for anyone. I work for a large EU company and this possibility is taken very seriously.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#49
post #4

Why 90 days? Why not 30, 14, or 7? Microsoft might have requested responsible disclosure for exploits affecting Windows, but what gave Google the right to set a deadline? I feel the 2 US companies have a friendly competition with each other which can help secure their systems.

What gives Microsoft the right to set the deadline? It’s their bug, and the bad guys aren’t going to stop using a bug because Microsoft has decided to be slow at patching.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#50
post #36

Earlier quoted context omitted.

For a bug that should take no more than a few days to patch and test 90 days seems like more than enough for a product with automatic security updates. For a bug with completely unknown scope and very difficult fixes (such as the recent intel issues) the story might be different. But 90 days here? Why would Microsoft need more than that?

Because of an "unforeseen code relationship", they say. What more could we want to know? It sounds like some other piece of MS software is relying on .NET not performing the checks that it should have been performing.

Is Microsoft allowed to make arbitrary business decisions that prevent it from responding to security vulnerabilities or is backwards compatibility given a special pass?

They own an operating system. We get to hold them responsible for whatever choices they make that impact security.

Post reply on HN