Earlier quoted context omitted.
I would pay to see this happen. "Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now. Kisses, Microsoft."
I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…
Google's Project Zero exposes unpatched Windows 10 lockdown bypass
41–50 of 126 posts
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#42Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 months to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could've cost Google's customers tens of millions in misplaced ad campaigns. 1: https://bugs.chromium.org/p/project-zero/issues/detail?id=15.…
First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#43Earlier quoted context omitted.
Yeah. It's not as severe as the article makes it seem. It's just a bypass in a very insignificant component for which you need 2-3 other vulns to exploit. I presume the editor just wanted to put an article out with Microsoft and Project Zero in the title, rather than analyze the actual flaw in the context of its severity.
A journalist lying. Not particularly noteworthy.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#44To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn't going to help protect customers, what's the point in granting an exception? https://bugs.chromium.org/p/project-zero/issues/detail?id=15..…
My thinking would be exactly the opposite - severe bugs have to be disclosed sooner while non-severe can be left lingering around.
I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant marketing and recruiting trick.
(It worked well; they stole my favorite pentester from one of my preferred boutique consulting firms.)
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#45Earlier quoted context omitted.
I would pay to see this happen. "Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now. Kisses, Microsoft."
I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…
I doubt it. The fines will be completely irrelevant, and they won't even need to notify more than 1% of their lawyers and lobbyists to ensure they can keep it up for the next decade.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#46Earlier quoted context omitted.
My thinking would be exactly the opposite - severe bugs have to be disclosed sooner while non-severe can be left lingering around.
And Google has actually had a track record of using that reasoning as well, so it's not like their words actually mean much. Great example of a drive-by high-sev exploit getting exposed long before Microsoft could patch: https://www.digitaltrends.com/computing/google-project-zero-... I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant…
Also in the bug you’re referring to, Google expresses surprise Microsoft let it get through because of the severity, and declined to comment on details that would only help exploitation. I also don’t see anything on the bug re: will disclose _because_ sev:hi (your core argument AIUI); but I agree that it doesn’t really impact what their policy should be.
You say Google’s words don’t mean anything, but it sounds like you’re advocating for their 90 day disclosure policy to not mean anything whenever a company doesn’t get its act together in time, which I’m sure isn’t your intention. P0 might have some of the best pentesters in the world (it does) but that doesn’t matter much if everyone else gets a ton more time to find and exploit bugs.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#47Earlier quoted context omitted.
For a bug that should take no more than a few days to patch and test 90 days seems like more than enough for a product with automatic security updates. For a bug with completely unknown scope and very difficult fixes (such as the recent intel issues) the story might be different. But 90 days here? Why would Microsoft need more than that?
Because of an "unforeseen code relationship", they say. What more could we want to know? It sounds like some other piece of MS software is relying on .NET not performing the checks that it should have been performing.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#48Earlier quoted context omitted.
I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…
> They can't, and they'll learn it the hard way. I doubt it. The fines will be completely irrelevant, and they won't even need to notify more than 1% of their lawyers and lobbyists to ensure they can keep it up for the next decade.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#49Why 90 days? Why not 30, 14, or 7? Microsoft might have requested responsible disclosure for exploits affecting Windows, but what gave Google the right to set a deadline? I feel the 2 US companies have a friendly competition with each other which can help secure their systems.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#50Earlier quoted context omitted.
For a bug that should take no more than a few days to patch and test 90 days seems like more than enough for a product with automatic security updates. For a bug with completely unknown scope and very difficult fixes (such as the recent intel issues) the story might be different. But 90 days here? Why would Microsoft need more than that?
Because of an "unforeseen code relationship", they say. What more could we want to know? It sounds like some other piece of MS software is relying on .NET not performing the checks that it should have been performing.
They own an operating system. We get to hold them responsible for whatever choices they make that impact security.