Live data from Hacker News

Google's Project Zero exposes unpatched Windows 10 lockdown bypass

zdnet.com

51–60 of 126 posts

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#51
post #15

Earlier quoted context omitted.

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…

Disclosing unpatched vulnerabilities when the company is asking for an extension of a few weeks to patch is absolutely a dick more and extremely irresponsible.

What is an acceptable amount of time? Why isn’t 90 days the correct number? A comparable bug has been out since Aug2017 and MS hasn’t patched it. Is a year the right number? Does everyone get that extension by asking? How does that help anyone but the people who own the bugs to save face publicly and attackers more time to exploit the bug?

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#52
post #47
post #36

Earlier quoted context omitted.

Because of an "unforeseen code relationship", they say. What more could we want to know? It sounds like some other piece of MS software is relying on .NET not performing the checks that it should have been performing.

Windows attempt to always remain backwards compatible has left a huge tangled mess of dependencies. I applaud Microsoft's attempts at this but a slow cycle of breaking changes would allow a much better long-term system. Of course, that also means you have to be committed to some sort of long-term roadmap (something that appeared to be lacking between XP and Longhorn/Vista/7).

The last time they did that was with the launch of vista. People were not pleased.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#53
post #27

Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests

Just think about it before you ask for that.

Imagine if DNS resolution on Windows was pay-to-play.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#54

To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn't going to help protect customers, what's the point in granting an exception? https://bugs.chromium.org/p/project-zero/issues/detail?id=15..…

Alice: "My bug isn't particularly severe, and there are similar issues from Bob and Carol. If it isn't going to protect customers, what is the point in fixing it?"

Bob: "My bug isn't particularly severe, and there are similar issues from Alice and Carol. If it isn't going to protect customers, what is the point in fixing it?"

Carol: "My bug isn't particularly severe, and there are similar issues from Alice and Bob. If it isn't going to protect customers, what is the point in fixing it?"

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#55
post #33

Earlier quoted context omitted.

I would pay to see this happen. "Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now. Kisses, Microsoft."

I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…

Google has no problem with the GDPR. They helped draft it and are very prepared for it.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#56
post #33

Earlier quoted context omitted.

I would pay to see this happen. "Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now. Kisses, Microsoft."

I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…

To be clear, DNT being enabled by default was probably more harmful to DNT than helpful. DNT should have been a choice from users and a clear indication of intent; by making it Default, there was no conscious decision like there is with Ad-blocking. DNT should have been (be) the clear message from users they do or do not want something, an undeniable response to over-reaching TOSes.

Microsoft making it default felt less like something to help consumers and more just bandwagoning. Whether or not DNT was particularly effective as a means of __blocking__ tracking has always been irrelevant. The point was the __message__ sent by those who enabled it.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#57
post #17

Earlier quoted context omitted.

YOu are talking about a very large, complex, mission critical, and incredibly widely used piece of software. If they mess up a patch it's a big deal. If they break systems, introduce further bugs, etc... 90 days to understand the problem, fix the bug, verify the fix, plan the release, get it out to customers. There is a lot of work involved in such a thing.

Do you have any experience with complex systems where a security patch could possibly take more than three months to implement?

He might have or not but I have. Not as complex but similar mission critical and distributed. 90 days is nothing as outlined.

Once you go life or death situations, regulatory environment applies, backward compatability matters, ... Everything takes endless. It is not code, commit, test and deploy. Intake, Risk Analysis, project planning, approvals, alignments, etc. So many more processes. We should not fool ourselves that other platforms are better in that once you go for serious SLAs. Linux Kernel or user land patch might be fast, but RedHat delivery will take longer.

Welcome to Enterprise development.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#58
post #14
post #7

Earlier quoted context omitted.

For something installed on so many devices, 90 days seems like an incredibly tight timeframe to change anything.

Don't forget that these 90 days are also 90 more days where this vulnerability can be exploited by attackers. Microsoft has set up a patch delivery infrastructure that's pretty effective and comparably fast by industry standards, if not deactivated by the people who got offended by the forced Windows 10 upgrade and feature creep.

Well, Windows Update is forcing me to deactivate it in one machine bacause it continues to make it unusable. I have come to terms with most quirks of the forced updates, but in this particular situation Windows is nasty und uncooperative.

Add to it Microsofts well established unwillingness to provide any useful diagnostic information and suddenly the only way to use the machine is to not update it.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#59

To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn't going to help protect customers, what's the point in granting an exception? https://bugs.chromium.org/p/project-zero/issues/detail?id=15..…

Alice: "My bug isn't particularly severe, and there are similar issues from Bob and Carol. If it isn't going to protect customers, what is the point in fixing it?" Bob: "My bug isn't particularly severe, and there are similar issues from Alice and Carol. If it isn't going to protect customers, what is the point in fixing it?" Carol: "My bug isn't particularly severe, and there are similar issues from Alice and Bob. I…

That preexisting exploit has been known since at least August 3 2017, so it's not like MS is scrambling to fix these.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#60

Earlier quoted context omitted.

>The right to freedom of speech means Google ... Surely it means specific people employed by Google may "speak". Does the right extend to corporations?

Corporations are people. https://www.npr.org/2014/07/28/335288388/when-did-companies-...

Corporations are made of people and you do not lose your rights because you form a corporation.
Post reply on HN