Live data from Hacker News

Google's Project Zero exposes unpatched Windows 10 lockdown bypass

zdnet.com

61–70 of 126 posts

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#61

To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn't going to help protect customers, what's the point in granting an exception? https://bugs.chromium.org/p/project-zero/issues/detail?id=15..…

Alice: "My bug isn't particularly severe, and there are similar issues from Bob and Carol. If it isn't going to protect customers, what is the point in fixing it?" Bob: "My bug isn't particularly severe, and there are similar issues from Alice and Carol. If it isn't going to protect customers, what is the point in fixing it?" Carol: "My bug isn't particularly severe, and there are similar issues from Alice and Bob. I…

Because attackers only need 1 of the bugs to work? The argument only tenuously holds for disclosure to begin with, but it doesn’t make sense at all for patching.

Also, the other bug has been known, with POC, for more than half a year.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#62
post #18

Earlier quoted context omitted.

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…

> First of all, Google has no responsibility to give any period of time. It isn't a "dick move". The motivation of the project is supposedly to protect Google's users. Being firm on disclosure deadlines helps ensure that vendors take the issue seriously. Did they have any indication that Microsoft wasn't taking this seriously? If not, then it sounds like their true motivation is elsewhere.

They asked for multiple extensions, couldn’t give a hard deadline on the Redstone release, didn’t disclose why it was hard to patch (“unforeseen code interactions” is basically every patch ever, definitionally!) and a comparable bug has gone unpatched since being publicly disclosed since Aug 2017. Also, looking at the fix... if they have code that relies on being able to lie about which DLL a COM object maps to maybe that’s a problem?!

The onus is on MS to show more time is warranted, and so far I’m only seeing evidence to the contrary.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#63

To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn't going to help protect customers, what's the point in granting an exception? https://bugs.chromium.org/p/project-zero/issues/detail?id=15..…

Alice: "My bug isn't particularly severe, and there are similar issues from Bob and Carol. If it isn't going to protect customers, what is the point in fixing it?" Bob: "My bug isn't particularly severe, and there are similar issues from Alice and Carol. If it isn't going to protect customers, what is the point in fixing it?" Carol: "My bug isn't particularly severe, and there are similar issues from Alice and Bob. I…

it seems that cartels are sometimes very useful

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#64

To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn't going to help protect customers, what's the point in granting an exception? https://bugs.chromium.org/p/project-zero/issues/detail?id=15..…

Alice: "My bug isn't particularly severe, and there are similar issues from Bob and Carol. If it isn't going to protect customers, what is the point in fixing it?" Bob: "My bug isn't particularly severe, and there are similar issues from Alice and Carol. If it isn't going to protect customers, what is the point in fixing it?" Carol: "My bug isn't particularly severe, and there are similar issues from Alice and Bob. I…

First off, this is about disclosure, not fixing.

Second, you're neglecting the time aspect.

This is a valid argument: "There's a similar issue that microsoft hasn't bothered patching for months, so what's the point in keeping it secret?"

This is not a valid argument: "In a few months there will be a similar issue, so what's the point in keeping it secret?"

So there is no loop leading to mistakes.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#65
post #55
post #33

Earlier quoted context omitted.

I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…

Google has no problem with the GDPR. They helped draft it and are very prepared for it.

Google has huge problem with GDPR, their whole bussiness model is standing on tracking users, they are only smart enough not to piss into the wind. Actually they know far more about you than FB, imagine that they have almost everything you have on your android phone.

And let me explain "draft it". They lobbied. The proof for that is fb and ggl attack on Canada to prevent legalising something similar as GDPR.

Please (PLEASE, FOR GOD SAKE!), stop beeing protective to corporations, either FB, CocaCola, Tesla, Google or whatever comes to your mind. None is have priority in making world a better place, their only priority is money and power and money and they do not care about you more then a milking cow. If you disagree, you have fundamential lack of understanding how world functions.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#66
post #57

Earlier quoted context omitted.

Do you have any experience with complex systems where a security patch could possibly take more than three months to implement?

He might have or not but I have. Not as complex but similar mission critical and distributed. 90 days is nothing as outlined. Once you go life or death situations, regulatory environment applies, backward compatability matters, ... Everything takes endless. It is not code, commit, test and deploy. Intake, Risk Analysis, project planning, approvals, alignments, etc. So many more processes. We should not fool ourselves…

Very very little of enterprise is life or death, and windows is not suitable for life or death.

When enterprise just falls on its face, I don't have much sympathy. "So many more processes" sounds like taking a handful of steps, splitting them up, and making each one require multiple days of memos back and forth. Can you provide any justification for this? Am I misreading?

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#67
post #33

Earlier quoted context omitted.

I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…

On an unrelated note, I think that's a really smart move on the part of the EU. Most of these companies do what they can not to pay taxes in Europe, and counteracting it is difficult without hurting other businesses or creating other kinds o bureaucracy. But with the GDPR, the EU can easily put million-dollar fees on these companies easily.

Any fines would likely go to court many times, before they actually have to be paid. And all those large corporations will show up with a huge mountain of lawyers to try and get around any law that may exist.

Taxing the large companies is difficult, because of individual countries (like Ireland and Netherlands) free-riding to attract investment, while hurting all other EU members. "Tragedy of the Commons" that sort of thing.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#68
post #18

Earlier quoted context omitted.

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…

> First of all, Google has no responsibility to give any period of time. It isn't a "dick move". The motivation of the project is supposedly to protect Google's users. Being firm on disclosure deadlines helps ensure that vendors take the issue seriously. Did they have any indication that Microsoft wasn't taking this seriously? If not, then it sounds like their true motivation is elsewhere.

> Did they have any indication that Microsoft wasn't taking this seriously? If not, then it sounds like their true motivation is elsewhere.

That doesn't follow. The primary reason to be firm is to ensure that vendors take future issues seriously. Belief that the vendor is serious about a single issue removes only a tiny fraction of the motivation to be firm on deadlines.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#69
post #46
post #44

Earlier quoted context omitted.

And Google has actually had a track record of using that reasoning as well, so it's not like their words actually mean much. Great example of a drive-by high-sev exploit getting exposed long before Microsoft could patch: https://www.digitaltrends.com/computing/google-project-zero-... I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant…

“Long before Microsoft could patch” meaning when Microsoft decided to cancel a patch Tuesday? If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like? Also in the bug you’re referring to, Google expresses surprise Microsoft let it get through because of the severity, and declined to commen…

You're reading far more into my comment than I put to paper, but I'll indulge.

> If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like?

Absolutely and enthusiastically yes, and for absolutely the reason you wrapped in parens.

When so much software runs on your platform, availability matters (and is a critical component of security, which I feel Google doesn't quite understand for reasons not entirely related to p0). QA-test the hell out of a patch unless there's evidence of 0d or imminent exploitation. Plenty of examples exist where that kind of regression testing was provably necessary, such as this one case:

https://technet.microsoft.com/library/security/MS15-011

https://blogs.technet.microsoft.com/srd/2015/02/10/ms15-011-...

I'm happy as hell it wasn't p0 who found that one.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#70
I think there are so many point of views here. I'm not going to defend Google nor Microsoft, but imagine you're paid by Google to work on security issues. What would be the metric to prove your existence, if there is no public awareness of your work, like this zdnet article? Project Zero IMO from time to time need to show they exists and doing great job. I think that could be one of reasons, why they resists to prolong standard 90 day period.
Post reply on HN