Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests
Google's Project Zero exposes unpatched Windows 10 lockdown bypass
71–80 of 126 posts
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#72I think there are so many point of views here. I'm not going to defend Google nor Microsoft, but imagine you're paid by Google to work on security issues. What would be the metric to prove your existence, if there is no public awareness of your work, like this zdnet article? Project Zero IMO from time to time need to show they exists and doing great job. I think that could be one of reasons, why they resists to prolo…
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#73Earlier quoted context omitted.
My thinking would be exactly the opposite - severe bugs have to be disclosed sooner while non-severe can be left lingering around.
And Google has actually had a track record of using that reasoning as well, so it's not like their words actually mean much. Great example of a drive-by high-sev exploit getting exposed long before Microsoft could patch: https://www.digitaltrends.com/computing/google-project-zero-... I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant…
No, they aren’t. Don’t make things up. You don’t know what you’ talking about.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#74I think there are so many point of views here. I'm not going to defend Google nor Microsoft, but imagine you're paid by Google to work on security issues. What would be the metric to prove your existence, if there is no public awareness of your work, like this zdnet article? Project Zero IMO from time to time need to show they exists and doing great job. I think that could be one of reasons, why they resists to prolo…
I have a hard time thinking of a more elite team than P0. They earned their stripes long before they got there. The disclosure policy is the right thing to do, not to make someone feel better about their job.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#75Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests
This could happen 10 years ago, today Microsoft embraced tracking and spying. Win 10 grabs more info about you than google.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#76Earlier quoted context omitted.
YOu are talking about a very large, complex, mission critical, and incredibly widely used piece of software. If they mess up a patch it's a big deal. If they break systems, introduce further bugs, etc... 90 days to understand the problem, fix the bug, verify the fix, plan the release, get it out to customers. There is a lot of work involved in such a thing.
Correct there is a lot of work to be done. It is not 90 days worth of work. If you think that is not enough time, you need to raise your standards.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#77Earlier quoted context omitted.
And Google has actually had a track record of using that reasoning as well, so it's not like their words actually mean much. Great example of a drive-by high-sev exploit getting exposed long before Microsoft could patch: https://www.digitaltrends.com/computing/google-project-zero-... I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant…
”I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant marketing and recruiting trick.” No, they aren’t. Don’t make things up. You don’t know what you’ talking about.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#78Earlier quoted context omitted.
First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…
> First of all, Google has no responsibility to give any period of time. Any security researcher has a responsibility to disclose a vulnerability in such a way that it does not cause widespread damage. I don't know why you would think otherwise.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#79Earlier quoted context omitted.
On an unrelated note, I think that's a really smart move on the part of the EU. Most of these companies do what they can not to pay taxes in Europe, and counteracting it is difficult without hurting other businesses or creating other kinds o bureaucracy. But with the GDPR, the EU can easily put million-dollar fees on these companies easily.
Any fines would likely go to court many times, before they actually have to be paid. And all those large corporations will show up with a huge mountain of lawyers to try and get around any law that may exist. Taxing the large companies is difficult, because of individual countries (like Ireland and Netherlands) free-riding to attract investment, while hurting all other EU members. "Tragedy of the Commons" that sort o…
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#80Earlier quoted context omitted.
“Long before Microsoft could patch” meaning when Microsoft decided to cancel a patch Tuesday? If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like? Also in the bug you’re referring to, Google expresses surprise Microsoft let it get through because of the severity, and declined to commen…
You're reading far more into my comment than I put to paper, but I'll indulge. > If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like? Absolutely and enthusiastically yes, and for absolutely the reason you wrapped in parens. When so much software runs on your platform, availability matt…
Your argument only works if a few things are true:
* P0 is unwilling to budge from the 90 day disclosure if a bug is legitimately hard to fix. But that isn't true: for example, they kept Spectre/Meltdown under wraps for a very long time. It's not just bugs that conveniently affect Google, either: plenty of Windows issues were given grace periods (usually to hit a patch Tuesday). They've even re-restricted bugs after MSRC _failed to request a grace period in time_ (e.g. P0-395).
* If a bug was being exploited, you'd know. (If this isn't true, delay just means attackers have more time to exploit the bug.) But that isn't (generally) true: plenty of bugs are hard to detect remotely, and we have no clue what hoard attackers are sitting on.
Never mind the fact that that the onus is on Microsoft to show that a period is warranted (attackers aren't nice enough to leave them a detailed reproducer), can we even come up with a plausible reason for this bug being delayed that isn't "we didn't prioitize it"? Is there code that legitimately tries to load the wrong DLL? If the argument is just 'QA should win by default" and mine is "disclosure should win by default", we're just going to have to agree to disagree. Vendors do not get to arbitrarily model their business to manipulate how disclosure works. Attackers don't care.