Live data from Hacker News

Google's Project Zero exposes unpatched Windows 10 lockdown bypass

zdnet.com

81–90 of 126 posts

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#81
post #80
post #69

Earlier quoted context omitted.

You're reading far more into my comment than I put to paper, but I'll indulge. > If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like? Absolutely and enthusiastically yes, and for absolutely the reason you wrapped in parens. When so much software runs on your platform, availability matt…

What did I read into your comment that you didn't say? You claimed Google used a line of reasoning when it suits them, I refuted that. Your argument only works if a few things are true: * P0 is unwilling to budge from the 90 day disclosure if a bug is legitimately hard to fix. But that isn't true: for example, they kept Spectre/Meltdown under wraps for a very long time. It's not just bugs that conveniently affect Goo…

> Vendors do not get to arbitrarily model their business to manipulate how disclosure works. Attackers don't care.

Right, hence my earlier point, emphasis added:

> When so much software runs on your platform, availability matters […]. QA-test the hell out of a patch unless there's evidence of 0d or imminent exploitation.

At the expense of sounding like a broken record: (from an arguably oversimplified angle), confidentiality, integrity, and availability all matter.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#82
post #81
post #80

Earlier quoted context omitted.

What did I read into your comment that you didn't say? You claimed Google used a line of reasoning when it suits them, I refuted that. Your argument only works if a few things are true: * P0 is unwilling to budge from the 90 day disclosure if a bug is legitimately hard to fix. But that isn't true: for example, they kept Spectre/Meltdown under wraps for a very long time. It's not just bugs that conveniently affect Goo…

> Vendors do not get to arbitrarily model their business to manipulate how disclosure works. Attackers don't care. Right, hence my earlier point, emphasis added: > When so much software runs on your platform, availability matters […]. QA-test the hell out of a patch unless there's evidence of 0d or imminent exploitation. At the expense of sounding like a broken record: (from an arguably oversimplified angle), confide…

I already addressed why that doesn't really hold water: it assumes that you're likely to know if a bug is being exploited or not. Google found the bug. They're already doing the free research, giving Microsoft a reproducer, and giving Microsoft a well-established policy for when they're going to go public with the bug. Are you suggesting they're responsible for knowing if a bug is being exploited in the wild, or that we should take Microsoft's word for it if it is or not?

To be clear: Microsoft can do whatever they want with the bug they themselves found too. (I imagine their internal teams would want similar policies to make sure that they can hold internal teams accountable for fixing their bugs, though, but whatever, that's on them.)

You are again only interacting with a tiny part of my argument. We're taking it as read that somehow this bug requires significant QA. Can we agree that some bugs don't need 6 months of intense QA to fix? A UAF is a UAF.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#83

Earlier quoted context omitted.

>The right to freedom of speech means Google ... Surely it means specific people employed by Google may "speak". Does the right extend to corporations?

Corporations are people. https://www.npr.org/2014/07/28/335288388/when-did-companies-...

That doesn't answer the question. Do corporations have the right to bear arms separate to the rights of the members of the corp - can Google keep an arsenal even if none of the people in it had a gun license?

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#84
post #46
post #44

Earlier quoted context omitted.

And Google has actually had a track record of using that reasoning as well, so it's not like their words actually mean much. Great example of a drive-by high-sev exploit getting exposed long before Microsoft could patch: https://www.digitaltrends.com/computing/google-project-zero-... I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant…

“Long before Microsoft could patch” meaning when Microsoft decided to cancel a patch Tuesday? If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like? Also in the bug you’re referring to, Google expresses surprise Microsoft let it get through because of the severity, and declined to commen…

> If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like?

Microsoft uses a regular patch cadence so enterprise users can allocate the necessary resources for review and update of their computers. There are scores of enterprises that use tens of thousands or hundreds of thousands of computers per install.

The manner of Google's expected information release puts many end-customers at risk. It is true that in this case the vulnerability was due to Microsoft, but the release of exploitable information will put enterprises at risk. That is why Microsoft asked for additional time. This is a business decision not a technical decision.

Sure, Microsoft may have encountered technical issues in their fixing of the issue, but the risk upon exploit information being released is the issue. Google shoulders that risk all by themselves.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#86
post #55
post #33

Earlier quoted context omitted.

I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…

Google has no problem with the GDPR. They helped draft it and are very prepared for it.

> Google has no problem with the GDPR. They helped draft it and are very prepared for it.

The opposite is true, despite Google having lobbied during the drafting. The entire premise of how google makes money conflicts with GDPR.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#87
post #17

Earlier quoted context omitted.

YOu are talking about a very large, complex, mission critical, and incredibly widely used piece of software. If they mess up a patch it's a big deal. If they break systems, introduce further bugs, etc... 90 days to understand the problem, fix the bug, verify the fix, plan the release, get it out to customers. There is a lot of work involved in such a thing.

Do you have any experience with complex systems where a security patch could possibly take more than three months to implement?

I have that experience. Security patches take a long time. You need to ensure that mission critical operations are not impacted, that the private builds which had been supplied to customers are not impacted, that documentation gets updated, that laws and regulations are followed across the world and in specific regulated verticals, etc. Then customers need time to review the patches and follow through on their schedule of updating their devices.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#88
post #26

Earlier quoted context omitted.

The right to freedom of speech means Google can say what they want when they want about the vulnerability, giving them the right to set a deadline. There are certainly companies doing much worse than setting 90 day deadlines. For example VUPEN, Hacking Team, and GrayKey selling undisclosed vulnerabilities to "good" governments, and other companies servicing the shadier governments[1]. [1] https://www.bloomberg.com/ne…

>The right to freedom of speech means Google ... Surely it means specific people employed by Google may "speak". Does the right extend to corporations?

This speech was ultimately done by specific people employed by Google.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#89
post #71
post #27

Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests

This could happen 10 years ago, today Microsoft embraced tracking and spying. Win 10 grabs more info about you than google.

No it doesn’t. Not even close.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#90
post #71
post #27

Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests

This could happen 10 years ago, today Microsoft embraced tracking and spying. Win 10 grabs more info about you than google.

You need to check your facts.
Post reply on HN