Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests
Google's Project Zero exposes unpatched Windows 10 lockdown bypass
91–100 of 126 posts
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#92Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#93Earlier quoted context omitted.
Google has no problem with the GDPR. They helped draft it and are very prepared for it.
Google has huge problem with GDPR, their whole bussiness model is standing on tracking users, they are only smart enough not to piss into the wind. Actually they know far more about you than FB, imagine that they have almost everything you have on your android phone. And let me explain "draft it". They lobbied. The proof for that is fb and ggl attack on Canada to prevent legalising something similar as GDPR. Please (…
Here you are having a study, about your behaviour, READ IT, you will thank me later, you are having issues worth psychiatrical care, help yourself and stop annoying the human race: https://insight.kellogg.northwestern.edu/article/leave_my_br...
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#94Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#95Earlier quoted context omitted.
“Long before Microsoft could patch” meaning when Microsoft decided to cancel a patch Tuesday? If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like? Also in the bug you’re referring to, Google expresses surprise Microsoft let it get through because of the severity, and declined to commen…
> If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like? Microsoft uses a regular patch cadence so enterprise users can allocate the necessary resources for review and update of their computers. There are scores of enterprises that use tens of thousands or hundreds of thousands of comput…
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#96Earlier quoted context omitted.
I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…
On an unrelated note, I think that's a really smart move on the part of the EU. Most of these companies do what they can not to pay taxes in Europe, and counteracting it is difficult without hurting other businesses or creating other kinds o bureaucracy. But with the GDPR, the EU can easily put million-dollar fees on these companies easily.
This applies to all companies, everywhere. The problem is that the EU don't close their loopholes.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#97Earlier quoted context omitted.
> Vendors do not get to arbitrarily model their business to manipulate how disclosure works. Attackers don't care. Right, hence my earlier point, emphasis added: > When so much software runs on your platform, availability matters […]. QA-test the hell out of a patch unless there's evidence of 0d or imminent exploitation. At the expense of sounding like a broken record: (from an arguably oversimplified angle), confide…
I already addressed why that doesn't really hold water: it assumes that you're likely to know if a bug is being exploited or not. Google found the bug. They're already doing the free research, giving Microsoft a reproducer, and giving Microsoft a well-established policy for when they're going to go public with the bug. Are you suggesting they're responsible for knowing if a bug is being exploited in the wild, or that…
Google is operating with limited-to-zero information on what exactly breaks when the bug is fixed, and Windows (or even just the .net framework) is a behemoth. Google and Microsoft do both have threat intelligence groups, but that's a separate thread.
When you're producing software designed to run on many configurations with absolutely stable operation for at least a month at a time, it's extremely, extremely hard to say that "some bugs don't need 6 months of intense QA to fix." I'm not an engineer at Microsoft, but so long as Microsoft is giving routine updates on a private channel—which they did in this case—as to why it's taking so long, it at least signals that the team is in fact actively working towards a resolution.
In fact, with this specific defect, Google applied its own rules/practices to decide whether Redstone 4 (which is my assumed read into what "RS4" means) would be considered a broad patch, whereas Microsoft considers system requirements for minor Windows 10 releases to be hardware-identical in need and entirely backwards-compatible.
Timeline (per the report):
-> 2018-01-19: Reported issue to secure@microsoft.com and received MSRC case number 43182
-> 2018-04-02: Informed MSRC that as the issue will not be fixed with 90+14 days then the grace extension does not apply.
-> 2018-04-06: Informed MSRC that this isn't possible. Made it clear that the issue isn't particularly serious and other .NET based DG bypasses are still unfixed.
-> 2018-04-12: Informed MSRC that as there's no firm date for RS4 this couldn't be applied, and RS4 wouldn't be considered a broadly available patch per the disclosure conditions.
-> 2018-04-19: Issue exceeds deadline.
——————————
——————————
As an aside:
> You are again only interacting with a tiny part of my argument.
I'm developing RSIs and would prefer to minimize my interaction to what's most relevant to the debate. I apologize if that makes it more difficult.
Edit: though for what it's worth, I'm enjoying interacting. I bear no ill will towards you for your perspective; I've seen and learned quite a bit about balancing security and managing business impact as I've continued to climb the career ladder, things which were shielded from me when I was a lowly developer or security engineer.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#98Earlier quoted context omitted.
Do you have any experience with complex systems where a security patch could possibly take more than three months to implement?
He might have or not but I have. Not as complex but similar mission critical and distributed. 90 days is nothing as outlined. Once you go life or death situations, regulatory environment applies, backward compatability matters, ... Everything takes endless. It is not code, commit, test and deploy. Intake, Risk Analysis, project planning, approvals, alignments, etc. So many more processes. We should not fool ourselves…
That is assuming whoever you are replying to is foreign to enterprises.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#99Earlier quoted context omitted.
> If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like? Microsoft uses a regular patch cadence so enterprise users can allocate the necessary resources for review and update of their computers. There are scores of enterprises that use tens of thousands or hundreds of thousands of comput…
I already demonstrated that this is false: there are tons of examples of Google giving MSRC grace periods to hit a patch Tuesday, and in the example GF cited, Microsoft _skipped the patch Tuesday_!
Google is not a lawmaker, and if they continue to release 0-day exploits in this manner, even after being instructed otherwise by the vendors, at some point they will be made to shoulder some of the burdens of their having done so. Google knows this to be true, or they would not have held some recent vulnerabilities past their stated 90 day release window.
Thoughts about the relative technical merits of the companies or source codes doesn't come into play here. These are business decisions that affect real world companies and people.
Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass
#100Earlier quoted context omitted.
I would pay to see this happen. "Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now. Kisses, Microsoft."
I think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has al…
This is pretty blatant re-writing of history. DNT was a piss poor standard that relied on advertisers respecting it. As soon as Microsoft put it on by default they got shit on endlessly for it, and advertisers just bailed anyway.
again, HN was upset at Microsoft for doing it.