Live data from Hacker News

Google's Project Zero exposes unpatched Windows 10 lockdown bypass

zdnet.com

101–110 of 126 posts

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#101
post #26

Earlier quoted context omitted.

The right to freedom of speech means Google can say what they want when they want about the vulnerability, giving them the right to set a deadline. There are certainly companies doing much worse than setting 90 day deadlines. For example VUPEN, Hacking Team, and GrayKey selling undisclosed vulnerabilities to "good" governments, and other companies servicing the shadier governments[1]. [1] https://www.bloomberg.com/ne…

>The right to freedom of speech means Google ... Surely it means specific people employed by Google may "speak". Does the right extend to corporations?

> Does the right extend to corporations

Unfortunately it does, to some degree.

Religious freedom too. The US is fucked.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#102
post #18

Earlier quoted context omitted.

First of all, Google has no responsibility to give any period of time. It isn't a "dick move". Second, the researcher in question: 1) Never gave a required date for disclosure. 2) Upon requesting the right to disclose, was told no and he followed suit. 3) Was initially offered a bug bounty of $1300, which was upgraded to $5000. He apparently never bartered on that issue at all. So your entire post was completely irre…

> First of all, Google has no responsibility to give any period of time. It isn't a "dick move". The motivation of the project is supposedly to protect Google's users. Being firm on disclosure deadlines helps ensure that vendors take the issue seriously. Did they have any indication that Microsoft wasn't taking this seriously? If not, then it sounds like their true motivation is elsewhere.

> The motivation of the project is supposedly to protect Google's users

Exposing competitors security bugs is only a nice marketing side effect.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#103
post #99
post #95

Earlier quoted context omitted.

I already demonstrated that this is false: there are tons of examples of Google giving MSRC grace periods to hit a patch Tuesday, and in the example GF cited, Microsoft _skipped the patch Tuesday_!

That doesn't demonstrate this is false. This is true, because these are the actions being taken at this time... That different things happened for other vulnerabilities is not relevant to this situation. Google is threatening to publicly release an exploit for which Microsoft has admitted they are already working on a fix. Google is not a lawmaker, and if they continue to release 0-day exploits in this manner, even a…

Statements like this suggest a fundamental misunderstanding of what a vulnerability is. Google will never be held responsible for someone else’s mistakes, no matter how they make those mistakes known.

Your speculation about the reasoning for the extension could not be more off. All you have to do is read their blog discussing their disclosure policy to understand why those exist.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#104
post #99

Earlier quoted context omitted.

That doesn't demonstrate this is false. This is true, because these are the actions being taken at this time... That different things happened for other vulnerabilities is not relevant to this situation. Google is threatening to publicly release an exploit for which Microsoft has admitted they are already working on a fix. Google is not a lawmaker, and if they continue to release 0-day exploits in this manner, even a…

Statements like this suggest a fundamental misunderstanding of what a vulnerability is. Google will never be held responsible for someone else’s mistakes, no matter how they make those mistakes known. Your speculation about the reasoning for the extension could not be more off. All you have to do is read their blog discussing their disclosure policy to understand why those exist.

> Statements like this suggest a fundamental misunderstanding of what a vulnerability is.

That's simply absurd. Stop trying to turn a discussion into an argument.

> Your speculation about the reasoning for the extension could not be more off.

What was my speculation about Google's reasoning? I made no speculation whatsoever about Google's reasoning. Their stated reasonings in a blog post don't matter. Their actions matter.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#105

Earlier quoted context omitted.

Corporations are people. https://www.npr.org/2014/07/28/335288388/when-did-companies-...

That doesn't answer the question. Do corporations have the right to bear arms separate to the rights of the members of the corp - can Google keep an arsenal even if none of the people in it had a gun license?

Knowledge of where Microsoft forgot to enable a security check is not “bearing arms”.

Imagine that world. I point out a mistake to you, and by reading or hearing it, you are suddenly holding a gun! We would have to criminalize coredumps :)

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#106
post #18

Earlier quoted context omitted.

> First of all, Google has no responsibility to give any period of time. It isn't a "dick move". The motivation of the project is supposedly to protect Google's users. Being firm on disclosure deadlines helps ensure that vendors take the issue seriously. Did they have any indication that Microsoft wasn't taking this seriously? If not, then it sounds like their true motivation is elsewhere.

> Did they have any indication that Microsoft wasn't taking this seriously? If not, then it sounds like their true motivation is elsewhere. That doesn't follow. The primary reason to be firm is to ensure that vendors take future issues seriously. Belief that the vendor is serious about a single issue removes only a tiny fraction of the motivation to be firm on deadlines.

There are two possible outcomes with any security issue:

1) The issue is so obscure that nobody else in the world will ever discover it, so not disclosing it to anyone but the vendor is the right choice.

2) The issue has been discovered by someone with malicious intent, and every second that you hide the details from the users, they're at risk.

You can't know which case applies, which is why policies about disclosure are useful. If a vendor is informed of a security hole, and they immediately fix it, great, users are saved. If a vendor is informed of a security hole, and they do nothing... eventually users will have to mitigate the risk in their own way (which is usually "stop using the flawed product"). A disclosure deadline strikes a balance; in many cases it's pretty likely that no evildoers have independently discovered the flaw, but would be able to exploit it if they knew the details. So giving the vendor a bit of time to fix the issue is the best solution. But given infinite time, all bugs will be discovered and exploited, so the longer you wait to fix or mitigate, the more risk you take on. Therefore, I think Google's policy strikes a very reasonable balance between protecting through patching and protecting by telling users to use something else.

With that in mind, I have no real qualms with people that disclose flaws immediately (letting users be aware of their risk), or vendors that fix an obscure bug that's not being exploited slowly. In the end, if users want to be free from all risk, they should be finding and mitigating these issues themselves... anything you get for free out of someone else's goodwill is a benefit.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#107

Earlier quoted context omitted.

>The right to freedom of speech means Google ... Surely it means specific people employed by Google may "speak". Does the right extend to corporations?

Corporations are people. https://www.npr.org/2014/07/28/335288388/when-did-companies-...

No corporations aren't people. That headline is pure clickbait. Some rights are extended to corporations due to corporations being a group of people who come together for a purpose.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#108
post #26

Earlier quoted context omitted.

The right to freedom of speech means Google can say what they want when they want about the vulnerability, giving them the right to set a deadline. There are certainly companies doing much worse than setting 90 day deadlines. For example VUPEN, Hacking Team, and GrayKey selling undisclosed vulnerabilities to "good" governments, and other companies servicing the shadier governments[1]. [1] https://www.bloomberg.com/ne…

>The right to freedom of speech means Google ... Surely it means specific people employed by Google may "speak". Does the right extend to corporations?

Yes, it does, at least since 2010.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#109
Google reported the issue to Microsoft on January 19. Microsoft confirmed the issue about three weeks later

Microsoft should make a mental note that when you receive an email from a member of Google's Project Zero team you don't wait 3 weeks to respond.

Re: Google's Project Zero exposes unpatched Windows 10 lockdown bypass

#110

Google reported the issue to Microsoft on January 19. Microsoft confirmed the issue about three weeks later Microsoft should make a mental note that when you receive an email from a member of Google's Project Zero team you don't wait 3 weeks to respond.

Answering an email and confirming an issue is not really the same thing.
Post reply on HN