TL;DR -- Google found bug in Windows 8.1. Gave Microsoft standard 90 days notice of public release on 11 January. Microsoft wanted to move release date to patch Tuesday on 13 January. Google released on their 90 day notice date of 11 January. Personally, I don't think Google should bend to the internal red tape of other companies. You are going to start maintaining this long list of exceptions based on other peoples…
Microsoft hits out at Google team over bug report
41–50 of 165 posts
Re: Microsoft hits out at Google team over bug report
#42Earlier quoted context omitted.
What if other people already know about the breach? Would you prefer the joy of ignorance, or would you rather protect yourself by some means?
Does it really matter if it's 90 or 92 day disclosure?
Yes. Google designed Project Zero to "pressure firms into dealing with security problems more quickly." A firm policy with unambiguous enforcement has its advantages. Muddying the 90-day deadline with questions about when (and for whom) to make exceptions weakens it. For example, in the future, I expect Microsoft will not wait the extra two days in the event of a security disclosure from Google.
One may disagree with the 90-day policy to begin with. I, for one, think it should have had an exception process built in. But while these are Google policies, not laws, I respect them for adhering to published protocol. Even when it was difficult.
Re: Microsoft hits out at Google team over bug report
#432 days leeway is not uncalled for. Bad form Google.
Didn't they give MS 90 days to patch? (That's two or three patch Tuesdays).
In this case, the bug was reported on 13 Oct, 15 working days before the first Tuesday of November. Assuming Microsoft couldn't fix and test a change to a core service running on millions of desktops in that time, their only remaining opportunity within the disclosure window was the patch day in December - allowing them only 50 calendar days to deal with the bug.
What's worse is that the bug isn't even all that severe. Effectively Google were trying to strong-arm Microsoft into releasing an out of band patch for a minor issue, which would have knock-on effects for thousands of IT departments. A completely dick move, and thankfully one that's being given recognition here.
Shit like this is why I have a hard time dealing with the infosec community in general – a strange mix of conformance to pointless minutia, a deeply ingrained sense of self-importance (only worsening over time with PR crap like APT), and a fatal attraction with some of the most puerile elements of society. The result is a unique melting pot of genius and dumb that I regularly can't stomach.
Re: Microsoft hits out at Google team over bug report
#44This is crazy. By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the second patch day, the vulnerability will be disclosed before the third).…
It seems to me Microsoft is like that student who has 3 months to do a project, but waits until the last 2 days, and then asks the professor to give him some more time. It was Microsoft's responsibility to patch the bug at the last Patch Tuesday.
Re: Microsoft hits out at Google team over bug report
#45Google headcount: ~49k MS headcount: ~130k
There is going to be a huge difference in speed based on size alone, but MS also has a much greater commitment to regression testing than Google ever has.
Google has embraced an engineering culture where the security team can contribute fixes directly to their own projects. I imagine this creates an unreasonable prejudice culture about how easy it is to implement fixes without concern for regression issues. You can see examples of this in recent e.o.y will not fix bug closures in AOSP. Those savants are going to set the usability vs security debate back a decade by by marking all http connections as insecure.
Finally, don't forget that Eric Schmidt agreed to a recruiting cease fire. For. All of their pride and arrogance, those Google security engineers are never going to escape the fact that they have compromised their own potential maximum value so they can sneer at other companies cultures.
Toxic and stupid.
Re: Microsoft hits out at Google team over bug report
#46Re: Microsoft hits out at Google team over bug report
#47I applaud Google for not bending on their 90-day deadline (assuming they do hold all companies to that, and it appears they do). Maybe this incident will help encourage some companies that might otherwise be lax when confronted with a bug to hurry up. There's no telling who else knew about this bug and was actively exploiting it (probably lots of people).
Re: Microsoft hits out at Google team over bug report
#48This is crazy. By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the second patch day, the vulnerability will be disclosed before the third).…
Re: Microsoft hits out at Google team over bug report
#49TL;DR -- Google found bug in Windows 8.1. Gave Microsoft standard 90 days notice of public release on 11 January. Microsoft wanted to move release date to patch Tuesday on 13 January. Google released on their 90 day notice date of 11 January. Personally, I don't think Google should bend to the internal red tape of other companies. You are going to start maintaining this long list of exceptions based on other peoples…
If there can't be any common sense exceptions to the 90-day policy, that's just bureaucracy by itself.
If you don't have it, then you have a lot of time wasted on communication, handling special exceptions, making decisions if you should bend it or not and so on.
Re: Microsoft hits out at Google team over bug report
#50Earlier quoted context omitted.
From the article: >"We asked Google to work with us to protect customers by withholding details until Tuesday, January 13, when we will be releasing a fix," Microsoft's senior director of research Chris Betz said in a blog post.
You're just citing the press release (or a blog post, or whatever). How does that respond to the original question? The issue mentioned in the article [ https://code.google.com/p/google-security-research/issues/de... ] says that: > Microsoft confirmed that they are on target to provide fixes for these issues in February 2015. They asked if this would cause a problem with the 90 day deadline. So (a) Microsoft is unabl…