Live data from Hacker News

Microsoft hits out at Google team over bug report

bbc.co.uk

91–100 of 165 posts

Re: Microsoft hits out at Google team over bug report

#91
If I were MS I wouldn't complain on this issue and instead I would just take the bait and put an internal team to find out bugs exclusively in Google products like for instance Android [1] and declare an arbitrary short disclosure policy [2] and then release these bugs when time is up.

[1] https://news.ycombinator.com/item?id=8874339

[2] https://nakedsecurity.sophos.com/2010/06/15/tavis-ormandy-pl...

Re: Microsoft hits out at Google team over bug report

#92

Earlier quoted context omitted.

What a disingenuous comparison. It's not "accede to our demands or we'll publish this information"; it's "we're publishing this information in 90 days whether you like it or not." If we ask "what gives any company the right to publish vulnerabilities about their competitors?" it's only a short step to asking "what gives journalists the right to publish scathing negative reviews?" The answer is the same: freedom of sp…

It doesn't matter if Google publishes it after the patch. It matters if the publish before . If they publish before the patch, even knowing when the patch will come out, that's enforcing their demands or making MS suffer the consequences. Google knew Microsoft had a patch. Google published it anyway, because their competitor didn't work fast enough, for Google's definition of "fast enough". Journalists are not direct…

> If they publish before the patch, even knowing when the patch will come out, that's enforcing their demands or making MS suffer the consequences.

So? As a general rule, people (and companies) have the right to say things like "I'll do X if you do Y" or "I'll do X unless you do Y". It becomes blackmail under certain circumstances, like where you're threatening to harm someone illegally, or demanding money for covering up a crime. In this case, Google picked a 90-day disclosure timeline which seems to be considered generally reasonable by the security community, so I don't see how they're doing anything wrong by sticking firmly to it.

> Google published it anyway, because their competitor didn't work fast enough, for Google's definition of "fast enough".

Yup, sounds like competition to me.

> Imagine the next bug they find in Windows, and they publish it saying "ChromeOS doesn't have this bug!".

Yup, sounds like competition to me.

Maybe I'm just being dense but it would help if you could explain why you think this is "anti-competitive." To me, forbidding a company from trying to demonstrate that its product is more secure than its competitors' is anti-competitive.

> Would Google publish their own vulnerability if they were unable to fix it in 90 days?

Maybe, maybe not. Presumably since Microsoft has so many employees and cares so much about security, it has its own team of researchers dedicated to finding bugs in Chrome, right? Or is it Google's responsibility to find everyone's bugs, and then give them as much time as they want to fix them?

Re: Microsoft hits out at Google team over bug report

#93
post #76

Earlier quoted context omitted.

In what world does the recipe for Coca Cola in any way influence the maintenance of a fleet of trucks? Google's policy is responsible disclosure. Wavering on the well-known deadline would become a political headache. If you give a mouse a cookie... Two days becomes a week; a week becomes half of a month; half a month becomes a full month. Perhaps if Google is feeling generous, they could not disclose a vulnerability…

Which they're doing with Windows 10. Consumers get them now, business get them on Tuesday. Have you ever deployed patches to a couple thousand machines? It's not something you want to do every night.

When to deploy patches to my thousands of machines is my administration problem, not Microsoft's. Giving me the tools to make these decisions puts more power to protect my company into my hands. Denying patches to me simply to fit a schedule denies me flexibility and, potentially, security.

Re: Microsoft hits out at Google team over bug report

#94
post #5

This is crazy. By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the second patch day, the vulnerability will be disclosed before the third).…

The "second-tuesday-of-the-month" policy is a completely arbitrary MS-only policy. If Google (or any other group that discovers security issues) has to take into account every policy of every software producer it becomes utterly impossible to have any disclosure policy. If MS wants to handicap themselves, that's their problem. The rest of the world doesn't have to bend to their will, those days are over. Yes, this is…

Have you ever managed a nontrivial installation of user-facing desktop systems? 'Cause if not, declaring the policy of a predictable, telegraphed-well-in-advance day on which security patches will drop "peculiar" kind of just reveals where your head's at.

Re: Microsoft hits out at Google team over bug report

#95

TL;DR -- Google found bug in Windows 8.1. Gave Microsoft standard 90 days notice of public release on 11 January. Microsoft wanted to move release date to patch Tuesday on 13 January. Google released on their 90 day notice date of 11 January. Personally, I don't think Google should bend to the internal red tape of other companies. You are going to start maintaining this long list of exceptions based on other peoples…

I wonder how many Android devices out there are missing security updates.

Re: Microsoft hits out at Google team over bug report

#96

Everyone is saying that Google should have waited for Microsoft's patch day, but why should Google bend their standard procedure to fit Microsoft? If it really meant that much to Microsoft, they could have released a patch earlier. They knew they had 90 days and decided to ignore it.

"but why should Google bend their standard procedure to fit Microsoft?" well, there are quite a few users affected.

All the more reason for Microsoft to get to it and release the patch sooner. MS had already said they intended to delay the fix until February. The 90-day deadline seems to be Working As Designed®

Re: Microsoft hits out at Google team over bug report

#97
post #58

What? Microsoft asked for 2 extra days and Google refused? Seems like an asshole move. I am in general a huge Google fan, but in using Google services I realize that I am not much of a customer (I purchase extra storage and buy stuff on the Play Store); advertisers are the customers. Microsoft on the other hand gets its money from computer users and it seems like they have a much more customer focused mentality.

or, Google asked for 90 and Microsoft refused. Who's the asshole? (neither, or both)

I think it is safe to say that it is likely that many end users were hurt by Google not waiting the extra two days.

Re: Microsoft hits out at Google team over bug report

#98
post #78

Earlier quoted context omitted.

> By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. Which is a dumb policy for security patches. When its fixed it should be released. > If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the…

It's a darn good policy if you're the one who is responsible to apply the patches inside of your organisation and you have to test the effect of the patches to the applications running in your company before you actually install them. Applying the patch a few days later typically doesn't noticeably increase your risks but rolling them out unchecked can make some serious damage.

Why can't we just have the choice to apply as soon as it's ready?

If you don't want to apply the patches as soon as they're released, then you'd be more than welcome to put them on hold for 4 weeks yourself when it's more convenient.

Re: Microsoft hits out at Google team over bug report

#99
post #89
post #78

Earlier quoted context omitted.

It's a darn good policy if you're the one who is responsible to apply the patches inside of your organisation and you have to test the effect of the patches to the applications running in your company before you actually install them. Applying the patch a few days later typically doesn't noticeably increase your risks but rolling them out unchecked can make some serious damage.

I wanted to say this, but evidently it was pointless given that seemingly 80% the people on this thread have absolutely no understanding of change management whatsoever, or more importantly the problems you might face when customers have your update infrastructure indirectly linked to national grids and industrial automation. Clearly Microsoft should just release Windows as a repo on GitHub and push fixes to master.

I agree with you and mentioned elsewhere in the thread that patch Tuesday was one of the best moves MS made when they started taking security seriously. Enterprises could now schedule change management around the dates far out into the future which leads to a predictable update schedule downstream.

Before, many enterprises rarely patched because the testing involved was a huge pain and it fell outside what they typically planned for.

Re: Microsoft hits out at Google team over bug report

#100
post #78

Earlier quoted context omitted.

> By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. Which is a dumb policy for security patches. When its fixed it should be released. > If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the…

It's a darn good policy if you're the one who is responsible to apply the patches inside of your organisation and you have to test the effect of the patches to the applications running in your company before you actually install them. Applying the patch a few days later typically doesn't noticeably increase your risks but rolling them out unchecked can make some serious damage.

If you're in a situation where you test the effects of patches before applying them, then if Microsoft releases the security patch early, YOU have the option to wait and apply it on the regular patch day along with any other patches in the normal schedule.

Releasing the patch late (i.e., on patch day) makes that choice for everyone.

Post reply on HN