Earlier quoted context omitted.
> By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. Which is a dumb policy for security patches. When its fixed it should be released. > If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the…
It's a darn good policy if you're the one who is responsible to apply the patches inside of your organisation and you have to test the effect of the patches to the applications running in your company before you actually install them. Applying the patch a few days later typically doesn't noticeably increase your risks but rolling them out unchecked can make some serious damage.
Microsoft hits out at Google team over bug report
121–130 of 165 posts
Re: Microsoft hits out at Google team over bug report
#122Re: Microsoft hits out at Google team over bug report
#123Re: Microsoft hits out at Google team over bug report
#124Re: Microsoft hits out at Google team over bug report
#125"Do no evil" Unless it hurts a competitor and is bad for their customers.
Google's action resulted in a security bugfix which improved the security of Windows, and on faster schedule than Microsoft would have provided otherwise. But sure, let's call it evil.
I don't believe for a second that they would have disclosed this if it was Android and they had a fix that would land within 2 days. No f'ing way.
That's the evil.
Re: Microsoft hits out at Google team over bug report
#126Isn't this all MS's fault for having a security flaw in their system? If the Project Zero programmers were independent or malicious, they could have sold this information or released it without giving the 90 day window. Seems like Google is trying to do the right thing by alerting others on these flaws and holding a fast deadline to fix it.
Re: Microsoft hits out at Google team over bug report
#127Earlier quoted context omitted.
> By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. Which is a dumb policy for security patches. When its fixed it should be released. > If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the…
It's a darn good policy if you're the one who is responsible to apply the patches inside of your organisation and you have to test the effect of the patches to the applications running in your company before you actually install them. Applying the patch a few days later typically doesn't noticeably increase your risks but rolling them out unchecked can make some serious damage.
Re: Microsoft hits out at Google team over bug report
#128Even given that Windows 8.1 is a large and complicated machine, what was it about this particular bug that required basically all of Q4 for MS to patch it?
It's one bug.
I have a sinking suspicion that MS simply didn't consider it a priority, even after responsible disclosure to them, which is why it's good that Google's public disclosure policy is a hard-limit 90 days. Too many companies, when given the option to choose their own priority tree over the priority tree enforced by security needs, will choose the former.
Re: Microsoft hits out at Google team over bug report
#129Earlier quoted context omitted.
or, Google asked for 90 and Microsoft refused. Who's the asshole? (neither, or both)
I think it is safe to say that it is likely that many end users were hurt by Google not waiting the extra two days.
Re: Microsoft hits out at Google team over bug report
#130Earlier quoted context omitted.
or, Google asked for 90 and Microsoft refused. Who's the asshole? (neither, or both)
I think it is safe to say that it is likely that many end users were hurt by Google not waiting the extra two days.