Live data from Hacker News

Google discloses another Windows security issue after deadline exceeded

code.google.com

41–50 of 152 posts

Re: Google discloses another Windows security issue after deadline exceeded

#41
post #33

Earlier quoted context omitted.

How is that a reasonable excuse? If they have so much money their operating system should be fixed faster, not slower, than other operating systems.

More money (or resources) = faster solutions is a pretty common fallacy. Often the size, scope and wealth of resources induces an increasingly slower response to such things.

How is it a fallacy? Because management is incompetent? If your budget goes from 1M to 10M even a child could show you how to spend 1M and throw the rest into a big fire or something. Maybe run two agile teams at 1M each.

Re: Google discloses another Windows security issue after deadline exceeded

#42
post #16

So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…

I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…

3 months is a long ass time to produce a patch.

Re: Google discloses another Windows security issue after deadline exceeded

#43

Earlier quoted context omitted.

I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…

3 months is a long ass time to produce a patch.

Even if we're talking about such a massive roll-out to millions of machines, with various versions of the OS running on various hardware? I don't know how easy or not the actual patch is to produce, but it's not out of the realm of possibilities that they did run into a compatibility issue that they wanted more time to sort out. Think of the outcry and damage to their business if they rolled out a patch that accidentally broke some installations.

Re: Google discloses another Windows security issue after deadline exceeded

#44
post #33

Earlier quoted context omitted.

More money (or resources) = faster solutions is a pretty common fallacy. Often the size, scope and wealth of resources induces an increasingly slower response to such things.

How is it a fallacy? Because management is incompetent? If your budget goes from 1M to 10M even a child could show you how to spend 1M and throw the rest into a big fire or something. Maybe run two agile teams at 1M each.

I honestly can't tell if you are attempting parody or being serious.

Re: Google discloses another Windows security issue after deadline exceeded

#45
post #16

So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…

Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…

I used to work on telephone switches. We had 31 million lines of code. I can't remember the entire details since it was over a decade ago, but I believe Bellcore required us to deploy fixes for 70% of all reported bugs within 30 days. We were a huge, fat-ass company with 5000 programmers working on the same project and managed this. 90 days is a lifetime to fix a security problem.

The point behind having a deadline before publicly disclosing is that if one person has discovered a security problem, then some other people probably have as well. It is fair enough to give vendors time before you make disclosure but if the vendor is moving too slowly -- for whatever reason -- you want to give the consumers a chance to implement their own security work around. Because if you don't they are vulnerable.

Giving Microsoft 90 days to fix an issue is fine. They can prioritize it anyway they want. If they think it is super urgent, they can almost certainly get a fix out. If they think it is not so urgent, then they don't have to make a fix -- but they know that the problem will be disclosed.

Nowhere in Google's documentation of this problem do I see a massive issue. Google gave MS 90 days. MS found a fix but there was another bug so they couldn't meet the window. Google released the information. Nowhere do I see MS requesting more time or any indication that anybody in the process thinks that anything went badly at all. It didn't meet the disclosure deadline. That's just the way it goes sometimes.

Re: Google discloses another Windows security issue after deadline exceeded

#46

Earlier quoted context omitted.

3 months is a long ass time to produce a patch.

Even if we're talking about such a massive roll-out to millions of machines, with various versions of the OS running on various hardware? I don't know how easy or not the actual patch is to produce, but it's not out of the realm of possibilities that they did run into a compatibility issue that they wanted more time to sort out. Think of the outcry and damage to their business if they rolled out a patch that accident…

Yes, even then. Imagine if the bug had been found by security researchers who believe in full disclosure. You think it's reasonable for Microsoft to allow dozens of rootkits and viruses to proliferate for more than three months, for botnets to grow to hundreds of millions in size? Microsoft's release process is broken.

Re: Google discloses another Windows security issue after deadline exceeded

#48
post #16

So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…

Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…

The Kaminsky bug was disclosed 30 days after it was announced, and by then, pretty much the entire internet had been patched. Google is being generous with 90 days, and Microsoft is being utterly incompetent.

Re: Google discloses another Windows security issue after deadline exceeded

#50
post #47

[deleted]

Microsoft seems to be making a habit of not taking these vulnerabilities seriously enough, as this is the second time in the past few weeks that this has happened.

3 months is more than enough time to fix an important vulnerability that is potentially being exploited in that time period and longer. The threat of shouting it to the world should be enough to make it a top priority.

Post reply on HN