Earlier quoted context omitted.
How is that a reasonable excuse? If they have so much money their operating system should be fixed faster, not slower, than other operating systems.
More money (or resources) = faster solutions is a pretty common fallacy. Often the size, scope and wealth of resources induces an increasingly slower response to such things.
Google discloses another Windows security issue after deadline exceeded
41–50 of 152 posts
Re: Google discloses another Windows security issue after deadline exceeded
#42So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…
I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…
Re: Google discloses another Windows security issue after deadline exceeded
#43Earlier quoted context omitted.
I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…
3 months is a long ass time to produce a patch.
Re: Google discloses another Windows security issue after deadline exceeded
#44Earlier quoted context omitted.
More money (or resources) = faster solutions is a pretty common fallacy. Often the size, scope and wealth of resources induces an increasingly slower response to such things.
How is it a fallacy? Because management is incompetent? If your budget goes from 1M to 10M even a child could show you how to spend 1M and throw the rest into a big fire or something. Maybe run two agile teams at 1M each.
Re: Google discloses another Windows security issue after deadline exceeded
#45So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…
Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…
The point behind having a deadline before publicly disclosing is that if one person has discovered a security problem, then some other people probably have as well. It is fair enough to give vendors time before you make disclosure but if the vendor is moving too slowly -- for whatever reason -- you want to give the consumers a chance to implement their own security work around. Because if you don't they are vulnerable.
Giving Microsoft 90 days to fix an issue is fine. They can prioritize it anyway they want. If they think it is super urgent, they can almost certainly get a fix out. If they think it is not so urgent, then they don't have to make a fix -- but they know that the problem will be disclosed.
Nowhere in Google's documentation of this problem do I see a massive issue. Google gave MS 90 days. MS found a fix but there was another bug so they couldn't meet the window. Google released the information. Nowhere do I see MS requesting more time or any indication that anybody in the process thinks that anything went badly at all. It didn't meet the disclosure deadline. That's just the way it goes sometimes.
Re: Google discloses another Windows security issue after deadline exceeded
#46Earlier quoted context omitted.
3 months is a long ass time to produce a patch.
Even if we're talking about such a massive roll-out to millions of machines, with various versions of the OS running on various hardware? I don't know how easy or not the actual patch is to produce, but it's not out of the realm of possibilities that they did run into a compatibility issue that they wanted more time to sort out. Think of the outcry and damage to their business if they rolled out a patch that accident…
Re: Google discloses another Windows security issue after deadline exceeded
#47Re: Google discloses another Windows security issue after deadline exceeded
#48So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…
Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…
Re: Google discloses another Windows security issue after deadline exceeded
#49Re: Google discloses another Windows security issue after deadline exceeded
#50[deleted]
3 months is more than enough time to fix an important vulnerability that is potentially being exploited in that time period and longer. The threat of shouting it to the world should be enough to make it a top priority.