Live data from Hacker News

Google discloses another Windows security issue after deadline exceeded

code.google.com

71–80 of 152 posts

Re: Google discloses another Windows security issue after deadline exceeded

#72
post #16

So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…

I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…

> others that Microsoft would just put off fixes forever if Google didn't do this.

People wouldn't think that if MS didn't have a long history of doing exactly that.

Re: Google discloses another Windows security issue after deadline exceeded

#75
post #67

Earlier quoted context omitted.

Thank the carriers for being jerks for that one. I know on the last time this article came up I took a hard line on them, but upon further reflection, it's not like they can just write a patch and have it out in a week. Heck, it takes months for point releases to go through acceptance testing at the carriers, and probably not insignificant amounts of cash. At least they're starting to own more of the ecosystem. I wou…

Carriers not rolling out updates a) doesn't waive Google's responsibility to roll out patches to their largest OS cohort and b) is really all Google's fault because they let the carriers get away with it and have never reigned them in even after years of incompetence on the carriers' part. It's not an excuse.

Why are you blaming Google, and not Samsung, HTC, LG? Aren't they the ones who produce software updates for their phones?

I really don't see how Google is stopping them from updating their handsets.

Re: Google discloses another Windows security issue after deadline exceeded

#76
post #40

Earlier quoted context omitted.

I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…

> [...] and discloses a zero-day. 90-day, you mean. It's only zero-day if they had zero days to come up with a solution. That's what "zero-day" means.

But that doesn't sound nearly as cool or media hype-able.

Re: Google discloses another Windows security issue after deadline exceeded

#77
post #19

In another news, google stop fixing security bugs which cover 60% of the current android users (4.3 or older). Not saying microsoft is right, but they just dropped windows xp support last year (that is >10 years of support). [1] http://arstechnica.com/security/2015/01/google-wont-fix-bug-...

I consider google with android to be a similar position to the linux kernel on my servers. I don't expect any of the kernel team to produce a patch for my 2.6.18 kernel I am running on a RHEL 5 system, I expect Red Hat to do that.

Why doesn't Samsung / LG / HTC manage Long Term support for Android versions, back port the patches and roll them out? Alternatively why don't they all pool together and manage an LTS version for customers.

It seems crazy that the company that has a relationship with the customer doesn't have to support the customer, and everyone instead blames google who wrote the code. The android vendors could back port, create alternative patches or simply make the device able to be updated to a more recent version.

Re: Google discloses another Windows security issue after deadline exceeded

#78
post #17

Earlier quoted context omitted.

You mean like Redhat?

RedHat runs on no where near as many devices as Windows does.

Red Hat and CentOS run on many servers, which arguably have the highest economic impact when they are exploited (or when a 'fix' leads to problems).

Re: Google discloses another Windows security issue after deadline exceeded

#79

Earlier quoted context omitted.

Even if we're talking about such a massive roll-out to millions of machines, with various versions of the OS running on various hardware? I don't know how easy or not the actual patch is to produce, but it's not out of the realm of possibilities that they did run into a compatibility issue that they wanted more time to sort out. Think of the outcry and damage to their business if they rolled out a patch that accident…

Yes, even then. Imagine if the bug had been found by security researchers who believe in full disclosure. You think it's reasonable for Microsoft to allow dozens of rootkits and viruses to proliferate for more than three months, for botnets to grow to hundreds of millions in size? Microsoft's release process is broken.

Sure, three months is a long time to fix an issue, but what does Microsoft have to gain by taking longer to fix an issue of this severity than it believes it needs to? If Microsoft released the fixes when they were going to, and Google then released the details of the issues and when they first reported them, Google could still make a stink about Microsoft's turn-around time on critical security bugs, and there wouldn't be any gap between global notification of the issues and a readily available fix for them.

Put another way, Google may have just notified the world of black-hat hackers of an issue they weren't otherwise aware of, an issue that demonstrably will not be patched for some time. If that is the case, then Google just recklessly endangered people's computers in the interest of raising awareness of Microsoft's poor turn around time on these issues. There is also the very real chance that this issue was already known by the black-hat community, in which case there isn't nearly as much lost by reporting here, but that's a gamble Google is making in order to make a point.

Re: Google discloses another Windows security issue after deadline exceeded

#80
post #71
post #2

Doubling the deadline to 180 days is probably reasonable IMO.

Whatever time frame Google would come up with Microsoft would still find a reason to delay past it and publicly cry out loud.

This is conjecture and frankly nonsense. If the time frame was 5 years, would MS really find a reason to delay and to publicly cry out loud? No. The only org being unreasonable is big G.
Post reply on HN