Doubling the deadline to 180 days is probably reasonable IMO.
Google discloses another Windows security issue after deadline exceeded
71–80 of 152 posts
Re: Google discloses another Windows security issue after deadline exceeded
#72So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…
I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…
People wouldn't think that if MS didn't have a long history of doing exactly that.
Re: Google discloses another Windows security issue after deadline exceeded
#73Dick move by Google.
Re: Google discloses another Windows security issue after deadline exceeded
#74Re: Google discloses another Windows security issue after deadline exceeded
#75Earlier quoted context omitted.
Thank the carriers for being jerks for that one. I know on the last time this article came up I took a hard line on them, but upon further reflection, it's not like they can just write a patch and have it out in a week. Heck, it takes months for point releases to go through acceptance testing at the carriers, and probably not insignificant amounts of cash. At least they're starting to own more of the ecosystem. I wou…
Carriers not rolling out updates a) doesn't waive Google's responsibility to roll out patches to their largest OS cohort and b) is really all Google's fault because they let the carriers get away with it and have never reigned them in even after years of incompetence on the carriers' part. It's not an excuse.
I really don't see how Google is stopping them from updating their handsets.
Re: Google discloses another Windows security issue after deadline exceeded
#76Earlier quoted context omitted.
I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…
> [...] and discloses a zero-day. 90-day, you mean. It's only zero-day if they had zero days to come up with a solution. That's what "zero-day" means.
Re: Google discloses another Windows security issue after deadline exceeded
#77In another news, google stop fixing security bugs which cover 60% of the current android users (4.3 or older). Not saying microsoft is right, but they just dropped windows xp support last year (that is >10 years of support). [1] http://arstechnica.com/security/2015/01/google-wont-fix-bug-...
Why doesn't Samsung / LG / HTC manage Long Term support for Android versions, back port the patches and roll them out? Alternatively why don't they all pool together and manage an LTS version for customers.
It seems crazy that the company that has a relationship with the customer doesn't have to support the customer, and everyone instead blames google who wrote the code. The android vendors could back port, create alternative patches or simply make the device able to be updated to a more recent version.
Re: Google discloses another Windows security issue after deadline exceeded
#78Re: Google discloses another Windows security issue after deadline exceeded
#79Earlier quoted context omitted.
Even if we're talking about such a massive roll-out to millions of machines, with various versions of the OS running on various hardware? I don't know how easy or not the actual patch is to produce, but it's not out of the realm of possibilities that they did run into a compatibility issue that they wanted more time to sort out. Think of the outcry and damage to their business if they rolled out a patch that accident…
Yes, even then. Imagine if the bug had been found by security researchers who believe in full disclosure. You think it's reasonable for Microsoft to allow dozens of rootkits and viruses to proliferate for more than three months, for botnets to grow to hundreds of millions in size? Microsoft's release process is broken.
Put another way, Google may have just notified the world of black-hat hackers of an issue they weren't otherwise aware of, an issue that demonstrably will not be patched for some time. If that is the case, then Google just recklessly endangered people's computers in the interest of raising awareness of Microsoft's poor turn around time on these issues. There is also the very real chance that this issue was already known by the black-hat community, in which case there isn't nearly as much lost by reporting here, but that's a gamble Google is making in order to make a point.
Re: Google discloses another Windows security issue after deadline exceeded
#80Doubling the deadline to 180 days is probably reasonable IMO.
Whatever time frame Google would come up with Microsoft would still find a reason to delay past it and publicly cry out loud.