Live data from Hacker News

Google discloses another Windows security issue after deadline exceeded

code.google.com

81–90 of 152 posts

Re: Google discloses another Windows security issue after deadline exceeded

#81
post #67

Earlier quoted context omitted.

Carriers not rolling out updates a) doesn't waive Google's responsibility to roll out patches to their largest OS cohort and b) is really all Google's fault because they let the carriers get away with it and have never reigned them in even after years of incompetence on the carriers' part. It's not an excuse.

Why are you blaming Google, and not Samsung, HTC, LG? Aren't they the ones who produce software updates for their phones? I really don't see how Google is stopping them from updating their handsets.

See the beauty of the situation is that they are all at fault. However, only one company makes the core OS software these hardware manufacturers run on.

Perhaps if Google provided the update and the pressure could be put on the manufacturers to roll out the update to their paying customers...?

Re: Google discloses another Windows security issue after deadline exceeded

#82
post #69

Earlier quoted context omitted.

Thank the carriers for being jerks for that one. I know on the last time this article came up I took a hard line on them, but upon further reflection, it's not like they can just write a patch and have it out in a week. Heck, it takes months for point releases to go through acceptance testing at the carriers, and probably not insignificant amounts of cash. At least they're starting to own more of the ecosystem. I wou…

Seriously, if you depend on heavily unreliable third parties to deploy critical patches to your product, your release mechanism is broken.

It's not Google's product any more than it's the Linux Foundation's product. Both are just organizations with software built into somebody else's product. Nexus phones purchased from Google are Google's product.

Separately, complaining that the vulnerabilities are unpatched in Android is a rubbish argument. They are fixed in the latest release.

Re: Google discloses another Windows security issue after deadline exceeded

#83

Earlier quoted context omitted.

I honestly can't tell if you are attempting parody or being serious.

I'm perfectly serious. Perhaps I misread the comment I am replying to. Flat out 'more money to fix the problem' should never make things slower. Worst case you can ignore the money. Even if it's too late to add people for project X, you should be able to use the money for something to improve productivity on project X+3. If I'm wrong about something please explain.

Well if you were being serious it sounds like you really need to read this book https://en.wikipedia.org/wiki/Mythical_man_month

Re: Google discloses another Windows security issue after deadline exceeded

#84
post #81

Earlier quoted context omitted.

Why are you blaming Google, and not Samsung, HTC, LG? Aren't they the ones who produce software updates for their phones? I really don't see how Google is stopping them from updating their handsets.

See the beauty of the situation is that they are all at fault . However, only one company makes the core OS software these hardware manufacturers run on. Perhaps if Google provided the update and the pressure could be put on the manufacturers to roll out the update to their paying customers...?

[deleted]

Re: Google discloses another Windows security issue after deadline exceeded

#85

Earlier quoted context omitted.

Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…

I used to work on telephone switches. We had 31 million lines of code. I can't remember the entire details since it was over a decade ago, but I believe Bellcore required us to deploy fixes for 70% of all reported bugs within 30 days. We were a huge, fat-ass company with 5000 programmers working on the same project and managed this. 90 days is a lifetime to fix a security problem. The point behind having a deadline b…

You had one system on, at most, a few thousand machines, and those machines were tailored to the software.

The still-supported Windows versions, by contrast, are 50+ million lines of code EACH installed on hundreds of millions of machines EACH.

Your telephone switch analogy is just not even in the same solar system as what Microsoft is dealing with.

I'm not saying 90 days is necessarily too little time, I'm just saying your reasoning is totally flawed.

Re: Google discloses another Windows security issue after deadline exceeded

#86

Earlier quoted context omitted.

I'm perfectly serious. Perhaps I misread the comment I am replying to. Flat out 'more money to fix the problem' should never make things slower. Worst case you can ignore the money. Even if it's too late to add people for project X, you should be able to use the money for something to improve productivity on project X+3. If I'm wrong about something please explain.

Well if you were being serious it sounds like you really need to read this book https://en.wikipedia.org/wiki/Mythical_man_month

I am aware of that book. I considered referencing it in my earlier comments.

I don't know how I can my my point more clear.

If a manager shoves in more workers and slows things down, they are failing at their job.

They are worse than useless.

Because someone useless would take the extra budget, not hire anyone, and not slow down the work. Perhaps they would waste it in vegas.

I am saying nothing that contradicts that book. Just two simple points:

1. More resources only slow down a project when they are misused. They are never inherently bad.

2. It's not even hard to speed up work on security bugs, because each bugfix is a different project and can have its own dedicated team.

Please actually point out something I said that was wrong, instead of making vague references.

Re: Google discloses another Windows security issue after deadline exceeded

#87
post #19

In another news, google stop fixing security bugs which cover 60% of the current android users (4.3 or older). Not saying microsoft is right, but they just dropped windows xp support last year (that is >10 years of support). [1] http://arstechnica.com/security/2015/01/google-wont-fix-bug-...

Thank the carriers for being jerks for that one. I know on the last time this article came up I took a hard line on them, but upon further reflection, it's not like they can just write a patch and have it out in a week. Heck, it takes months for point releases to go through acceptance testing at the carriers, and probably not insignificant amounts of cash. At least they're starting to own more of the ecosystem. I wou…

Maybe google should stop breaking calling functionality, then the rollouts would be faster? (there was a HN thread on that)

Re: Google discloses another Windows security issue after deadline exceeded

#88

Earlier quoted context omitted.

Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…

The Kaminsky bug was disclosed 30 days after it was announced, and by then, pretty much the entire internet had been patched. Google is being generous with 90 days, and Microsoft is being utterly incompetent.

This is trolling.

Re: Google discloses another Windows security issue after deadline exceeded

#89
post #16

So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…

I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…

"Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this."

... and yet others think that both of those statements are true :)

Re: Google discloses another Windows security issue after deadline exceeded

#90
What I would like for Google to do is instead of publishing the details of the bug, after the deadline they would publish vague summary of vulnerability, so people would know it exists, but not quite able to exploit it right away. That would both inform people about danger and put pressure on MS, but without puting so much risk onto systems.
Post reply on HN