Live data from Hacker News

Google discloses another Windows security issue after deadline exceeded

code.google.com

91–100 of 152 posts

Re: Google discloses another Windows security issue after deadline exceeded

#91

Earlier quoted context omitted.

I really dislike your description because while it is technically true it heavily implies that they decided on dates on a per-bug case, when they decided on a flat 90 days.

Then again, 90 days contains 2.5 of their fix cycles. If the vulnerability really is serious, and they can't fix it in that time line, they should exit the business.

Google roughly supports one version of their product on 2 OSs.

Microsoft supports all versions of all their products for 10years+ after release, integrated with a combination of all other products they have shipped in that same time-frame.

Needless to say, Microsoft needs to do more QA on their bug-fixes before they can safely release it to all customers without the risk of causing new issues.

It's easy for Google to be big in the mouth when they don't bother to support their existing customers properly.

Speaking of being big in the mouth: Did you know that Google isn't back-porting security fixes to older versions of Android either (only 2 last minor releases)? I guess supporting more than 40% of your user base is too much work.

Guess which side my sympathy is leaning to in this case.

Re: Google discloses another Windows security issue after deadline exceeded

#92
post #55
post #51

Earlier quoted context omitted.

For one, IBM does, and has for some time. Others in the thread note that Red Hat and others do. Apple does iOs, which runs on far more devices than anything else mentiond in this thread.

The total number of iPhones is not really relevant to the discussion, the number of iPhone models is. Testing a fix on an enumerable number of iPhone models in the wild (lets say iPhone 4, 4s, 5, 5c, 5s, 6, 6+) is nowhere near the complexity of testing Windows against the variety of devices that it would need to be validated against.

Few of these issues are in driver level code, so the variety of devices doesn't play into that.

The most recent one is somewhere in the User Profile Service, which is about as far away from the hardware as possible. Shellshock didn't need testing on every possible hardware combination it runs on either, did it?

Re: Google discloses another Windows security issue after deadline exceeded

#93
post #16

So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…

Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…

Then perhaps MS ought to shorten its bug fixing period. Three months is quite a long time to find a bug, fix it, and run extensive tests. What good is a fixed time period if you're willing to extend it just because one company can't pull their shit together?

As for the Kaminsky DNS bug, it was leaked more than a solid week ahead of the time he intended to release it. Sure, patches had already been released, but how about if other companies had said, "We need a full month to test this patch prior to rolling it into production."? They would have been putting themselves at risk. Mind you, this bug was simply an extension of an earlier flaw - too small a range of transaction IDs, and some DNS projects (`djbdns` comes to mind) had already mitigated it (ostensibly fixing the root cause as opposed to the symptom). Had the other vendors mitigated that flaw in a similar fashion (they had almost a decade since djb pointed it out), they would not have been vulnerable. However, there was no looming deadline, so few of them even noticed until an actual attack was possible (as opposed to fixing issues as they come up).

What happens if someone leaks the bug early? Or if a malicious adversary discovers the bug at the same time? The whole idea of these deadlines is to force security bug fixes to be released ASAP, taking precedence int time and importance over all else.

Deadlines can't be adjusted just so MS can screw around for longer doing nothing. If it's really taking them more than three months to fix a bug and release patches, perhaps they need to rethink their priorities and dedicate more resources to the task. And perhaps we need to seriously reconsider our dependence on their products.

Re: Google discloses another Windows security issue after deadline exceeded

#94
The first thing Microsoft does when they learn about a zero-day is to hand it to the NSA. Microsoft doesn't get to fix it until the NSA tells Microsoft they're done exploiting it. Google may be pissed about this. They've been pissed off before about NSA's shenanigans.

Re: Google discloses another Windows security issue after deadline exceeded

#95
post #19

In another news, google stop fixing security bugs which cover 60% of the current android users (4.3 or older). Not saying microsoft is right, but they just dropped windows xp support last year (that is >10 years of support). [1] http://arstechnica.com/security/2015/01/google-wont-fix-bug-...

I can't fault Google for that. They've released subsequent versions of Android that has fixed the vuln in WebViews. Also, they took a major step in Android L by removing the WebView from the Android Framework and distributing it via the Play Store, thereby, enabling them to push security updates to all newer devices without the devices themselves having to update to a newer version of Android to get security fixes.

Microsoft also released subsequent versions of Windows, but they still keep updating old ones.

I don't understand why Google hasn't build an update process for Android in the first place. Everyone knows the OEMs won't update if they don't have to.

Re: Google discloses another Windows security issue after deadline exceeded

#96
post #81

Earlier quoted context omitted.

Why are you blaming Google, and not Samsung, HTC, LG? Aren't they the ones who produce software updates for their phones? I really don't see how Google is stopping them from updating their handsets.

See the beauty of the situation is that they are all at fault . However, only one company makes the core OS software these hardware manufacturers run on. Perhaps if Google provided the update and the pressure could be put on the manufacturers to roll out the update to their paying customers...?

No. They are not all at fault. The only one's responsible for updating their phones are the companies supplying the phones. There is nothing stopping Samsung, Sony, HTC, LG from creating and submitting a patch to AOSP and they are the ones who actually have a responsibility to their customers to do so. There is also very little stopping them from updating their phones to 4.4.

> is really all Google's fault because they let the carriers get away with it and have never reigned them in even after years of incompetence on the carriers' part.

You are again blaming Google for the carriers policy of updating phones not even belonging to Google. Do you really think Google is involved with a carriers agreement to carry Samsung phones?

Last time I checked, Nexus phone's can also be updated without the assistance of the carrier.

Re: Google discloses another Windows security issue after deadline exceeded

#97
post #49

Earlier quoted context omitted.

Since Redhat is a distribution of Linux, how many Android installs are there?

? Nobody is running redhat on their android phone.

That's correct. They run Linux, like Redhat.

Re: Google discloses another Windows security issue after deadline exceeded

#98

Earlier quoted context omitted.

and then you have tons of device who cannot upgrade to 4.4

Its the manufacturer's (HTC, Samsung ..) fault that they cannot be updated.

And Google, because they have not implemented a default update system for the android core. Google only updates Apps.

Re: Google discloses another Windows security issue after deadline exceeded

#99
post #32

Earlier quoted context omitted.

Android is "fully open source" except that Google writes 99.999% of the code in secret. Rarely they will accept a pull request but there is zero transparency into that process.

That sucks but it's not relevant to google having released a new version and carriers ignoring it.

Why does Google still rely on the carries, even though they know for years, that they don't have interest in updates. They could easily implement an update mechanism for the core of Android, like they do for App-Updates as well.

When i buy a Laptop from HP, Dell, Lenovo or any other OEM, i still get Windows updates (even if i don't upgrade to the latest Windows version). I would really like to know why it is not possible for Google to implement such an update system? Blaming carriers is easier i guess.

Re: Google discloses another Windows security issue after deadline exceeded

#100

Earlier quoted context omitted.

That sucks but it's not relevant to google having released a new version and carriers ignoring it.

Why does Google still rely on the carries, even though they know for years, that they don't have interest in updates. They could easily implement an update mechanism for the core of Android, like they do for App-Updates as well. When i buy a Laptop from HP, Dell, Lenovo or any other OEM, i still get Windows updates (even if i don't upgrade to the latest Windows version). I would really like to know why it is not poss…

That's exactly what they are doing, although perhaps for two-fold reasons. More recent versions of Android move more and more core stuff into the Play services. This enables Google to push updates to core services like normal app updates. It also ensures that a lot of core APIs are covered by services only available on phones licensed with Google.
Post reply on HN