Live data from Hacker News

Google discloses another Windows security issue after deadline exceeded

code.google.com

111–120 of 152 posts

Re: Google discloses another Windows security issue after deadline exceeded

#111

Earlier quoted context omitted.

Its the manufacturer's (HTC, Samsung ..) fault that they cannot be updated.

And Google, because they have not implemented a default update system for the android core. Google only updates Apps.

I'm honestly not sure what you're talking about. Android does have a system update mechanism. You go to settings -> About phone -> System updates.

If manufacturers / carriers change that to check for updates on their own servers, rather than google's - which they can do since Android is open-source, and so they all do - then that's how the system update mechanism will work.

I don't follow what you're suggesting google could do about that, apart from moving more and more OS functions out of the core OS and into google play services. Which is exactly what they've been doing.

Re: Google discloses another Windows security issue after deadline exceeded

#112
post #67

Earlier quoted context omitted.

Carriers not rolling out updates a) doesn't waive Google's responsibility to roll out patches to their largest OS cohort and b) is really all Google's fault because they let the carriers get away with it and have never reigned them in even after years of incompetence on the carriers' part. It's not an excuse.

Why are you blaming Google, and not Samsung, HTC, LG? Aren't they the ones who produce software updates for their phones? I really don't see how Google is stopping them from updating their handsets.

Look into the "Open" Handset Alliance (especially findings from the SkyHook lawsuit) to see how much control Google actually wields over manufacturers. Google controls what software and services are bundled with handsets (see SkyHook). Google prevents manufacturers from creating competing Android devices using forks of Android (see Acer; that's why the quotes around "Open"). If it cared at all, Google could easily require manufacturers to provide regular updates.

Re: Google discloses another Windows security issue after deadline exceeded

#113
post #111

Earlier quoted context omitted.

And Google, because they have not implemented a default update system for the android core. Google only updates Apps.

I'm honestly not sure what you're talking about. Android does have a system update mechanism. You go to settings -> About phone -> System updates. If manufacturers / carriers change that to check for updates on their own servers, rather than google's - which they can do since Android is open-source, and so they all do - then that's how the system update mechanism will work. I don't follow what you're suggesting googl…

Starting with Android 5, WebCore is part of the Google Services and is therefore updated silently through the Play Store.

But I obviously do not approve what the OEMs are doing.

Re: Google discloses another Windows security issue after deadline exceeded

#114
post #40

Earlier quoted context omitted.

I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…

> [...] and discloses a zero-day. 90-day, you mean. It's only zero-day if they had zero days to come up with a solution. That's what "zero-day" means.

[deleted]

Re: Google discloses another Windows security issue after deadline exceeded

#115
post #40

Earlier quoted context omitted.

I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…

> [...] and discloses a zero-day. 90-day, you mean. It's only zero-day if they had zero days to come up with a solution. That's what "zero-day" means.

Actually, 0-day refers to the time since public disclosure.

Re: Google discloses another Windows security issue after deadline exceeded

#116
post #114
post #40

Earlier quoted context omitted.

> [...] and discloses a zero-day. 90-day, you mean. It's only zero-day if they had zero days to come up with a solution. That's what "zero-day" means.

[deleted]

http://en.wikipedia.org/wiki/Zero-day_attack

> It is called a "zero-day" because the programmer has had zero days to fix the flaw

Re: Google discloses another Windows security issue after deadline exceeded

#117
post #52
post #47

[deleted]

> That's a pretty high horse Google is on. Google is happy to receive security bug reports from any comers.

Yes, and then they ask people to sit on them longer when it's their ass on the line, something they won't do for Microsoft: https://news.ycombinator.com/item?id=8873898

Re: Google discloses another Windows security issue after deadline exceeded

#118
post #115
post #40

Earlier quoted context omitted.

> [...] and discloses a zero-day. 90-day, you mean. It's only zero-day if they had zero days to come up with a solution. That's what "zero-day" means.

Actually, 0-day refers to the time since public disclosure.

If that would be the case then we would have another term for the thing I just described, because that's the worst case scenario.

Anyhow, the Wikipedia article disagrees with you, too. Got any sources for your definition?

Re: Google discloses another Windows security issue after deadline exceeded

#119

I can understand both points of view with the disclosure of the security issue. A while ago I discovered some security issues with Adobe ColdFusion and Railo. I wish I had put a deadline on disclosing the Adobe ColdFusion issues, as they dragged their feet so much (with admitting it was an issue and progressing with a fix) that at points I felt like throwing in the towel. Regrettably, instead of lighting a fire under…

Did Railo fix the bug?

Re: Google discloses another Windows security issue after deadline exceeded

#120

I can understand both points of view with the disclosure of the security issue. A while ago I discovered some security issues with Adobe ColdFusion and Railo. I wish I had put a deadline on disclosing the Adobe ColdFusion issues, as they dragged their feet so much (with admitting it was an issue and progressing with a fix) that at points I felt like throwing in the towel. Regrettably, instead of lighting a fire under…

Did Railo fix the bug?

They fixed one of the issues I reported. I don't believe I had official confirmation of the other issue I had with Railo being resolved. I probably should try it out again on their latest version, but I don't use Railo and haven't found myself with much fondness for ColdFusion either.

But I should probably pull my thumb out and check ;)

Post reply on HN