Google discloses another Windows security issue after deadline exceeded
121–130 of 152 posts
Re: Google discloses another Windows security issue after deadline exceeded
#122Earlier quoted context omitted.
I'm honestly not sure what you're talking about. Android does have a system update mechanism. You go to settings -> About phone -> System updates. If manufacturers / carriers change that to check for updates on their own servers, rather than google's - which they can do since Android is open-source, and so they all do - then that's how the system update mechanism will work. I don't follow what you're suggesting googl…
Starting with Android 5, WebCore is part of the Google Services and is therefore updated silently through the Play Store. But I obviously do not approve what the OEMs are doing.
Aka, no longer part of Android. The millions of users without Google Play will have an even less functional OS than they used to, all in the name of greater control by Google.
Re: Google discloses another Windows security issue after deadline exceeded
#123Earlier quoted context omitted.
Well if you were being serious it sounds like you really need to read this book https://en.wikipedia.org/wiki/Mythical_man_month
I am aware of that book. I considered referencing it in my earlier comments. I don't know how I can my my point more clear. If a manager shoves in more workers and slows things down, they are failing at their job. They are worse than useless. Because someone useless would take the extra budget, not hire anyone, and not slow down the work. Perhaps they would waste it in vegas. I am saying nothing that contradicts that…
Ignoring more money is pretty unlikely to be an option as a whole, and inefficiencies generally cascade down to some extent.
Re: Google discloses another Windows security issue after deadline exceeded
#124Earlier quoted context omitted.
RedHat runs on no where near as many devices as Windows does.
Since Redhat is a distribution of Linux, how many Android installs are there?
RedHat is POSIX compliant so why don't you just lump in every POSIX compliant device ever made? /s
Re: Google discloses another Windows security issue after deadline exceeded
#125Earlier quoted context omitted.
> others that Microsoft would just put off fixes forever if Google didn't do this. People wouldn't think that if MS didn't have a long history of doing exactly that.
What security fixes has Microsoft put off forever?
http://blog.washingtonpost.com/securityfix/2007/01/critical_...
Re: Google discloses another Windows security issue after deadline exceeded
#126Earlier quoted context omitted.
Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…
In my experience, the only kind of PHP (or any) app where you can change just one line and walk away is a well written one. It's the poorly written ones where you have to change dozens or hundreds of lines, and run away screaming. But point taken.
Say I patch a security flaw in a webapp I run. If I screw up the phone starts ringing, and then I undo the patch I made and think some more about it. Meanwhile no one has any clue about the flaw.
If I have to deploy a release to fixed endpoints, I have to think about what could possibly go wrong on every device out there running my software. Plus, if I didn't fix the problem completely, the nature of distributing the patch has now told the rev-eng community exactly where the problem was.
Google once pushed out a version of their browser that stopped the entire browser from working when their sync server went offline (for anyone using sync in their browser). Microsoft does not want even 1% of their users to suddenly be unable to use their computers.
Re: Google discloses another Windows security issue after deadline exceeded
#127Earlier quoted context omitted.
> That's a pretty high horse Google is on. Google is happy to receive security bug reports from any comers.
Yes, and then they ask people to sit on them longer when it's their ass on the line, something they won't do for Microsoft: https://news.ycombinator.com/item?id=8873898
The github repo readme says "A few days ago, Google has introduced a new version of ReCaptcha" which seems to me like it was a 0-day disclosure. If that is the case why would it be hypocritical of Google to ask for the repo to come down so they have some time to fix the issue?
Re: Google discloses another Windows security issue after deadline exceeded
#128Earlier quoted context omitted.
Why are you blaming Google, and not Samsung, HTC, LG? Aren't they the ones who produce software updates for their phones? I really don't see how Google is stopping them from updating their handsets.
See the beauty of the situation is that they are all at fault . However, only one company makes the core OS software these hardware manufacturers run on. Perhaps if Google provided the update and the pressure could be put on the manufacturers to roll out the update to their paying customers...?
Security updates aren't sexy and don't get applied unless they include shiny things along with them.
Re: Google discloses another Windows security issue after deadline exceeded
#129So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…
Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…
Re: Google discloses another Windows security issue after deadline exceeded
#130Earlier quoted context omitted.
I can't fault Google for that. They've released subsequent versions of Android that has fixed the vuln in WebViews. Also, they took a major step in Android L by removing the WebView from the Android Framework and distributing it via the Play Store, thereby, enabling them to push security updates to all newer devices without the devices themselves having to update to a newer version of Android to get security fixes.
Microsoft also released subsequent versions of Windows, but they still keep updating old ones. I don't understand why Google hasn't build an update process for Android in the first place. Everyone knows the OEMs won't update if they don't have to.
So now they're having to lock the gate after the horse has bolted.
But if you want to compare it with Windows, the early versions of Windows didn't have an automated update process in place either.