Live data from Hacker News

Google discloses another Windows security issue after deadline exceeded

code.google.com

131–140 of 152 posts

Re: Google discloses another Windows security issue after deadline exceeded

#131
post #32

Earlier quoted context omitted.

Android is "fully open source" except that Google writes 99.999% of the code in secret. Rarely they will accept a pull request but there is zero transparency into that process.

When I go to their public code review app [0], it looks pretty active. The last 100 changes listed there were modified in the last 24 hours! Which parts are they coding in secret? (Honestly, I don't know, please help me understand) [0]: https://android-review.googlesource.com/#/q/status:open

One thing to note, more and more of what constitutes the android user experience is being pulled into the Google Play Services app which is closed source. A big part of the reason why is that it gives Google a better negotiation tool to use with carriers as they have to license the use of the Google Play platform and that isn't really optional in modern Android right now. AOSP has been left behind not in support but in more and more features of "Android" being closed source. Another huge benefit is that tons of bug fixes that would have required coaxing carriers into supporting a software update on the phones can now be applied just by patching Google Play Services and rolling it out as an app update.

Re: Google discloses another Windows security issue after deadline exceeded

#132

What I would like for Google to do is instead of publishing the details of the bug, after the deadline they would publish vague summary of vulnerability, so people would know it exists, but not quite able to exploit it right away. That would both inform people about danger and put pressure on MS, but without puting so much risk onto systems.

That is not providing information about how to protect against the vulnerability regardless of a patch from Microsoft. Full disclosure is the only way to go.

Re: Google discloses another Windows security issue after deadline exceeded

#133
post #16

So there are 3 issues [1] against OS X, released a while ago, and one against Microsoft. Why the HN focus on the Windows bugs? At least Microsoft is communicating with Google, and have patches planned, just not on the exact timeline of the arbitrary 90 day deadline. Is there something about the OS X ones that doesn't warrant the same exposure/discussion? [1] https://code.google.com/p/google-security-research/issues/l…

Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…

Ya, my comment was too brief. I was mostly reacting to the HN posters that basically were saying "Microsoft evil" by gently pointing out that other companies are leaving bugs in for longer than Microsoft. For example, someone posted "Other companies fix such bugs in days." Well, there are counterexamples, aren't there (OS X at the moment).

I think what Microsoft is doing is really hard. I don't have insight into their process, having never worked there. So yes, we can speculate that they could do things much faster. But can they? I find it rather tasteless to just assume so with no evidence and to then go on and call them names. I dunno, maybe they are falling flat on their faces internally, or maybe the team is performing heroics at the cost of personal lives, or maybe it is just business as usual.

But, it was also an honest question. Maybe there is evidence out there that Microsoft is just failing, and I haven't seen it or my reading comprehension failed me and I saw it but didn't register it.

But mostly, I am tired of the hurl accusations and drag people&companies through the mud meme that happens here, and this seemed to be more of the same (again, open to evidence, not claims, to the contrary).

Re: Google discloses another Windows security issue after deadline exceeded

#134

Earlier quoted context omitted.

Everybody is saying that 90 days is too much, even at MS' scale. So, taking into account that everybody seems to know very well what MS has to support, what is a good number of days to finish all the work that needs to be done?

90 days seems just fine. What they need to do is give greater importance to bugs and apply more resources accordingly. When it actually affects them, they aren't hesitant to do whatever the hell it takes, with no regards as to the consequences for others, with zero warning at all, as was shown during the whole fiasco when they effectively took down NoIP's services. Meanwhile, when Google holds them to a perfectly rea…

> If they need to break some third-party application in fixing a security vulnerability, that's okay. Because that application can also be fixed by its developer, and security needs come ahead of an app here or an app there.

That is exactly the opposite of what Microsoft's customers think. If Microsoft began taking this attitude, there would be mass outrage. And maybe rightfully so: for countless applications in the Windows world, the developers are no longer around or ask for money to update the software. People are more likely to simply not update or roll back the update after they get it.

> Besides, it isn't as if users of Microsoft's products are not used to the concept of having stuff break all the time anyways.

They actually aren't. It certainly happens, but it's very rare that a Windows update (or even upgrade) breaks anything.

Re: Google discloses another Windows security issue after deadline exceeded

#135
post #49

Earlier quoted context omitted.

RedHat runs on no where near as many devices as Windows does.

Since Redhat is a distribution of Linux, how many Android installs are there?

Do you honestly feel like that is anything but disingenuous?

Re: Google discloses another Windows security issue after deadline exceeded

#136
post #4

Earlier quoted context omitted.

This apparently _does_ take that long, but should absolutely not.

Either Google is sending Microsoft bug reports like rapid-fire, and Microsoft has already fixed dozens of them that we haven't found out about - or for some strange reason, Microsoft didn't fix the only two bugs Google reported in the last 90 day period. If that's the case, then either Microsoft forgot about them, or they carefully orchestrated a PR scandal against Google (wouldn't be the first time - like the time t…

There are other bugs not reported by Google that Microsoft has to investigate and resolve as well. I doubt Google is the primary channel of security bug reports.

Re: Google discloses another Windows security issue after deadline exceeded

#137
post #71
post #2

Doubling the deadline to 180 days is probably reasonable IMO.

Whatever time frame Google would come up with Microsoft would still find a reason to delay past it and publicly cry out loud.

My understanding was that Microsoft had a specified timeline. Do you have reason to believe it's derived from Google's timeline?

If Microsoft says "100 days", saying "okay" instead of " no, 90" gives a timeline 100 days, not 101.

Re: Google discloses another Windows security issue after deadline exceeded

#138
post #33

Earlier quoted context omitted.

More money (or resources) = faster solutions is a pretty common fallacy. Often the size, scope and wealth of resources induces an increasingly slower response to such things.

How is it a fallacy? Because management is incompetent? If your budget goes from 1M to 10M even a child could show you how to spend 1M and throw the rest into a big fire or something. Maybe run two agile teams at 1M each.

Do people not read The Mythical Man Month anymore?

Re: Google discloses another Windows security issue after deadline exceeded

#139

Earlier quoted context omitted.

Other companies do not develop enterprise operating systems.

How is that a reasonable excuse? If they have so much money their operating system should be fixed faster, not slower, than other operating systems.

More resources should make the number of fixes possible per year greater, but it may not substantially reduce the time from notice to fix any single issue (and may, because of organizational overhead involved, sometimes increase the time for particular fixes over an organization with fewer total resources.)

Maintaining code is not a trivially parallelizable function.

Re: Google discloses another Windows security issue after deadline exceeded

#140

Earlier quoted context omitted.

I am aware of that book. I considered referencing it in my earlier comments. I don't know how I can my my point more clear. If a manager shoves in more workers and slows things down, they are failing at their job. They are worse than useless. Because someone useless would take the extra budget, not hire anyone, and not slow down the work. Perhaps they would waste it in vegas. I am saying nothing that contradicts that…

My point wasn't that more money itself induces potential slowness, but added infrastructure & scope that surround it (not necessarily even in the same department) often can . Ignoring more money is pretty unlikely to be an option as a whole, and inefficiencies generally cascade down to some extent.

Other departments matter in some ways, but bugfixing can be self-contained and mostly avoid slowdowns.

But even more important is that these outside slowdown effects are pretty minor. If this was software development then you might have no recourse and you'd be somewhat slower overall. But this is handling many many independent projects. You can hire more teams without having man-month problems, and then handle bugs efficiently.

>Ignoring more money is pretty unlikely to be an option as a whole, and inefficiencies generally cascade down to some extent.

Again, I blame management. A nice sturdy cardboard box as a manager is impervious to social effects from other departments, and it can soak up extra cash too.

I expect anyone being paid to manage to do a better job than a box. Not to go along with the flow uncritically.

Post reply on HN