Earlier quoted context omitted.
What security fixes has Microsoft put off forever?
They are obviously much better about this now but back when IE was the browser du jour there were tons of bugs that took ages for them to fix. http://blog.washingtonpost.com/securityfix/2007/01/critical_...
Google discloses another Windows security issue after deadline exceeded
141–150 of 152 posts
Re: Google discloses another Windows security issue after deadline exceeded
#142Earlier quoted context omitted.
See the beauty of the situation is that they are all at fault . However, only one company makes the core OS software these hardware manufacturers run on. Perhaps if Google provided the update and the pressure could be put on the manufacturers to roll out the update to their paying customers...?
That assumes that you can make enough consumers with these (relatively) older devices care loud enough for any "pressure" to be applied to the manufacturers. Security updates aren't sexy and don't get applied unless they include shiny things along with them.
Releasing the update gives the customer power to press for pushing their manufacturers.
The whole model where carriers or manufacturers can send updates is ridiculous. Carriers update baseband. Manufacturers should defer to google for Core OS updates and Google Play. The fact that they're even involved is simply a recipe for disappointment.
It's bad for everyone because compromised machines simply reward and embolden the criminals which will eventually increase the harm to everyone who ins't a criminal.
Re: Google discloses another Windows security issue after deadline exceeded
#143The first thing Microsoft does when they learn about a zero-day is to hand it to the NSA. Microsoft doesn't get to fix it until the NSA tells Microsoft they're done exploiting it. Google may be pissed about this. They've been pissed off before about NSA's shenanigans.
In any case, I think both Microsoft and Google would be high value targets for all sorts of infiltration by the NSA, whether it's sanctioned by the power structures of these companies or not.
Re: Google discloses another Windows security issue after deadline exceeded
#144Earlier quoted context omitted.
I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…
> [...] and discloses a zero-day. 90-day, you mean. It's only zero-day if they had zero days to come up with a solution. That's what "zero-day" means.
Re: Google discloses another Windows security issue after deadline exceeded
#145The first thing Microsoft does when they learn about a zero-day is to hand it to the NSA. Microsoft doesn't get to fix it until the NSA tells Microsoft they're done exploiting it. Google may be pissed about this. They've been pissed off before about NSA's shenanigans.
I suspect that Google is an NSA front organization, which is why Google appears to be pissed at the NSA. In any case, I think both Microsoft and Google would be high value targets for all sorts of infiltration by the NSA, whether it's sanctioned by the power structures of these companies or not.
Apple was on one of those slides. I suppose they're an NSA front organization as well?
Re: Google discloses another Windows security issue after deadline exceeded
#146Earlier quoted context omitted.
I suspect that Google is an NSA front organization, which is why Google appears to be pissed at the NSA. In any case, I think both Microsoft and Google would be high value targets for all sorts of infiltration by the NSA, whether it's sanctioned by the power structures of these companies or not.
So HN has gone from seeing Google's name on a PRISM slide, to assuming it's entirely an NSA outfit? Apple was on one of those slides. I suppose they're an NSA front organization as well?
I also said that I suspect that's the case, not the I assume it to be. Given that the NSA seems to do what it wants and the obvious motivation for infiltrating or starting companies like Google...I think the suspicion is warranted.
Re: Google discloses another Windows security issue after deadline exceeded
#147Earlier quoted context omitted.
The Kaminsky bug was disclosed 30 days after it was announced, and by then, pretty much the entire internet had been patched. Google is being generous with 90 days, and Microsoft is being utterly incompetent.
This is trolling.
"Imagine if Google found the Kaminsky DNS bug. The internet would have melted on day 91 when google told everyone, "Sorry, too bad."
Given this, if the Kaminsky bug was fixed in 31 days, that seems like a very bad example to use.
Re: Google discloses another Windows security issue after deadline exceeded
#148Earlier quoted context omitted.
Seriously, if you depend on heavily unreliable third parties to deploy critical patches to your product, your release mechanism is broken.
It's not Google's product any more than it's the Linux Foundation's product. Both are just organizations with software built into somebody else's product. Nexus phones purchased from Google are Google's product. Separately, complaining that the vulnerabilities are unpatched in Android is a rubbish argument. They are fixed in the latest release.
Re: Google discloses another Windows security issue after deadline exceeded
#149Earlier quoted context omitted.
How is that a reasonable excuse? If they have so much money their operating system should be fixed faster, not slower, than other operating systems.
More resources should make the number of fixes possible per year greater, but it may not substantially reduce the time from notice to fix any single issue (and may, because of organizational overhead involved, sometimes increase the time for particular fixes over an organization with fewer total resources.) Maintaining code is not a trivially parallelizable function.
Yes, I know this, thank you.
But we are talking about billions of dollars vs. millions of dollars (for Linux / BSD). We are talking multiple orders of magnitude(!) more money. I realize there isn't a Silver Bullet, but the fact that what we have heard coming out of Microsoft about they're management practices year after year is ABYSMAL, it is not an excuse. Especially when people who are working for free, with no/little organizational support, can beat them at releasing security fixes.
> because of organizational overhead involved
So maybe they should fix it? How is their incompetence at running an organization a valid excuse? If it was a problem they cared about they would be researching how developers and teams of developers perform best, how best to organize code, etc. Instead they used stacked teams for years on end. I have no sympathy.
If it's as serious problem maybe they should stop making new operating system features and devote more resources to fixing, cleaning up, depreciating, etc. the ones they already have?
They are making business decisions, and their ineptitude at security is a result of them. There are no excuses of "they are the only one's doing X" for "they are bad at doing Y when they do X" when they are promising Y!
Re: Google discloses another Windows security issue after deadline exceeded
#150Earlier quoted context omitted.
How is it a fallacy? Because management is incompetent? If your budget goes from 1M to 10M even a child could show you how to spend 1M and throw the rest into a big fire or something. Maybe run two agile teams at 1M each.
Do people not read The Mythical Man Month anymore?
The point is that Microsoft has the money to hire 100x more developers than the other guys, they should at least be well organized enough to deploy a part of that man power effectively.
Lets put it this way, there are 7 companies out there (at least) maintaining various different distributions of UNIX that can patch quickly, why can't Microsoft patch their 7 operating systems as quickly? From my view what you are saying is that because Microsoft is a monolithic company with 7 code bases it is somehow harder than 7 companies with 1 code base each? How does that track? Especially when Microsoft has a 100x more money than each of those other companies.
I'm not saying there is such a thing as a man-month. I'm saying there are ways to organize production, teams, and software so that people can provide more work than in poorly managed environments.