Earlier quoted context omitted.
Have you ever managed a nontrivial installation of user-facing desktop systems? 'Cause if not, declaring the policy of a predictable, telegraphed-well-in-advance day on which security patches will drop "peculiar" kind of just reveals where your head's at.
The rate at which security vulnerabilities are reported/abused isn't predictable. Please don't sit on a fix until the time is more "convenient", give it to me now and let me be the judge on how important this security patch is to me.
Microsoft hits out at Google team over bug report
151–160 of 165 posts
Re: Microsoft hits out at Google team over bug report
#152If I were MS I wouldn't complain on this issue and instead I would just take the bait and put an internal team to find out bugs exclusively in Google products like for instance Android [1] and declare an arbitrary short disclosure policy [2] and then release these bugs when time is up. [1] https://news.ycombinator.com/item?id=8874339 [2] https://nakedsecurity.sophos.com/2010/06/15/tavis-ormandy-pl...
Re: Microsoft hits out at Google team over bug report
#153Earlier quoted context omitted.
So, who forces Microsoft to stick to (so called) patch Tuesdays? No one, actually - it's Microsoft internal schedule, and clearly there are cases when it's absolutely unreasonable - e.g. when there's a 0day in the wild. So there has to be a way to fast track a fix - if there's not, there's something seriously wrong IMNSHO. Apparently, they thought Google won't stick to the 90-day limit.
> So, who forces Microsoft to stick to (so called) patch Tuesdays? Their tens of millions of customers who plan internal deployment, overtime, and other things around those specific dates? > it's Microsoft internal schedule It's their external schedule actually.
If you plan your internal deployment updates based on the belief that the schedule will never change, then I'm really sorry for you and your users. In real world, not all issues are reported in advance - some are observed in the wild, and in that case you have to fast-track the fix. If you have no way to do that (e.g. because the vendor only releases fixes on Tuesdays once per month, or because you decided to choose such schedule on your own), then good luck. That might have been appropriate in 1995, not in 2015.
There are many projects and/or companies publishing fixes continuously, and leaving it up to the users when/how to apply them in production. That's essentially what all the linux distributions (RH, Suse, ...) and smaller projects do.
Re: Microsoft hits out at Google team over bug report
#154Earlier quoted context omitted.
I think it is safe to say that it is likely that many end users were hurt by Google not waiting the extra two days.
That's not safe to say. You're presuming that Microsoft and Google are the only two parties who knew about the exploit. Historically, it's more likely that the vulnerability was already known among cracking circles, and Google just announced something that was already in the wild.
Why do you say this?
It implies a world where software is almost perfectly secure, and there are only a few bugs to fix, and then it's perfectly secure, and we are all happy.
In reality, there are effectively an infinite number of bugs out there, many with security holes. Finding one and going through the motions to fix, patch, test, and release still leaves you software with plenty of open holes.
If you magically theorize "the bad guys know about all the holes already," then they are still going to exploit all the other holes in the system, because they magically know about them, too.
Re: Microsoft hits out at Google team over bug report
#155Hasnt Microsoft released "out of band" patches before? Why is this one so special?
Re: Microsoft hits out at Google team over bug report
#156Earlier quoted context omitted.
Google's action resulted in a security bugfix which improved the security of Windows, and on faster schedule than Microsoft would have provided otherwise. But sure, let's call it evil.
I get that. I don't get that they didn't let Microsoft fit it into their patch schedule (2 days later). I don't believe for a second that they would have disclosed this if it was Android and they had a fix that would land within 2 days. No f'ing way. That's the evil.
I really do hear what you're saying, and while I'm sympathetic to it, I think that it's much more likely that the Project Zero team adopted the 90-day policy specifically because of years and years of vendors playing push-the-deadline. If there was an industry history of vendors acting promptly in good faith, this wouldn't even be a thing, but the politics behind bug reporting and disclosure are really pretty mature at this point, and I really do think it's naive to just chalk it up to "Google wants to embarrass its competition and is playing dirty to do it".
Re: Microsoft hits out at Google team over bug report
#157[1] http://www.zdnet.com/article/google-stops-providing-patches-...
Re: Microsoft hits out at Google team over bug report
#158Re: Microsoft hits out at Google team over bug report
#159I think there is something to notice about having a hard fixed timeline for everyone. See from the bug: https://code.google.com/p/google-security-research/issues/de... > Microsoft confirmed that they are on target to provide fixes for these issues in February 2015. They asked if this would cause a problem with the 90 day deadline. Microsoft confirmed that they anticipate to provide fixes for these issues in January 2…
Which sounds like blackmail to me. What did Microsoft have to put aside to move this up in their schedule? Maybe now the release date for Microsoft's new browser slips, giving Google the upper hand? Should corporations force their competitors to move like this? "If you don't drop everything, we're going to release vulnerability details about your product"? I work in information security and patches are important, I u…
Re: Microsoft hits out at Google team over bug report
#160Look, I'm been really happy with a lot of the stuff Microsoft has been doing recently, particularly in open source. But this is ridiculous. They had plenty of notice that Microsoft's standard 90-day (90 day!) policy applied, and that no exceptions were going to be made. I applaud Google for not bending on their 90-day deadline (assuming they do hold all companies to that, and it appears they do). Maybe this incident…
Reading the comments on the ticket however, I really feel like Microsoft was in the wrong here. They asked 4 days ago to push it for a whole month and then now they are fine for their January release. I really feel like they start to feel the pressure of the 90 days so being strict about it is a good choice from Google.