Live data from Hacker News

Microsoft hits out at Google team over bug report

bbc.co.uk

71–80 of 165 posts

Re: Microsoft hits out at Google team over bug report

#71

I think there is something to notice about having a hard fixed timeline for everyone. See from the bug: https://code.google.com/p/google-security-research/issues/de... > Microsoft confirmed that they are on target to provide fixes for these issues in February 2015. They asked if this would cause a problem with the 90 day deadline. Microsoft confirmed that they anticipate to provide fixes for these issues in January 2…

Which sounds like blackmail to me. What did Microsoft have to put aside to move this up in their schedule? Maybe now the release date for Microsoft's new browser slips, giving Google the upper hand? Should corporations force their competitors to move like this? "If you don't drop everything, we're going to release vulnerability details about your product"? I work in information security and patches are important, I u…

What a disingenuous comparison. It's not "accede to our demands or we'll publish this information"; it's "we're publishing this information in 90 days whether you like it or not."

If we ask "what gives any company the right to publish vulnerabilities about their competitors?" it's only a short step to asking "what gives journalists the right to publish scathing negative reviews?" The answer is the same: freedom of speech.

It's a fact of life that if you want to fix security bugs, that takes time away from working on other things. If you don't like it, fix the bugs faster, or pay more attention to security from the get-go. Microsoft should be thanking Google for finding the bug in the first place.

Re: Microsoft hits out at Google team over bug report

#72
post #5

This is crazy. By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the second patch day, the vulnerability will be disclosed before the third).…

The "second-tuesday-of-the-month" policy is a completely arbitrary MS-only policy.

If Google (or any other group that discovers security issues) has to take into account every policy of every software producer it becomes utterly impossible to have any disclosure policy.

If MS wants to handicap themselves, that's their problem. The rest of the world doesn't have to bend to their will, those days are over.

Yes, this is about being an ass. And it's Microsoft that's being an ass by claiming the rest of the world should take into account their peculiar policy.

Re: Microsoft hits out at Google team over bug report

#73
post #5

This is crazy. By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the second patch day, the vulnerability will be disclosed before the third).…

I agree with this completely. Even if Google didn't know about patch days they should have allowed them two more days to release the patch since they asked for it. I would even say they could have given them another week window if they needed it. Releasing an exploit into the wild when you know a patch is coming is a really awe-full thing to do. If the tables were turned I wonder what Microsoft would have done here.

And the next company that comes along will ask for 3 days, and then 5 days, etc. Pretty soon we're back to serious bugs not getting fixed until the vendor feels like it. The power of a set timeline is the fact that its not up to the vendor when things happen. They have proven time and again that they won't fix things until they are forced to; this forces them.

It's just like being late for work. "But I was only 5 minutes late." Late is late.

Re: Microsoft hits out at Google team over bug report

#74
post #7

Earlier quoted context omitted.

If Google insists on exactly 90 days without any consideration for patch Tuesdays, this means that, if unlucky, MS will only get 60 days (if they got the announcement right after a patch Tuesday)

So, who forces Microsoft to stick to (so called) patch Tuesdays? No one, actually - it's Microsoft internal schedule, and clearly there are cases when it's absolutely unreasonable - e.g. when there's a 0day in the wild. So there has to be a way to fast track a fix - if there's not, there's something seriously wrong IMNSHO. Apparently, they thought Google won't stick to the 90-day limit.

it's Microsoft internal schedule

Not entirely true now. Users of MS software have built up their own testing processes around patch Tuesday.

Patch Tuesday was one of the best things MS did when they decided to take security seriously. They realized that testing patches downstream takes time and giving their customers a consistent patch day let them also plan ahead.

Re: Microsoft hits out at Google team over bug report

#75
post #5

This is crazy. By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the second patch day, the vulnerability will be disclosed before the third).…

The "second-tuesday-of-the-month" policy is a completely arbitrary MS-only policy. If Google (or any other group that discovers security issues) has to take into account every policy of every software producer it becomes utterly impossible to have any disclosure policy. If MS wants to handicap themselves, that's their problem. The rest of the world doesn't have to bend to their will, those days are over. Yes, this is…

The patch-day policy is not for Microsoft, it's for sysadmins who maintain the installations.

Re: Microsoft hits out at Google team over bug report

#76

I think there is something to notice about having a hard fixed timeline for everyone. See from the bug: https://code.google.com/p/google-security-research/issues/de... > Microsoft confirmed that they are on target to provide fixes for these issues in February 2015. They asked if this would cause a problem with the 90 day deadline. Microsoft confirmed that they anticipate to provide fixes for these issues in January 2…

Which sounds like blackmail to me. What did Microsoft have to put aside to move this up in their schedule? Maybe now the release date for Microsoft's new browser slips, giving Google the upper hand? Should corporations force their competitors to move like this? "If you don't drop everything, we're going to release vulnerability details about your product"? I work in information security and patches are important, I u…

In what world does the recipe for Coca Cola in any way influence the maintenance of a fleet of trucks?

Google's policy is responsible disclosure. Wavering on the well-known deadline would become a political headache. If you give a mouse a cookie... Two days becomes a week; a week becomes half of a month; half a month becomes a full month. Perhaps if Google is feeling generous, they could not disclose a vulnerability to a vendor until a later time (for example, if a vulnerability is found just before a well-known extended holiday or something) thus automatically "extending" the expiration of the quiet period. But that still leaves us, the users, more vulnerable for longer if the bad guys were already aware of the problem.

On a slight tangent, Microsoft's policy to not release security patches as soon as they're available (and instead wait until "patch Tuesday") harms us all. They don't have to forcibly push the fixes, but immediate availability would be a tremendous improvement.

Re: Microsoft hits out at Google team over bug report

#78
post #5

This is crazy. By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the second patch day, the vulnerability will be disclosed before the third).…

> By now the world really knows about Microsoft's second-tuesday-of-the-month policy for patches. Which is a dumb policy for security patches. When its fixed it should be released. > If Google isn't willing to wait the two additional days such that the patch can be deployed within the regular update window, this means that Google effectively gives MS only 60 days to react and fix issues (because once they missed the…

It's a darn good policy if you're the one who is responsible to apply the patches inside of your organisation and you have to test the effect of the patches to the applications running in your company before you actually install them.

Applying the patch a few days later typically doesn't noticeably increase your risks but rolling them out unchecked can make some serious damage.

Re: Microsoft hits out at Google team over bug report

#79

Earlier quoted context omitted.

Which sounds like blackmail to me. What did Microsoft have to put aside to move this up in their schedule? Maybe now the release date for Microsoft's new browser slips, giving Google the upper hand? Should corporations force their competitors to move like this? "If you don't drop everything, we're going to release vulnerability details about your product"? I work in information security and patches are important, I u…

What a disingenuous comparison. It's not "accede to our demands or we'll publish this information"; it's "we're publishing this information in 90 days whether you like it or not." If we ask "what gives any company the right to publish vulnerabilities about their competitors?" it's only a short step to asking "what gives journalists the right to publish scathing negative reviews?" The answer is the same: freedom of sp…

It doesn't matter if Google publishes it after the patch. It matters if the publish before. If they publish before the patch, even knowing when the patch will come out, that's enforcing their demands or making MS suffer the consequences. Google knew Microsoft had a patch. Google published it anyway, because their competitor didn't work fast enough, for Google's definition of "fast enough".

Journalists are not directly competing with tech companies. Google is. Imagine the next bug they find in Windows, and they publish it saying "ChromeOS doesn't have this bug!". They already use their search to push their browser, why not use their bug reporting to push their OS? When does free speech stop and anti-competitive behavior start? Would Google publish their own vulnerability if they were unable to fix it in 90 days?

Re: Microsoft hits out at Google team over bug report

#80
post #8

Earlier quoted context omitted.

And they asked for 92 days and Google decided to publish anyway? While I'm not surprised, it doesn't strike me as the most responsible action.

If you define a limit for disclosure, and then not stick to it, why to define a limit in the first place? 90 days is more than enough - if MS has a lot of internal overhead, you should probably complain to them, not to google.

"Our objective is to significantly reduce the number of people harmed by targeted attacks." (http://googleprojectzero.blogspot.co.uk/2014/07/announcing-p...)

They've lost sight of this noble objective with an inflexible policy; who anointed Project Zero guardians of the internet? Why not wait the two days? cui bono?

Post reply on HN