What's up with them not being able to patch on time? How is 90 days not enough to get a patch out the door? That's a quarter, for goodness' sake!
What's up with them not being able to patch on time? How is 90 days not enough to get a patch out the door? That's a quarter, for goodness' sake!
1. Reliable exploitation might be difficult in such a way that the P0 people know how to get an exploit working, but Microsoft doesn't, and so it got deprioritized. A related (less likely) possibility is that the bug simply isn't easily exploitable in the configuration Microsoft ships, or expects to be shipping, these browsers in, due to environment differences in Google's testing lab.
2. Patching the bug might be more difficult than P0 anticipated (it might break compat, for instance).
3. The bug may be part of a pattern which is apparent to Microsoft but not to P0, so they may be holding off to get everything patched all at once rather than release an incremental patch that tips attackers off to a bunch more vulnerabilities.
Communication between P0 and other vendors isn't always great. (I think this is the fault of other vendors, by the way, and not P0).
That's in total contrast to web development where you can deploy a fix in ~ 1 hour to all your users simultaneously.
Hasn't stopped Microsoft pushing bad updates in the past.
> then wait some more because people ain't updating that often.
That's a problem with their update model, security waits for nobody.
It's a false dichotomy to suggest that MS's only options were an actual fix vs. do nothing. There are always other options.
Why does IE have a problem with this whereas other popular browsers do not?
Edit: This is sarcasm but the bank story is true.
But I hope Microsoft can prove me wrong and explain in detail next month why it couldn't deliver any of the 20-30+ bug patches because of a couple of other unrelated and broken patches.
Keep in mind that the Google docs/drive/whatever suite is the competitor for Microsofts Office 365 product.
Has Google ever released info about an unpatched critical bug on their own systems/applications?
> Has Google ever released info about an unpatched critical bug on their own systems/applications?
https://bugs.chromium.org/p/project-zero/issues/list?can=1&q...Are those critical? Not according to the text accompanying them, or am I missing something.
[1] Certainly not literally altruism. I suppose Google thinks this projects benefits everybody including themselves.
That's quite possible but once you start releasing unpatched vulnerabilities about competitor products there is at least a chance that 'including themselves' trumps 'everybody'.
It's not like we haven't been here before:
http://www.theverge.com/2016/10/31/13481502/windows-vulnerab...
So, google made a nice little 'hands-off' automatic disclosure feature which gives them a reason to say 'computer did it' but I don't think for an instant 'altruism' of any kind is the reason they do this.
If google really had the well-being of internet users at heart they'd shut down google analytics and stop accumulating profiles.
Until they do that my money is on Google estimating that they will do others more damage than they will do themselves through Project Zero and as such yes, we will all benefit but Google will benefit the most of all.
how would that "help" the well-being of internet users?
What's more, their analytics have nothing to do with the point at hand. Why even bring it up, except as an opportunity for a tangential soapbox? We're talking about disclosure timelines.
So if Google wanted to attack MS on the subject of privacy they'd have to go all the way to Skype to get some traction. So instead they attack on a front where Google is strong and Microsoft slightly weaker.
Google is anything but altruistic, their each and every move is to improve the bottom line for Google and their shareholders. If something is really altruistic it likely falls in their PR budget.
It seems pretty unreasonable to fault Google if the answer is "No, because they patch critical bugs in a timely manner."
There is so much missing in terms of transparency here. For instance: was there positive confirmation the message was received by the right people at the vendor? Was there any attempt at communication as the expiry date drew close?
Of course the onus is technically on Microsoft but Google has been at this before and it did not look clean to me at the time.
I can't believe I'm defending MS here.
I'm all for competitors keeping each other sharp but it helps to keep in mind they're competitors first.
One possible way around this is to set up something like project 0 independent of Google, Microsoft and so on and have all of them commit to contributing funding to keep it alive.
The answer is: Yes, thev're had critical Android bugs pass the deadline. And what I wrote 88 days ago still holds - still can't see what the actual android bug says, which is annoying.
(FD: Google pays me a day per week, but they don't pay me to spout of on HN in the evenings; this is all my opinionated opinion. :-)