Google discloses Microsoft Edge security flaw before a patch is ready
theverge.com
theverge.com
https://bugs.chromium.org/p/project-zero/issues/detail?id=14...
It's a race condition that allows an ACG bypass. Under ACG, only privileged processes in the browser process ensemble can create new executable pages. But the mechanism by which privileged processes "give" executable pages to less-privileged processes enables the lesser processes to populate them with code of their choosing. It's medium severity because it's just a bypass of a (relatively new) security control. For it to be useful, you already need to have an RCE-able bug.
The headline is a bit misleading, and the article keeps you on the hook for a couple grafs before explaining.
You don't get "indefinitely, until the patch is released" from Google. You get 90 days. It's on you, the vendor that shipped the buggy software, to figure out how to ship a patch within 3 months. If you can't, you can ask for a grace period, which Google isn't obliged to give you (but did give here). I believe, but am not sure, that Google will give longer grace periods for very severe vulnerabilities, at their discretion.
This is how it has to be. Big vendors --- Google almost surely included! --- will backburner patches for months and months if they aren't given hard deadlines. Deadlines serve the users --- not just of the vulnerable software, but of all the other users that might depend on the people who use that software in some indirect way.
Either way, it doesn't look like anything was done to spite Microsoft. But a "business continued as usual" headline wouldn't attract as many clicks, I get that.
What surprises me is that so many of the really big ones seem to be found by Google.
Spectre and Meltdown by multiple poeple. But Shellshock, Broadpwn, Heartbleed, and Cloudbleed if memory serves all found by Google.
Off the top of my head can not think of a major one the last couple of years found by anyone but Google. Anyone else?
I'd actually be super curious to know how they pick what they look into. Just a "hey, I wonder about this" while going about their day, or if they have some sort of agenda laid out for when to look at what software.
At least that is how I would run something like this.
Probably my favorite of late is from Jeff Dean
https://arxiv.org/abs/1712.01208
We just got YouTube TV recently and also something that is pretty impressive by Google and saves me a ton of money as my cable provider was awful charging for every TV monthly.
Another example of something I find really interesting is Spanner.
What if a user/users would rather a company spend their resources into adding a feature they care about, than fixing a bug that doesn't impact them? (Not that I disagree with Google's position here..., just a contrarian view)
If they're inconvenienced by the 90 day deadline, they have Microsoft to blame for it, not Google.
And if they don't have any intention of ever fixing it, it basically doesn't matter when it is disclosed. So in that case, having a deadline is no worse.
Yes, sometimes you can be more efficient if you have your choice of when to do something, but that's usually a relatively minor effect.
Microsoft has no right to be angry - they should be thankful. This is peoples data, their business at risk. After being in the business for so long time, and with the resources they have, they can afford to put a small army of swes to fix security bugs.
Unlike a small company, the bugs in widely used software, by definition, affects a large set of people.
Disclaimer: google employee.
That's not actually what responsible disclosure is for. Responsible disclosure is a process that [correctly] assumes that a malicious third party has also discovered the bug and is currently exploiting it or selling it, but acknowledges the assumption. If you disclosed bugs immediately, the could be novel and you could have let the cat out of the bag. If you never disclose bugs, they could already be in the wild and doing damage.
Forcing Microsoft to fix it is just a beneficial side-effect.
I am wondering how do the engineers at Google that work on finding software issues or vulnerabilities approach that kind of work? Is there a way to heuristically find security vulnerabilities and software issues?
Edit: Especially when those vulnerabilities need so much work to be revealed, like the meltdown/spectre issues we heard about recently
Here's the backstory on Meltdown specifically: https://www.bloomberg.com/news/articles/2018-01-17/how-a-22-...
Why isn't that enough?
Microsoft and Google both patch security updates every single month that fall well within the common 90 day disclosure window. And then every so often, they fail to.
I don't mind that 90 days is a soft deadline, at which point as long as they're showing determinable progress on the issue, all is well until it is patched. But disclosing the bug before a fix is in place exposes users to possible actors that wouldn't know of said issue previously (ie like WannaCry being based on leaked NSA offensive tools. Leaking effectively being an involuntary disclosure).