Google is irresponsible, claims Fortnite's chief in bug row
bbc.co.uk
bbc.co.uk
Timeline:
8/15/2018: Google reports issue to Epic
8/15/2018: Epic begins investigating
8/15/2018: Epic confirms bug and begins working on fix
8/16/2018: Epic is testing the fix
8/16/2018: Epic begins deploying fix
8/16/2018: Epic asks for full 90-day period to deploy and test the fix
8/24/2018: Google finally replies: "now the patched version of Fortnite Installer has been available for 7 days we will proceed to unrestrict this issue in line with Google's standard disclosure practices"
They literally waited until the last minute to go, no, sorry, we're not waiting, it's full-disclosure time, :trollface:Epic noted in the article that the game won't auto-update until the user runs it. So they clearly would have needed to inform users that didn't play regularly to get the update. However, Epic could have notified its own users when they were ready, rather than Google outing them by default.
If Google had replied, like, 7 days earlier, and said "sorry we're not waiting", maybe Epic could have made different decisions, knowing they wouldn't get the time they requested. It's clear that Epic worked their asses off to churn out a patch. They could have announced within that time if this was properly coordinated.
Whether this was just Google being indifferent to a company's reputation, or an active attempt to penalize Epic for not forking over 30% of their revenue, is left up to the reader. But Google acting in the interest of users is not a defense here, because Google just ignored Epic and then fulldisc'd.
The game came out on August 9th. Knowing how the release was big news, that the game itself is gigantic in size, and only runs on certain higher end smartphones, I would argue that there are close to no Android users that would not enter the game within those seven days.
Here, I'll quote it for you:
> [NOTE: This bug is subject to a 90-day disclosure deadline. After 90 days elapse or a patch has been made broadly available, the bug report - including any comments and attachments - will become visible to the public.]
Google waited a full week after the patch has been made available then they disclosed it.
This incentivizes companies not to announce their patches, not to coordinate with Google, and to only update in secret, because as soon as they tell Google they have a patch, the clock runs down in 7 days, rather than 90. This is a dangerous policy.
Anyone can break apart the patch and figure out what was changed, meaning they can figure out the security issue and take advantage of it. At this point, both Epic and Google are at fault for not disclosing the details and warning people to update right away.
If you think people should be warned right away, Epic should have the right to notify its own users, and Google should have the basic decency to reply to a request to coordinate.
Google found the bug, they have the right to disclose it however they want. There are no legal standards anywhere that requires anyone to do anything with bug reports.
Epic doesn't have any rights here, it sucks but they're not entitled to anything. I hate this because I've experienced this from Google before (at work), I would love to have that right to hold up to 90 days before we can notify people but until there are legal standards, there is no right.
They have an ethical obligation. Security disclosures have major ethical concerns. If you're acting unethically, you are a dick.
Sure, Epic doesn't have any rights here. But we don't need a law to know people [and corporations] should not be dicks.
Google could have been more ethical by replying to the vendor after making their initial communication. They chose not to.
You are correct in that Google has an ethical obligation; and they and met it by protecting all Android users. I would say that Google making this announcement lets all Android users know that its not safe to just randomly install apps on your phone. Yes, they allow it, but at the same time the public is genuinely ignorant of any type of security practices.
This is a non-sequitur. You are equivocating between legal obligation and ethical obligation.
Google's original view of the situation was that installers like this make devices measurably less secure (to which Epic's response was pretty meh), and the installer being exploitable to install pretty much anything only proved that point and then some.
...and frankly, it would not matter who wrote the installer if it got used for a mass infection and attack. Google would still get the bad press and a generous helping of blame because of the trashy way so many "tech reporters" behave to get those mouse clicks.
It would be reasonable to tell Google that they have a patch, show them the patch, and tell that's going to be released on third thursday of September or whatever, and the disclosure should wait until that - that's compatible with that policy. Showing the patch to Google and coordinating with them doesn't start the clock, the clock starts when you start sending the patch to random users.
It's not acceptable to release a patch to the general public and then delay the disclosure for weeks. Once Epic discloses the vulnerability to the bad guys (by making the patch broadly available), the good guys i.e. the general public needs to know the details ASAP.
The 90 day buffer is the time for analyzing the vulnerability and developing (and testing) a fix for it - but not for deploying the fix; deployment must be much, much faster than that, preferably on a single day.
I guarantee Fortnite wishes they had silently released the patch and hope Google didn't know.
I'm guessing they might in the future.
If Epic needed more time to prepare for deploying the patch, then they should have released the patch later, coordinating with Google - they certainly had time left for that, up to these 90 days. But once Epic started the clock by making the patch widely available, it is unreasonable to wait anything comparable to 90 days. Google should have disclosed the vulnerability on the same day as the patch, since the patch also 'discloses' the vulnerability to those who would use it. Delaying it for a day or two could be mostly safe; 7 days is pushing it, anything more than that is not a good idea - by that time the bad guys know the vulnerability anyway, and the delay is just harming everyone else.
At what point did people who browse a site called "Hacker News" start believing in Security through Obscurity?
If there was no update/patch, I might side with Epic, but as soon as the fix was out and everyone needed to update, users needed to know the risks of inaction would inhibit. Not least of all because people may start reverse engineering the patch.
Epic has decided this is revenge for them not using Google Play, but if you look at Google's bug efforts historically, this has always been how they handled these issues. They've been highly consistent about it.
If Epic wants to keep serious security bugs under wraps in the future, maybe they shouldn't rely on unpaid third parties to audit their code.
PS - Google gave them 7 days from patch release, so most auto-updaters likely updated the installer.
Except this is how Google has always handled these bugs. The article even links to other examples involving other companies.
> Google is being anti-secure here by not allowing the update to filter through the ecosystem.
Or pro-secure here by telling users to urgently update rather than doing nothing and hoping nobody spots the bug and starts exploiting it before users get lucky.
You don't have to go yelling about the fact you're distributing a highly important security patch, that only draws the attention of the bad guys.
Wanting to distribute such patches as low profile is a valid choice and is not "doing nothing and waiting to people to exploit it".
Low-profile means what it says on the tin; make it sound so boring that hackers are less likely to attempt it.
Plus being low profile reduces exposure to people who only look for high profile stuff.
And plus "not improbable" =!= "fact".
And it's not like they would have succeeded - you can't patch something silently, if you know of a vulnerability it's not that hard to verify if it has been fixed in every upcoming version or not. Google would have had noticed that within a day anyway and (with justification) disclosed the vulnerability right then and there, instead of giving them those 7 extra days.
It looks like the Fortnite APK is 1.88GB. I don't have familiarity with the Android platform, can you update via patches (over a full binary download)? If updates are anywhere near that size, a 7 day disclosure after patch is patently irresponsible (play store or not). This smells like a cheap PR play by Google.
The Fornite APK itself is also <100MB.
More like 5 - Nintendo, Microsoft, and Sony all control what software goes on their platform either digitally through their console app stores or physically since all media has to have keys from the console makers to run.
Sure, it provides extra security, but at a heavy cost.
Seeing how the last 30+ years of personal computer use has played out, the vast majoriyy of users should probably be using locked down devices.
And Epic provided the perfect example of why app developers should be forced into a strict sandbox. I need my phone to always work it’s much easier for me (but not most people) to recover from a virus/malware/ransomware on my computer than a hypothetical one on my phone.
Similarly, I also wouldn't care if a random hacker or reputable firm disclosed Target's vulnerabilities when they put millions of customers at risk. I'd blame Target by a big margin.
On a side note, I don't love Google's rules as I understand them. They seem to punish prompt action and honest communication in some cases (eg. this one). I think you should just get the 90 days if they're willing to allow it. Of course, this is always their call.
EDIT: Other users are saying the short deadline is because the public will be made aware of an exploit, due to existence of a patch. I did not think of that initially, but it does make sense
Epic is also saving their users some bucks. I'm not so sure that users hate the tradeoff.
There is nothing stopping Google and Apple charging a fixed fee for the cost of verifying the quality of submissions to the App store. The 30% is just pure rent-seeking, and frankly now it's monopolistic on Google's side.
+1 points for turning this issue into more publicity.
Epic doesn't have "secure" install infrastructure, that's the whole crux of this issue.
Given how right you are, it's exceptionally odd that a capable well-capitalized development organization would not use such systems and manage such a basic mistake.
That's definitely not what the bug report and Epic themselves say, they never fixed the execution of unverified code issue, they just moved where the unverified code was stored so that other apps couldn't replace it easily.
They still need to actually verify that what they're executing is what they verified.
They did. Why would you say otherwise?
If they can't trust the private storage to be private, then you're looking at a compromised phone where they can't trust any mechanism.
Because I read the bug report? Where Epic specifically say they didn't fix the execution, instead they changed the storage context from External to Internal. The main issue is that they verify after download instead of before execution.
You put an exclusive write lock on the file, verify the file, and then execute the file without releasing the lock. It is what every other major installer or updater does. Epic's version instead downloaded the file, verified it, then [Sleep], and installed whatever was at that location. It is insecure.
I'm not sure holding a lock even works to prevent file renaming on most OSes...
> Google's disclosure rules state that it reveals details of bugs to the public 90 days after reporting them to the developers responsible if they have not been tackled, but only waits one week after a patch is made "broadly available".
So Epic made a patch available and Google waited a week. But:
> ... [Time Sweeney] denied suggestions that the tech giant had acted in users' interests by refusing to keep the matter private until mid-November.
The 90 days is for unaddressed bugs.
This is nothing more than an attempt by Epic to fix bad PR from a security vulnerability they introduced (which arguably at this nascent stage might reduce public confidence in their bypassing the Play Store) by trying to deflect it onto Google.
And I get the desire to skip the 30% cut but if you're going to do that you're then responsible for the safety of a person's phone and data. At least be up to the task.
> [NOTE: This bug is subject to a 90-day disclosure deadline. After 90 days elapse or a patch has been made broadly available, the bug report - including any comments and attachments - will become visible to the public.]
Note the "or a patch has been made broadly available". 90 days policy almost never apply when there is a patch released.
It does not make sense to keep the vuln report hidden when a patch comes out, the act of the patch itself reveals the security issue for anyone who takes the time to check what it does.
The only thing Google should have done better is make it clear to epic that they will lift it in 7 days, not the 90 that they asked for. Epic could have known by looking at other incidents, but based on their request they obviously did not and Google should have corrected them.
This seems like an accurate take. Why else would google disclose the bug so quickly?
But here's my personal take. As a consumer I want my phones to run secure apps on secure operating systems. This has a cost obviously which is fair to pass on to developers.
It's clear to me, with all the rogue apps and crap in the Play Store that Google is not investing enough in managing app store content.
Fortnite won this battle but in my book Apple will win the war.
My kids install all sorts of crap. I've warned them that all their texts and photos will end up on the internet because of it. Not highly probable, but certainly possible. Makes for a useful double check they're not texting anything silly.
> You mean google?
He's saying that Apple, is doing a much better job of "managing app store content" than Google, and so ultimately it doesn't matter if Fortnite or Apple wins this battle: they're fighting over a mound of rubble while Apple builds a castle.
It doesn't matter. Apple doesn't win in the end.
In the other Apple vs mound of rubble fight (Windows), Apple lost.
Android is doing the same thing. Android 4.0 was Windows 3.1 (first Android version to be "modern", IMO), Android 5.0 was Windows 95 (better UX). Android now just needs Windows XP to be stable enough (I'd argue Android 8.0 was that) and Windows 7 to cover the security aspects (most likely wide spread adoption of new Android permissions). But the writing is kind of on the wall, outside the US Android has majority market share and it's only going up.
That charge cannot POSSIBLY be 30% of sales. Not least because the cost of checking the apps that go into the App store is not in any way related to the revenue the app generates.
The charges for appearing in the store come from Google (a monopoly in the smartphone market in most places) rent-seeking.
Alternatively, Google could of let users continue running unpatched software until the 90 days expired...
Want the profits? Then use them to actually make a safe product.
Epic patched it on August 17th, Google waited 7 more days (as it is their usual practice) and then they went public.
Issue tracker makes more sense than the article IMO: https://issuetracker.google.com/issues/112630336
I guess that usually seven days is more than enough for everyone to update to the latest version available on the Play store, however downloading a giant .apk file within seven days is an inconvenience for most users, which is why Epic requested 90.
My logic : Want security, stop recording peoples data. ( The most secure way to store data is not store data in the first place)
Would that be fair to google and the consumers of google.
And I would bet that I would be booked under some "Hacking" related law for doing that.
If anything, Google should just make sideloading of apps illegal and let companies like Epic face the legal risks if they try to bypass security for profit motives.
Google is throwing their weight around to dictate their philosophy on software to the entire industry. It's just good for us that it's debatable whether this particular edict is in everyone's interest, not just google's. Not all that reassuring about Alphabet in general, tho.
Rhymes with "how".
It can be pronounced like "grow" and like "how" (or "bough".)
Take a bow with your bow tie on.
Pile up a mow when you mow down your hay.
Have a row when the row is not straight.
Tie up the sow when you sow seeds.
That tow-headed man drives a tow truck.
(For additional fun, pronounce bough, cough, rough, and tough.)
The dick is Epic not Google