8 ms·
Advertising the details of an exploitable vulnerability before the vendor has patched is protecting users now? I don't buy this motive at all.
by besselheim 10y ago
Advertising the details of an exploitable vulnerability before the vendor has patched is protecting users now? I don't buy this motive at all.
- Godel_unicode 10y agoThat level of detail allows malware detection by static analysis, A/V signatures, HIPS rules, etc. Source: I've done these things before based off notices like this, and caught malware with it
- besselheim 10y agoAt the same time it allows exploit writers to quickly add this to their kits. I'd expect AV vendors to already have signatures for this given that it's being actively exploited, which means there must be malware samples to know this.
- anfedorov 10y agoMost importantly it tells MS "fix your shit when your users are being attacked". Seven days ago was a Monday. That means they had a full week and a weekend to fix this. I understand that big bureaucratic organizations move slowly, and that the fix isn't trivial, but this is really the kind of thing for which they should have "scramble the jets and fix it" processes in place if they care about their user's security. When there are known exploits attacks against users, giving a short time to get out quick patches to trusted software vendors makes a lot of sense, but I don't see a good reason for giving more than 24-48 hours before public disclosure.
- ascendantlogic 10y agoAh yes, the endless holy war over what constitutes "responsible" disclosure and the concern over who benefits more, the attackers or the attackees? In this case, the exploit was being actively used in the wild. That means bad actors already had access to this and it was the users who were in the dark. Now it may be added to the "toolkits" of scripters and people who buy exploit frameworks but the people who do real damage were already using it according to Google.
- stanleydrew 10y ago> I don't buy this motive at all. OK I'll bite. What do you think the motive is? According to the post's byline, it was written by Neel Mehta and Billy Leonard of the Threat Analysis Group at Google. Are you questioning their professional judgement and claiming they are individually biased? If not, are you suggesting that there is some management directive to look for Windows exploits and publish them on an aggressive timeline in order to embarrass Microsoft publicly? Do you think professional security researchers would abide by such a directive?
- besselheim 10y agoYes, I believe what you describe in your second paragraph is most likely to be the case, given that coordinated disclosure is the standard approach to protecting users.
- antarrah 10y agoHe's probably being sarcastic.
- zodiac 10y agoWaiting for coordinated disclosure should not delay disclosure indefinitely, though. Google decided on 7 days as per https://security.googleblog.com/2013/05/disclosure-timeline-for-vulnerabilities.html?m=1 https://security.googleblog.com/2013/05/disclosure-timeline-...
- besselheim 10y agoI can't imagine that Microsoft have refused to fix this vulnerability though, otherwise this would have been mentioned in the blog post. There's no good reason for Google not to respect coordinated disclosure here. Making an arbitrarily tight deadline their policy isn't protecting users.
- fulafel 10y agoThe cited motivation was "it's being exploited in the wild". It's better to enable the rest of the world to defend against it.
- mtgx 10y agoRegardless of Google's motives, "full disclosure" of vulnerabilities has always been about protecting the users and not the companies. The idea behind it is that companies need to be pressured into fixing bugs quickly. You can argue about the benefits and how effective such a strategy is, but that's why some people have done and continue to do full disclosure of bugs.
- timv 10y agoI'm not yet sure whether I agree with the action/timeframe here, but but broadly speaking the argument is that you need to set a deadline, and enforce that deadline in order to pressure companies to fix their issues. It's not just that people affected by this vulnerability are being protected by its disclosure (though there are reasons why that might be the case) it's that in the future vendors will take deadlines from P0 far more seriously when they realise that their reputation is on the line if they fail to patch in time. If you let vendors get away with "we know that this is being actively exploited, but we haven't been able to come up with a timely fix, so please don't tell our customers how screwed they are", then that becomes the standard line and you need to keep letting deadlines slip. Or you don't let them slip and you end up with this sort of situation.
- Ph0X 10y agoWhat about the thousands of people with imporant data that could be attacked in the coming days using this exploits, but can now protect themselves from it knowing this? It goes both ways. As they said, this is active in the wild and many are being hacked AS WE SPEAK completely unaware of it. Imagine you had some information that is worth millions of dollars on your computer who is vulnerable to this. Now that you know, the first thing you'll do it turn off your computer or find a way to protect yourself. If they hadn't released it, you could've been hit in the coming week or month or however long it takes Microsoft. As you can see, this isn't a black and white problem.
- tallanvor 10y agoHow does Google's disclosure allow people to protect themselves, though? They say to update Flash. Great, but that doesn't explain whether or not anything can be done to prevent the specific Microsoft vulnerability from being exploited if Flash isn't involved. So if Google doesn't have any way to mitigate the vulnerability, all putting these details out do is allow more actors the chance to use the vulnerability until Microsoft can release a patch, which is exactly the opposite of responsible.
- wstrange 10y ago