3 ms·
Yes, I believe what you describe in your second paragraph is most likely to be the case, given that coordinated disclosure is the standard approach to protectin
by besselheim 10y ago
Yes, I believe what you describe in your second paragraph is most likely to be the case, given that coordinated disclosure is the standard approach to protecting users.
- antarrah 10y agoHe's probably being sarcastic.
- zodiac 10y agoWaiting for coordinated disclosure should not delay disclosure indefinitely, though. Google decided on 7 days as per https://security.googleblog.com/2013/05/disclosure-timeline-for-vulnerabilities.html?m=1 https://security.googleblog.com/2013/05/disclosure-timeline-...
- besselheim 10y agoI can't imagine that Microsoft have refused to fix this vulnerability though, otherwise this would have been mentioned in the blog post. There's no good reason for Google not to respect coordinated disclosure here. Making an arbitrarily tight deadline their policy isn't protecting users.
- fulafel 10y agoThe cited motivation was "it's being exploited in the wild". It's better to enable the rest of the world to defend against it.
- besselheim 10y agoThis is flawed reasoning, as the vast majority of people will defend against it by installing the patch.
- Oletros 10y agoWhat patch?
- besselheim 10y agoThe future patch that Google should have coordinated their disclosure with.
- Oletros 10y agoSo, there is no patch. And the only mitigating thing is what Google has said, patching Flash. Now, tell me, how users would know about that without disclosing. And, remember, there are already exploits
- besselheim 10y agoThe problem is that Google also said this: > The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD. Which is enough information for someone to write an exploit from scratch. If they'd just said there is a win32k.sys vulnerability and advised users to make sure Flash is up to date, this would have been fine.
- protomyth 10y agoI'm starting to believe the base problem is a difference between a software company that has to test the heck out of every patch because of their large customer base (Microsoft) and a company that doesn't have a complete consumer facing experience[1] (Google). Seven days is not enough to patch anything that needs to be tested in the extensive manner required. An update / disable Flash would have been good enough until a proper patch on the day IT has planned (Patch Tuesday) activities around the deployment of patches. I'm starting to think the ultimate PC OS for IT would be one with a transactional audit trail on all changes to the PC. 1) try calling Google about a problem if you disagree with this statement
- stanleydrew 10y agoAs mentioned elsewhere in this thread, this has been Google's disclosure policy for more than three years. https://security.googleblog.com/2013/05/disclosure-timeline-for-vulnerabilities.html https://security.googleblog.com/2013/05/disclosure-timeline-... Stop spreading FUD without evidence.
- besselheim 10y agoLooks like a conveniently written policy for hitting their competitors with to me. What is certain is that Google pick and choose when to apply these disclosure time limits, they're not set in stone.
- stanleydrew 10y agoI guess it can look however you want it to look, if you've already decided that you know the truth.
- besselheim 10y agoNo, just sceptical of their claim to be protecting users by disclosing early.
- CiPHPerCoder 10y agoThank you for saying "coordinated disclosure" instead of the misnomer, "responsible disclosure". n.b. https://adamcaudill.com/2015/11/19/responsible-disclosure-is-wrong/ https://adamcaudill.com/2015/11/19/responsible-disclosure-is...
- ascendantlogic 10y ago"coordinated" disclosure is a wonderful thing in a vacuum, but when people are actively being exploited then what? You silently wait to announce until the vendor is ready? How many people get owned in that time frame? How many people could mitigate in the meantime if they're tipped off to what the bad guys already know and use? There's no "right" answer because this is a holy war that's been going on for a very, very long time now.