4 ms·
Or it's just P0 following their policy. Which is the only way P0 can maintain credibility and exert pressure on vendors to fix things. Especially after Google m
by konklone 10y ago
Or it's just P0 following their policy. Which is the only way P0 can maintain credibility and exert pressure on vendors to fix things. Especially after Google management just publicly overrode them regarding an Apple vulnerability a week or so ago.
- eganist 10y agoSure. My earlier point: > A longstanding policy doesn't make it a good one. If this was a disclosure by the books, there would've been broader, less overtly promotional mitigations discussed. Project zero would be better off reformulating its disclosure policy here if credibility is what they're going for. Sometimes it's healthier to admit being wrong.
- konklone 10y agoWhile it might assuage some kneejerk skepticism like this, I don't think they're obligated to omit that Chrome has mitigations in place when disclosing a vulnerability.
- eganist 10y agoYou're absolutely right. I'd rather have preferred a few different responses, such as including multiple mitigating strategies, even if they're user actions such as browsing only trusted sites until a patch is released. That said, even if the wording was "Browsers such as Chrome which block win32k.sys system calls using the Win32k lockdown mitigation on Windows 10 prevent exploitation of this sandbox escape vulnerability," I would've given them a partial pass.
- captn3m0 10y ago>Google management just publicly overrode them regarding an Apple vulnerability a week or so ago. Don't remember this. Can someone point me to a link?