4 ms·
I'm not yet sure whether I agree with the action/timeframe here, but but broadly speaking the argument is that you need to set a deadline, and enforce that dead
by timv 10y ago
I'm not yet sure whether I agree with the action/timeframe here, but but broadly speaking the argument is that you need to set a deadline, and enforce that deadline in order to pressure companies to fix their issues.
It's not just that people affected by this vulnerability are being protected by its disclosure (though there are reasons why that might be the case) it's that in the future vendors will take deadlines from P0 far more seriously when they realise that their reputation is on the line if they fail to patch in time.
If you let vendors get away with "we know that this is being actively exploited, but we haven't been able to come up with a timely fix, so please don't tell our customers how screwed they are", then that becomes the standard line and you need to keep letting deadlines slip. Or you don't let them slip and you end up with this sort of situation.
- Ph0X 10y agoWhat about the thousands of people with imporant data that could be attacked in the coming days using this exploits, but can now protect themselves from it knowing this? It goes both ways. As they said, this is active in the wild and many are being hacked AS WE SPEAK completely unaware of it. Imagine you had some information that is worth millions of dollars on your computer who is vulnerable to this. Now that you know, the first thing you'll do it turn off your computer or find a way to protect yourself. If they hadn't released it, you could've been hit in the coming week or month or however long it takes Microsoft. As you can see, this isn't a black and white problem.
- tallanvor 10y agoHow does Google's disclosure allow people to protect themselves, though? They say to update Flash. Great, but that doesn't explain whether or not anything can be done to prevent the specific Microsoft vulnerability from being exploited if Flash isn't involved. So if Google doesn't have any way to mitigate the vulnerability, all putting these details out do is allow more actors the chance to use the vulnerability until Microsoft can release a patch, which is exactly the opposite of responsible.
- wstrange 10y agoThey can use Chrome, which mitigates the attack.