3 ms·
This is flawed reasoning, as the vast majority of people will defend against it by installing the patch.
by besselheim 10y ago
This is flawed reasoning, as the vast majority of people will defend against it by installing the patch.
- Oletros 10y agoWhat patch?
- besselheim 10y agoThe future patch that Google should have coordinated their disclosure with.
- Oletros 10y agoSo, there is no patch. And the only mitigating thing is what Google has said, patching Flash. Now, tell me, how users would know about that without disclosing. And, remember, there are already exploits
- besselheim 10y agoThe problem is that Google also said this: > The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD. Which is enough information for someone to write an exploit from scratch. If they'd just said there is a win32k.sys vulnerability and advised users to make sure Flash is up to date, this would have been fine.
- protomyth 10y agoI'm starting to believe the base problem is a difference between a software company that has to test the heck out of every patch because of their large customer base (Microsoft) and a company that doesn't have a complete consumer facing experience[1] (Google). Seven days is not enough to patch anything that needs to be tested in the extensive manner required. An update / disable Flash would have been good enough until a proper patch on the day IT has planned (Patch Tuesday) activities around the deployment of patches. I'm starting to think the ultimate PC OS for IT would be one with a transactional audit trail on all changes to the PC. 1) try calling Google about a problem if you disagree with this statement
- fulafel 10y agoWell, here we get to the eternal debate about whether this trumps other considerations. Back before vulnerability researchers started putting credible deadlines to these things, vendors would sit on patches for months while the vulnerabilities were being exploited widely and were open secrets. A rough consensus seems to be that the common good is best served by these disclosure deadlines. Also there's the consideration that security-critical environments who pay attention these have much more value-at-risk than the average Windows user. You want your safety critical systems who pay attention to be protected.
- besselheim 10y agoI don't think this is the case here though. It's been a few days since reporting the vulnerability, not months. We don't yet know if this was being widely exploited (versus being a niche exploit used by an APT, for example), but it will be now either way.