5 ms·
Apparently it was only exploited by a single state actor. Now anyone can exploit it. Thousands of small companies with no DPI are screwed up until the patch arr
by NetStrikeForce 10y ago
Apparently it was only exploited by a single state actor. Now anyone can exploit it. Thousands of small companies with no DPI are screwed up until the patch arrives.
Way to go, Google.
- CaptSpify 10y agoDPI? Anyone could have exploited it before. Now people know it's exploitable. I'm still on Google's side here (as much as it pains me to say it). Making the vuln known is the best course of action.
- EdHominem 10y ago> Thousands of small companies with no DPI are screwed They were anyways. > Apparently it was only exploited by a single state actor. We don't actually know that. In fact, it's amazingly unlikely. > Way to go, Google. Suck it up and use the vulnerability as an excuse to implement better procedures. It'll only be worse tomorrow...
- NetStrikeForce 10y agoAll the reports I've read point to only GRU using the exploit, which invalidates your comment completely. And the downvote I got.
- CaptSpify 10y agoThat's the only group that we knew were using it. It's extremely likely that other groups were using it too, but weren't caught.
- NetStrikeForce 10y agoSo we only had evidence of a state actor using it against its objectives. Now we can be sure everyone is using it because the bug is public. I think it is easy to understand why this has been a mistake. I believe a patch was announced for next week; what's the risk for the general population if only one actor knows the bug? What's the risk if everyone knows the bug? IMHO this hasn't made the general population safer, quite the opposite. Google doesn't want to wait for the scheduled fix? Then disclose the information to AV and security vendors and at least we have a headstart against general exploitation of the bug until the fix is out.
- EdHominem 10y agoNo. We did it that way in the old days and MS took years to patch bugs. Now nobody gives their excuses any weight and they manage (mostly) to keep up. > only had evidence of a state actor You have no evidence of it being used so it must not have been then. That's that. Lack of evidence is evidence, or something. > hasn't made the general population safer Oh, you have evidence of that? This is a bit of a paradox. Any given disclosure might make some people less secure, but a policy of rapid disclosure has made all of us vastly more secure. > Then disclose the information to AV and security vendors Oh great, give the data to companies who will then turn around and bill me to tell me what to block. And weeks later, not in the moment when I need it. Thanks a lot! But this also misses that these partial disclosures are usually still enough to tell someone skilled how to write the exploit, and it only takes one exploit being written. All it does is give a false sense of security. Withholding bugs is a useless idea that's exclusively harmful.
- NetStrikeForce 10y agoGoogle's policy is to release under 7 days if there's evidence of the bug being exploited. They told Microsoft and a date for the patch was set, I guess because they follow processes to make sure they don't make it worse or break something else when patching. This is not "the old days", Microsoft's security track record is completely different. I can't believe that you're (rhetorically) asking me for evidence when it's Google who makes decisions based on that evidence. It's vox populi now that only one actor was using it. Google knows it, you know it too. Why are you trying to move the goal posts with useless rhetoric? How does publishing a bug with no patch available until a few days from now on make us safer? Especially when you don't want security companies to have a head start either. How are you going to protect your users then? I don't know if your comment is just bait, but there's a difference between withholding bugs and being a responsible company. As far as I understand Microsoft gave Google a date that's not very far in time. If whoever made the decision to disclose it anyway can't see the difference (or a calendar, this is 2016, not 1996) then I give up. Once the bug was discovered we need an urgent fix, disclosing the bug has prematurely expired any short time we had. There was no need for that. Why can't Google accept a patch date so close to their disclosure date and only disclose if the third party (Microsoft in this case) fails to deliver the patch? You can ignore all the above, but let me know one thing: How are you protecting your user base from someone exploiting this bug? If you don't have any security products capable of detecting the exploit nor a patched OS. I'm curious and I'm sure I can learn from you (I'm not being sarcastic).