4 ms·
All the reports I've read point to only GRU using the exploit, which invalidates your comment completely. And the downvote I got.
by NetStrikeForce 10y ago
All the reports I've read point to only GRU using the exploit, which invalidates your comment completely. And the downvote I got.
- CaptSpify 10y agoThat's the only group that we knew were using it. It's extremely likely that other groups were using it too, but weren't caught.
- NetStrikeForce 10y agoSo we only had evidence of a state actor using it against its objectives. Now we can be sure everyone is using it because the bug is public. I think it is easy to understand why this has been a mistake. I believe a patch was announced for next week; what's the risk for the general population if only one actor knows the bug? What's the risk if everyone knows the bug? IMHO this hasn't made the general population safer, quite the opposite. Google doesn't want to wait for the scheduled fix? Then disclose the information to AV and security vendors and at least we have a headstart against general exploitation of the bug until the fix is out.
- EdHominem 10y agoNo. We did it that way in the old days and MS took years to patch bugs. Now nobody gives their excuses any weight and they manage (mostly) to keep up. > only had evidence of a state actor You have no evidence of it being used so it must not have been then. That's that. Lack of evidence is evidence, or something. > hasn't made the general population safer Oh, you have evidence of that? This is a bit of a paradox. Any given disclosure might make some people less secure, but a policy of rapid disclosure has made all of us vastly more secure. > Then disclose the information to AV and security vendors Oh great, give the data to companies who will then turn around and bill me to tell me what to block. And weeks later, not in the moment when I need it. Thanks a lot! But this also misses that these partial disclosures are usually still enough to tell someone skilled how to write the exploit, and it only takes one exploit being written. All it does is give a false sense of security. Withholding bugs is a useless idea that's exclusively harmful.
- NetStrikeForce 10y agoGoogle's policy is to release under 7 days if there's evidence of the bug being exploited. They told Microsoft and a date for the patch was set, I guess because they follow processes to make sure they don't make it worse or break something else when patching. This is not "the old days", Microsoft's security track record is completely different. I can't believe that you're (rhetorically) asking me for evidence when it's Google who makes decisions based on that evidence. It's vox populi now that only one actor was using it. Google knows it, you know it too. Why are you trying to move the goal posts with useless rhetoric? How does publishing a bug with no patch available until a few days from now on make us safer? Especially when you don't want security companies to have a head start either. How are you going to protect your users then? I don't know if your comment is just bait, but there's a difference between withholding bugs and being a responsible company. As far as I understand Microsoft gave Google a date that's not very far in time. If whoever made the decision to disclose it anyway can't see the difference (or a calendar, this is 2016, not 1996) then I give up. Once the bug was discovered we need an urgent fix, disclosing the bug has prematurely expired any short time we had. There was no need for that. Why can't Google accept a patch date so close to their disclosure date and only disclose if the third party (Microsoft in this case) fails to deliver the patch? You can ignore all the above, but let me know one thing: How are you protecting your user base from someone exploiting this bug? If you don't have any security products capable of detecting the exploit nor a patched OS. I'm curious and I'm sure I can learn from you (I'm not being sarcastic).
- EdHominem 10y ago> you don't want security companies to have a head start Right. I want the information that I can use, or get my team to use, rather than waiting for some company to distill it for us. I've worked in some of those companies so I don't have any illusions about them. > This is not "the old days", Microsoft's security track record is completely different. Only because they got nailed so many times. Security isn't their market discriminator so they'd rather ignore the issue and hope it blows over. We're factually better off than we were years ago, thanks largely to a liberal disclosure policy. > Once the bug was discovered we need an urgent fix, We urgently needed the fix beforehand. It's not 0 -> DANGER, it's N -> N+3, where N is not a small number. > Why can't Google accept a patch date so close to their disclosure date and only disclose if the third party (Microsoft in this case) fails to deliver the patch? Why can't Microsoft hurry this critical patch even if it means breaking its routine a little? I imagine Google didn't give much weight to their arguments, probably because of past experience. > How does publishing a bug with no patch available until a few days from now on make us safer? Knowing there's a landmine in my yard makes me safer even if it means I simply don't go in the lawn. And you can almost always figure out a mitigation strategy. At that, if there's a super-bug that's so bad no mitigation strategy can be devised, I'd rather know to turn my computers off until patch-day. > You can ignore all the above Ignore nothing. Acknowledged and refuted. > How are you protecting your user base from someone exploiting this bug? Not having a user-base of windows machines, and thus not having read about it, I couldn't say. I'd probably be able to just turn on the draconian policies that users would rebel against normally. But the point isn't an interview question about what I'd do, if alone at the helm, but what the entire internet could come up with. I'd wait a bit and copy that. If a security company came up with it, then good for them. But if not, good for us anyways.