20 ms·
Google's policy is to release under 7 days if there's evidence of the bug being exploited. They told Microsoft and a date for the patch was set, I guess because
by NetStrikeForce 10y ago
Google's policy is to release under 7 days if there's evidence of the bug being exploited. They told Microsoft and a date for the patch was set, I guess because they follow processes to make sure they don't make it worse or break something else when patching. This is not "the old days", Microsoft's security track record is completely different.
I can't believe that you're (rhetorically) asking me for evidence when it's Google who makes decisions based on that evidence. It's vox populi now that only one actor was using it. Google knows it, you know it too. Why are you trying to move the goal posts with useless rhetoric?
How does publishing a bug with no patch available until a few days from now on make us safer? Especially when you don't want security companies to have a head start either. How are you going to protect your users then?
I don't know if your comment is just bait, but there's a difference between withholding bugs and being a responsible company. As far as I understand Microsoft gave Google a date that's not very far in time. If whoever made the decision to disclose it anyway can't see the difference (or a calendar, this is 2016, not 1996) then I give up.
Once the bug was discovered we need an urgent fix, disclosing the bug has prematurely expired any short time we had. There was no need for that. Why can't Google accept a patch date so close to their disclosure date and only disclose if the third party (Microsoft in this case) fails to deliver the patch?
You can ignore all the above, but let me know one thing: How are you protecting your user base from someone exploiting this bug? If you don't have any security products capable of detecting the exploit nor a patched OS. I'm curious and I'm sure I can learn from you (I'm not being sarcastic).
- EdHominem 10y ago> you don't want security companies to have a head start Right. I want the information that I can use, or get my team to use, rather than waiting for some company to distill it for us. I've worked in some of those companies so I don't have any illusions about them. > This is not "the old days", Microsoft's security track record is completely different. Only because they got nailed so many times. Security isn't their market discriminator so they'd rather ignore the issue and hope it blows over. We're factually better off than we were years ago, thanks largely to a liberal disclosure policy. > Once the bug was discovered we need an urgent fix, We urgently needed the fix beforehand. It's not 0 -> DANGER, it's N -> N+3, where N is not a small number. > Why can't Google accept a patch date so close to their disclosure date and only disclose if the third party (Microsoft in this case) fails to deliver the patch? Why can't Microsoft hurry this critical patch even if it means breaking its routine a little? I imagine Google didn't give much weight to their arguments, probably because of past experience. > How does publishing a bug with no patch available until a few days from now on make us safer? Knowing there's a landmine in my yard makes me safer even if it means I simply don't go in the lawn. And you can almost always figure out a mitigation strategy. At that, if there's a super-bug that's so bad no mitigation strategy can be devised, I'd rather know to turn my computers off until patch-day. > You can ignore all the above Ignore nothing. Acknowledged and refuted. > How are you protecting your user base from someone exploiting this bug? Not having a user-base of windows machines, and thus not having read about it, I couldn't say. I'd probably be able to just turn on the draconian policies that users would rebel against normally. But the point isn't an interview question about what I'd do, if alone at the helm, but what the entire internet could come up with. I'd wait a bit and copy that. If a security company came up with it, then good for them. But if not, good for us anyways.
- NetStrikeForce 10y agoI'll play game. > Right. I want the information that I can use, or get my team to use, rather than waiting for some company to distill it for us. I've worked in some of those companies so I don't have any illusions about them. You have it now, hope you're happy. How are you using it? > Not having a user-base of windows machines, and thus not having read about it, I couldn't say. I'd probably be able to just turn on the draconian policies that users would rebel against normally. > But the point isn't an interview question about what I'd do, if alone at the helm, but what the entire internet could come up with. I'd wait a bit and copy that. If a security company came up with it, then good for them. But if not, good for us anyways. Because there's nothing you can do!!! you're sold!!! there are companies with thousands of Windows seats. How can you just go and say "not having Windows users"? That shows very poor judgement and a seriously worrying detachment from reality. It also shows me you actually don't really give a shit about security and know nothing about the challenges in the real world. This disclosure and the kind of attitude shown on this thread are the two main reasons why the InfoSec industry stinks so hard. > Only because they got nailed so many times. Yes. Does it matter why though? When they were getting nailed I was probably shitting my diapers. Should I be judged now for what I was doing those years? > Security isn't their market discriminator so they'd rather ignore the issue and hope it blows over. Are you sure? I don't think you really know that Microsoft is these days a huge and (for many big companies) reliable security vendor. Compliance, tooling, innovation, products... They've got their hands on everything. They even help shutting down botnets. > Why can't Microsoft hurry this critical patch even if it means breaking its routine a little? Because it was not as critical until Google disclosed it. I'm baffled you can't see this. > I imagine Google didn't give much weight to their arguments, probably because of past experience. I think Google was just being strict about their policies. I don't think they've got prejudices. However, it is proven by your comments that you do have those prejudices and you're basing your opinion on them. Objectively we're not safer than before the disclosure. > Knowing there's a landmine in my yard makes me safer even if it means I simply don't go in the lawn. This shows poor understanding of the issue. This is not something you stumble upon while doing your daily menial tasks. If you'd like a silly comparison, this is like Google releasing blueprints to create super cheap surface to surface missiles because they were being used by a nation against another. Now they have weaponized any script kiddie out there. > And you can almost always figure out a mitigation strategy. At that, if there's a super-bug that's so bad no mitigation strategy can be devised, I'd rather know to turn my computers off until patch-day. Oh really? How? What's your mitigation strategy? What a sysadmin can do to mitigate this? If your answer is don't use Windows, which could be a good long term plan, you're again out of touch with reality. Remember, reality is not Silicon Valley. > Ignore nothing. Acknowledged and refuted. You're going to have to point me where you've refuted that we're not safer after weaponizing everyone. > But the point isn't an interview question about what I'd do, if alone at the helm, but what the entire internet could come up with. I'd wait a bit and copy that. If a security company came up with it, then good for them. But if not, good for us anyways. Holy shit. I hope I'm not using any of your products. This is not how you do security. I thought I was discussing with someone that took security seriously and that I could learn a thing or two (I can't call myself an expert, maybe a hobbyist); it does seem though you're in this conversation just because you like to stick it to Microsoft (or to the big guys, or whatever) and can't be objective about it. If you'd like to continue this conversation I'd like to ask you to tell me how can we be safer after the disclosure. How can I help my friends running small and medium businesses to protect themselves against the exploitation of this bug?