15 ms·
Google Goes Public with Unpatched Microsoft Edge and IE Vulnerability
- thehardsphere 10y agoHow often do these deadlines get missed?
- JoshTriplett 10y agoAnd perhaps even more critically: by which vendors? Who consistently misses the deadline?
- brainfog 10y agoJudging by https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3ADeadline-Exceeded&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q..., it looks like Apple, Adobe and Microsoft are the main vendors who miss deadlines, although I don't know how many other vendors Project Zero focuses on in total.
- vorpalhex 10y agoThat doesn't terribly surprise me. More/larger products, more opportunity to miss bugs or not be agile enough to work on them.
- certifiedloud 10y agoI guess when they say 90 days they really mean it.
- ErikAugust 10y agoProject Zero is taking names lately. I wonder if other firms will "retaliate" with their own Project Zero-style security teams.
- andreyf 10y agoThat's the kind of retaliation I can get behind whole-heartedly :-)
- ErikAugust 10y agoYeah, there would likely be a real net-positive to corporations trying to damage each other's credibilities via security disclosures. (No sarcasm - I believe it).
- xs 10y agoUnless, the retaliation is done by the NSA where they don't want any more of their precious 0 days getting leaked.
- CobrastanJorji 10y agoNSA guy #1: "Hey, Fred, Google released another Microsoft zero day. Those things cost us millions to buy. Can we punish Google somehow?" NSA guy #2: "Sure, let's release our Google zero day!" #1: "Oh, but didn't we spend millions on that?" #2: "Yeah, but it'll really screw up Google!" #1: "Okay, do it." Google: "Oh my, thanks for pointing out that exploit. We're so glad the NSA is getting back to its mandate to alert American companies and organizations when it had identified security holes. And....fixed. Let us know if you find any more!"
- bitmapbrother 10y agoThanks NSA! Where do you want us to send the bounty award to?
- user5994461 10y agoNo need, it's already been debited from your account.
- 10y ago
- andreyf 10y agoThis is not the first time Google has disclosed unpatched vulns in Microsoft product [1]. Anyone know any more? What's up with them not being able to patch on time? How is 90 days not enough to get a patch out the door? That's a quarter, for goodness' sake! 1. https://news.ycombinator.com/item?id=12841672 https://news.ycombinator.com/item?id=12841672
- mtgx 10y agoTo make matters worse, Microsoft has just completely skipped this month's patch bundle. As in no other security bug will be fixed until next month.
- DangerousPie 10y agoPresumably these two facts are related? I would assume this was supposed to get patched this month within the 90 day deadline but some last minute issue delayed the patch.
- mtgx 10y agoThey probably are. However, I also expect them to be related because of Microoft's own decisions of integrating security patches with one another, instead of keeping them more modular: the so called "patch bundle" policy. It's hard to believe that say some Flash bug couldn't be patched because of some other unrelated bug. But I hope Microsoft can prove me wrong and explain in detail next month why it couldn't deliver any of the 20-30+ bug patches because of a couple of other unrelated and broken patches.
- mrpippy 10y agoThey still release "out-of-band" patches for critical security bugs. There was one a few days ago for Flash Player that presumably would have been in February's patch bundle but was too important to wait for the next one.
- ocdtrekkie 10y ago
- nunez 10y agoI'm glad they aren't playing around with the 90 day limit.
- mtgx 10y agoThey actually have a 14-day grace period now, but only if the vendor says it has a patch that's almost ready to go (and can be deployed within that 14-day period). So I guess Microsoft missed both of those deadlines.
- dpark 10y ago> So I guess Microsoft missed both of those deadlines. No. It was 90 days from the time the bug was filed to the time it automatically disclosed. There was no additional 14-day period (for whatever reason).
- scarybeast 10y agoThere is always an additional 14-day period on offer, but the vendor has to choose to use it, and has to actually land the patch within the 14 extra days. So, a deadline miss is often really a 104 (!!) day deadline miss. As an industry that's trying to refocus on security, surely we can do better than that.
- actuator 10y agoI think OP meant that Microsoft missed the deadline by not even having the fix ready that would have earned them the 14 day grace period.
- Heliosmaster 10y agoor they did not communicate anything to P0
- qeternity 10y agoThe grace period isn't automatic, otherwise that would just be a 104 day window. The grace period applies when the vendor has been in communication with P0 that a patch is in the works and will be released within 2 weeks of the end of the 90 day window. Presumably that didn't happen here.
- rattray 10y agoLooks like they thought this would get fixed: > I will not make any further comments on exploitability, at least not until the bug is fixed. The report has too much info on that as it is (I really didn't expect this one to miss the deadline). Worth mentioning that "Goes Public" implies there was a human who pulled the trigger; it was a bot: > This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public. ... > Deadline exceeded -- automatically derestricting
- muthuraj57 10y ago> there was a human who pulled the trigger; it was a bot: is it a human or a bot?
- roflc0ptic 10y agoGP is saying "although the headline makes it sound like a human did this, it was actually a bot, as the following text from the tracker shows:"
- ProAm 10y agoA human programmed the bot.
- samstave 10y agoBut the bot pulled the trigger :-)
- PascLeRasc 10y agoYou might like The Office (US) S8E6.
- mnem 10y agoA bot.
- 10y ago
- rattray 10y agoHow is Microsoft's track record on security generally these days?
- mtgx 10y ago> Windows 10 was found to have the highest proportion of vulnerabilities of any OS (395), 46% more than Windows 8 and Windows 8.1 (265 each). https://www.avecto.com/news-and-events/news/94-of-critical-microsoft-vulnerabilities-mitigated-by-removing-admin-rights/ https://www.avecto.com/news-and-events/news/94-of-critical-m... Umm, not that great. Whatever security features they are adding to Windows 10, they seem to be overshadowed by all the other crap they're putting in Windows 10.
- SomeStupidPoint 10y agoThat's for vulnerabilities found in 2016 though, right? It would make sense that more are found in W10 (which was 5-17mos in 2016) than W8 (which was 40-52mos in 2016), because of their relative time on the market. To answer the question, we'd have to look at W10 at this point in its life-cycle compared to W8 at a similar point (and control for things like more active vuln researchers).
- rattray 10y ago(I think you meant to reply to the parent)
- ksk 10y agoWhether or not Windows 10 is secure, I don't consider that report to be representative of the OS itself. Literally the first 5 "windows" bugs I clicked on were adobe vulnerabilities.
- rickycook 10y agonot that i'm saying that this is the case for the adobe vulnerabilities, but in practical terms the ecosystem is pretty tightly coupled to "the OS" when it comes to security. if your OS needs a ton of cruft bolted onto it to make it useful, and that cruft has security issues then compare that to an OS that doesn't need that cruft, or has a more security software ecosystem. for example, adobe reader vs macos preview. ecosystem is hard to change, and not entirely the fault of the owners/developers/etc of the software, but it's still important
- doggydogs94 10y agoI figure it is a slow news day for Google so they do one of these to generate some publicity.
- johnsmith21006 10y agoGoogle owns a decent chunk of CloudFlare. They shared the flaw as they should last week. I see nothing close to Google trying to get MS. Instead it is what should be done. Mow me with things like Scrougle and MS replaced YouTube as with their own i probably would not be so nice. Look at Amazon will not allow Chromecast to be sold on their site. Personally i would have removed Amazon from their search engine but not Google. Look at Uber. If i was Google i would use my power to destroy but not Google. Feel how ever you want about Google but let's at least be fair.
- ErikAugust 10y agoUber is being sued by Google.
- adventured 10y agoThey should be sued. The theft of corporate property that occurred was serious. In that scenario, Uber is not the victim.
- ErikAugust 10y agoI don't disagree.
- imajes 10y agoTechnically, it's not. It's being sued by a sister company, both owned by the shared parent 'Alphabet'. Whether there is collusion or not, they are theoretically separate entities.
- plandis 10y agoWas Microsoft even notified about this? I didn't see any indication on the linked page.
- euyyn 10y agoCan we have the title of the post conform more to that of the thing it links to?
- lawnchair_larry 10y agoThe original title is completely meaningless without context. It's linking to a bug tracker. I would say that this title is neutral, descriptive, and appropriate.
- euyyn 10y ago> The original title is completely meaningless without context. That's why I said "conform more".
- ipsin 10y agoThe bug doesn't make it clear; was this issue reported to Microsoft? I wasn't sure if I missed a sign of notification, or if vendors are automatically cc'd/whitelisted on restricted bugs for their products.
- JepZ 10y agoIs it normal that IE and Edge bugs are getting reported to the chromium bug tracker?
- mcintyre1994 10y agoI think project zero at Google use the Chromium bug tracker - maybe Google use it for all public bug stuff? I'm not sure why Chromium and not something more general though.
- christop 10y agoQuite a few projects have issue trackers hosted on that hostname: https://bugs.chromium.org/hosting/ https://bugs.chromium.org/hosting/ I believe those projects switched to using this instance of the Monorail bug tracker since Google Code shut down.
- akaij 10y agoAll of those projects are related to Chrome/Chromium, and maybe P0 is a part of the same team, all under @laparisa? http://www.googblogs.com/why-attend-usenix-enigma-2/ http://www.googblogs.com/why-attend-usenix-enigma-2/ here you can see her introducing Ben Hawkes.
- christop 10y agoI don't think that they're all related. Gerrit, for example, isn't part of Chrome; it was initially developed for Android, AFAIK. Nor is Monorail. I think Breakpad even predates Chrome. But it's quite likely they all had their bug trackers on Google Code.
- george_ciobanu 10y ago"Project Zero's disclosure deadline policy has been in place since the formation of our team earlier in 2014. It's the result of many years of careful consideration and industry-wide discussions about vulnerability remediation. Security researchers have been using roughly the same disclosure principles for the past 13 years (since the introduction of "Responsible Disclosure" in 2001), and we think that our disclosure principles need to evolve with the changing infosec ecosystem. In other words, as threats change, so should our disclosure policy. On balance, Project Zero believes that disclosure deadlines are currently the optimal approach for user security - it allows software vendors a fair and reasonable length of time to exercise their vulnerability management process, while also respecting the rights of users to learn and understand the risks they face. By removing the ability of a vendor to withhold the details of security issues indefinitely, we give users the opportunity to react to vulnerabilities in a timely manner, and to exercise their power as a customer to request an expedited vendor response." From https://www.engadget.com/2015/01/02/google-posts-unpatched-microsoft-bug/ https://www.engadget.com/2015/01/02/google-posts-unpatched-m...
- user5994461 10y ago> On balance, Project Zero believes that disclosure deadlines are currently the optimal approach for user security You mean, like when they disclosed the cloudflare vulnerability after about a week and then the web turned into a race to whomever could find older-than-a-week cache with valuable information.
- govg 10y agoThere was a discussion on this in the report itself; the vulnerability was far too huge for it to go undisclosed for 90 days, I believe.
- forgot-my-pw 10y agoAnd it was disclosed after the Cloudflare announcement, IIRC
- Buge 10y ago
- lettersdigits 10y ago> This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public. Is this a common pattern in the bugs world ? publicizing a critical bug after 90 days of no response ?
- Ajedi32 10y agoNot sure about 90 days specifically, but as far as the general principle goes, yes: https://en.wikipedia.org/wiki/Responsible_disclosure https://en.wikipedia.org/wiki/Responsible_disclosure
- jwilk 10y agoPlease use the original title.
- ClassyJacket 10y ago"Microsoft Edge and IE: Type confusion in HandleColumnBreakOnColumnSpanningElement" ? This really isn't a useful headline. It provides no information about the actual relevant event of Google releasing the bug. It just seems like any mundane bug report.
- jwilk 10y agoThe original title is not great, but it's good enough. Editorializing titles is against HN guidelines.
- Havoc 10y agoAs undemocratic-y as it sounds these big corps should really talk to each other more...