6 ms·
Why does Microsoft not find and instead Google? MS is not a startup and it is their code. Seems weird that Google has to fine their issues. What does this
by johnsmith21006 10y ago
Why does Microsoft not find and instead Google? MS is not a startup and it is their code. Seems weird that Google has to fine their issues.
What does this say about using Google software versus software from Microsoft? Or am I missing something obvious?
- devopsproject 10y agoYou are expecting Microsoft to test a nearly infinite number of variables to find every flaw. This is not a reasonable position.
- davidgerard 10y agoHowever, the question is "if Google can find this, why couldn't Microsoft?" Which is an entirely reasonable question. Your statement would also make it unreasonable for Google to be able to find this stuff, but we have existence proof that that's not the case.
- deleted 10y ago[deleted]
- trentmb 10y agoMaybe a better way to frame it is that Google happened to find it.
- Navarr 10y agoThe biggest threat to security by obscurity: Google happening to find things.
- devopsproject 10y ago> However, the question is "if Google can find this, why couldn't Microsoft?" Which is an entirely reasonable question. His position is absurd. Microsoft could have found it. The thing stopping them is the incredible number of tests you would need to perform to find them all.
- komali2 10y agoWhy did that stop them, and not Google? I feel like you're refusing to address the main point here - google found this bug. It happened. They told Microsoft about it, and Microsoft hasn't fixed it 100% yet.
- devopsproject 10y agoNo one is denying that google found the bug. No one is denying that microsoft didn't fix it. The OP asked why Microsoft didn't find this first. The answer is too many things to test. The entire premise of the argument is insane. If microsoft had a viable way to test ALL of the their products for ANY problem, don't you think they would be doing that?
- deleted 10y ago[deleted]
- wmil 10y agoThey really should have, but this is understandable. Old vector formats are always a security nightmare - The original parsers / renderers where written on single user systems and focussed on rendering speed. They didn't anticipate hostile files. - The original developers are long gone. - EMF files were never popular on websites. I would argue that their real mistake was adding EMF / WMF support to IE in the first place. It made sense to developers because it was only a few lines of code, but it was a terrible decision for security.
- shawnz 10y agoEMF/WMF is especially bad because it is basically just a command language that gives direct access to GDI syscalls. It should just be considered excutable.
- tinus_hn 10y agoFor a large part this is really old, badly written code that is scary to clean up because the functionality is underspecified. A lot of programs that Microsoft wants to continue working depend on weird features in it.
- TeMPOraL 10y agoGoogle seems to have embarked on a mission to find vulnerabilities in everything that touches the Internet. Good for them (free marketing), good for us. Forming an opinion about Microsoft vs. Google software quality would require knowing how many similar problems Microsoft found and subsequently patched in their software. Without that data, we can't tell whether Microsoft isn't putting effort into finding vulnerabilities in its software, or whether Google simply got lucky and found something Microsoft missed.
- digi_owl 10y ago> Google seems to have embarked on a mission to find vulnerabilities in everything that touches the Internet. Good for them (free marketing), good for us. And perhaps scaremongerings us to embrace the cloud, and thus ChromeOS...
- j_s 10y agoIn this specific case, this is a valid question: this is round 2 after MS already got the notification they need to fix this issue. Google is back with a specific proof-of-concept after giving Microsoft a high-level description of how to find and fix this vulnerability. As part of MS16-074, some of the bugs were indeed fixed, such as the EMR_STRETCHBLT record, which the original proof-of-concept image relied on. However, we've discovered that not all of the DIB-related problems are gone.
- charonn0 10y agoCompanies tend not to publicly brag about it when they find bugs in their own code.