5 ms·
And _this_, ladies and gentlemen, is why we have disclosure deadlines for security vulnerabilities. For example, Project Zero expects vendors to fix security vu
by scarybeast 9y ago
And _this_, ladies and gentlemen, is why we have disclosure deadlines for security vulnerabilities. For example, Project Zero expects vendors to fix security vulnerabilities within 90 days of notification.
Looking at this story, it's possible that 90 days is almost too long and should be shortened. As time goes on, it's becoming more and more common for multiple parties to become aware of the same vulnerabilities. Not all of those parties have good intentions, as we see here. Shortening the window of exposure is key.
- nikanj 9y agoNext up on HN: extreme outrage after a botched security update breaks hundreds of millions of machines. Not all bugs can be fixed with a simple one-line fix, and the faster patches need to be cranked out, the lower quality they'll be.
- flukus 9y agoWell yeah, if a patch for a single application broke machines then the outrage would be deserved.
- geocar 9y agoOr maybe people stop shipping dogshit?
- bitexploder 9y agoThere was a simple settings change for a temp fix on this one too. When there is even a remote chance a bug is being exploited in the wild it needs to be disclosed. Corp IT can work around it almost always. Individuals can as well. This argument that "it's complex to patch" is a non-starter at best. We the users deserve the option to decide how to deal with it. Silent exploitation is how we all lose, even the vendor.
- BearGoesChirp 9y agoIn which case the users need to be informed of the security risks they are taking by using that software. Hiding risks is not the answer.
- grub5000 9y agoIt says it right in the article: > "We performed an investigation to identify other potentially similar methods and ensure that our fix addresses [sic] more than just the issue reported," Microsoft said through a spokesman, who answered emailed If MS had immediately patched CVE-2017-0199, only for someone to reverse the patch, discover an identical exploit somewhere else in the code and commence immediate abuse, people would crucify Microsoft. From the article, it seems clear that Microsoft scheduled a public release of the patch as soon as it became clear it was being publicly exploited.