3 ms·
"First post" and it's relevant and useful. 3 hours old and -zero- noise. This is why I love HN. You avoided commenting on the substance of their position, th
by jjguy 16y ago
"First post" and it's relevant and useful. 3 hours old and -zero- noise. This is why I love HN.
You avoided commenting on the substance of their position, though. From your role as a security researcher, I suspect you're in the google camp. I'm close enough to a security researcher to agree, too -- but I also know my perspective is fairly clouded. How will the vendors respond?
I suspect Microsoft will be reasonable, although they'll pushback at the proposed default window of 60 days. Microsoft is in the singularly unique position of having a reasonably agile security team, matrixed across the product teams. The majority of other vendors (Adobe?) are still struggling to put even basic processes into place; they won't have a choice but to push back with vigor and fill the discussion with FUD.
I second your "congrats google" -- it is a clueful corporate move and inspires confidence in their corporate bureaucracy. But I'm skeptical on it's effectiveness.
- makmanalp 16y agoMaybe I'm raving mad but doesn't 60 days seem like forever? That's tons of time for anyone to write, test and release their exploit. What takes 60 days, unless you've screwed up something completely fundamental to how your software works (in which case you'd spend far more than 60 days anyway)?
- simonw 16y agoTesting the patch.
- alecco 16y agoAnd middle management meetings.
- jjguy 16y agoand sometimes it takes a while to understand the true nature of a bug. and sometimes the "right way" to fix something is unclear. and sometimes the fix straddles multiple components, managed by different teams. and sometimes "that guy" who knows the subsystem is off at Disneyland for two weeks. 60 days can pass very quickly, especially as the project and vulnerability complexity grows. It's a short enough window to put the vendor under time pressures from day one.
- JoachimSchipper 16y agoA company like Microsoft only releases new software rarely - e.g. in Microsoft cases, patches are bundled once a month. If you report a bug just before the bundle comes out, their earlier possible [1] response is ~35 days, anyway. [1] Of course, "possible" depends on how much pressure you put on them, which is the whole argument of the Full-Disclosure camp...