10 ms·
Google's Project Zero exposes unpatched Windows 10 lockdown bypass
- ge0rg 8y agoOriginal source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1514&q= https://bugs.chromium.org/p/project-zero/issues/detail?id=15...
- saagarjha 8y agoCould someone who’s more knowledgeable about how Windows works than I am provide a semi-technical explanation of how this works?
- campuscodi 8y agoYeah. It's not as severe as the article makes it seem. It's just a bypass in a very insignificant component for which you need 2-3 other vulns to exploit. I presume the editor just wanted to put an article out with Microsoft and Project Zero in the title, rather than analyze the actual flaw in the context of its severity.
- nabc45 8y agoA journalist lying. Not particularly noteworthy.
- ILikeConemowk 8y agoDidn't you get the memo? It's not lying, it's giving newsworthy events a "spin" and it totes OK and ethical, because everyone else does it and we're the good guys. /s
- pmyteh 8y agoThe press had many problems, but this isn't close to a lie. Sensationalistic? Maybe. But to accuse the journalist of lying is claiming that the article is (1) false, and (2) that the journalist knows it's false. They're big claims, not to be made as throwaway snark. A functioning (and honest) press matters, and this does it and ourselves no benefit.
- pjc50 8y agoThere is a lockdown mode which restricted which COM objects could be instantiated from .net code to a short whitelist. The whitelist is based on GUID. The lookup of GUID to actual binary is done through the registry. COM hosting implementations should check that the object they got is the one they asked for. Net doesn't. So if you can write to the registry you can escape the sandbox.
- foepys 8y agoDenying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 months to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could've cost Google's customers tens of millions in misplaced ad campaigns. 1: https://bugs.chromium.org/p/project-zero/issues/detail?id=1514#c3 https://bugs.chromium.org/p/project-zero/issues/detail?id=15... 2: http://www.tomanthony.co.uk/blog/google-xml-sitemap-auth-bypass-black-hat-seo-bug-bounty/ http://www.tomanthony.co.uk/blog/google-xml-sitemap-auth-byp...
- saagarjha 8y agoIt seems that the researcher was relatively happy with the outcome. They could have certainly gone public far earlier if they had chosen to do so.
- JumpCrisscross 8y ago> that could've cost Google's customers tens of millions in misplaced ad campaigns You're comparing an operating system security bug to advertisers' lives being made inconvenient.
- pookeh 8y agoYeah so? Both involve tons of money.
- annabellish 8y agoOne can have a material impact on people's security, and thus everything from financial stability to physical safety. The other results in some companies making less money via advertising than they otherwise would have. Both involve money, but let's not pretend that the more money involved, the more important something is.
- ocdtrekkie 8y agoA company being driven out of business by advertising practices, having to let their employees go, and merely hope they can find new jobs, certainly impacts their financial stability, and likely their physical safety.
- avttre 8y agoWhy 90 days? Why not 30, 14, or 7? Microsoft might have requested responsible disclosure for exploits affecting Windows, but what gave Google the right to set a deadline? I feel the 2 US companies have a friendly competition with each other which can help secure their systems.
- saagarjha 8y agoNobody has any right to set a deadline. The 90 days is merely Google being courteous.
- fintler 8y agoFor something installed on so many devices, 90 days seems like an incredibly tight timeframe to change anything.
- pg_bot 8y ago3 months is more than enough time if you care about your customer's privacy and security.
- s2g 8y agoYOu are talking about a very large, complex, mission critical, and incredibly widely used piece of software. If they mess up a patch it's a big deal. If they break systems, introduce further bugs, etc... 90 days to understand the problem, fix the bug, verify the fix, plan the release, get it out to customers. There is a lot of work involved in such a thing.
- pg_bot 8y agoCorrect there is a lot of work to be done. It is not 90 days worth of work. If you think that is not enough time, you need to raise your standards.
- 8y ago
- andrewguenther 8y agoTo people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn't going to help protect customers, what's the point in granting an exception? https://bugs.chromium.org/p/project-zero/issues/detail?id=1514#c3 https://bugs.chromium.org/p/project-zero/issues/detail?id=15...
- cesis 8y agoMy thinking would be exactly the opposite - severe bugs have to be disclosed sooner while non-severe can be left lingering around.
- eganist 8y agoAnd Google has actually had a track record of using that reasoning as well, so it's not like their words actually mean much. Great example of a drive-by high-sev exploit getting exposed long before Microsoft could patch: https://www.digitaltrends.com/computing/google-project-zero-publishes-microsoft-browser-zero-day-bug/ https://www.digitaltrends.com/computing/google-project-zero-... I appreciate the work they do, and I sure as hell appreciate the talent, but Google is mostly treating this entire endeavor as a giant marketing and recruiting trick. (It worked well; they stole my favorite pentester from one of my preferred boutique consulting firms.)
- lvh 8y ago“Long before Microsoft could patch” meaning when Microsoft decided to cancel a patch Tuesday? If Microsoft decided that the correct patch cadence was quarterly or annually (because so much QA work goes into a release), does that change what a disclosure deadline should look like? Also in the bug you’re referring to, Google expresses surprise Microsoft let it get through because of the severity, and declined to comment on details that would only help exploitation. I also don’t see anything on the bug re: will disclose _because_ sev:hi (your core argument AIUI); but I agree that it doesn’t really impact what their policy should be. You say Google’s words don’t mean anything, but it sounds like you’re advocating for their 90 day disclosure policy to not mean anything whenever a company doesn’t get its act together in time, which I’m sure isn’t your intention. P0 might have some of the best pentesters in the world (it does) but that doesn’t matter much if everyone else gets a ton more time to find and exploit bugs.
- dewiz 8y agoGoogle, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests
- ILikeConemowk 8y agoI would pay to see this happen. "Google, we believe in our user's right to privacy and are looking for ways to improve their experience on our platforms. Due to your non-compliance with the upcoming GDPR and past misdeeds we have classified all your services as spyware and will be protecting our users accordingly should you fail to address this matter in 90 days from now. Kisses, Microsoft."
- mtgx 8y agoI think you know why Microsoft won't do that. They do the same kind of tracking in Windows 10. They had an opportunity to actually hurt Google by blocking tracking scripts long ago with their "Do Not Track" feature enabled by default in its browser. And they wasted it by simply asking advertisers like Google nicely if they'd like to stop tracking users or not (you'll never guess what happened next!). Microsoft has already been found violating previous and less strict EU privacy laws recently. I think Google, Microsoft, Facebook, Amazon - they'll all end-up paying big fines in the EU within 18 months after the GDPR passes, because neither take it seriously enough and they still think they can use "angles" to trick the regulators as well as users into getting that data without real consent. They can't, and they'll learn it the hard way. Oh, and the Privacy Shield will likely fall by the end of the year, too. So brace yourselves, it's going to be a wild ride for these privacy violators.
- dvfjsdhgfv 8y agoOn an unrelated note, I think that's a really smart move on the part of the EU. Most of these companies do what they can not to pay taxes in Europe, and counteracting it is difficult without hurting other businesses or creating other kinds o bureaucracy. But with the GDPR, the EU can easily put million-dollar fees on these companies easily.
- nikic 8y agoThe only "dick move" involved here is the fact that zdnet wrote this article. Minor security issue lapses standard disclosure deadline? Who cares. Instead we get this attempt to sensationalize this into some kind of big Google vs. Microsoft rivalry.
- deleted 8y ago[deleted]
- finchisko 8y agoI think there are so many point of views here. I'm not going to defend Google nor Microsoft, but imagine you're paid by Google to work on security issues. What would be the metric to prove your existence, if there is no public awareness of your work, like this zdnet article? Project Zero IMO from time to time need to show they exists and doing great job. I think that could be one of reasons, why they resists to prolong standard 90 day period.
- lvh 8y agoI have a hard time thinking of a more elite team than P0. They earned their stripes long before they got there. The disclosure policy is the right thing to do, not to make someone feel better about their job.
- finchisko 8y agoIt's one of the points of view, not saying the most significant one.
- kerng 8y agoRead about the details. Wow, having a bug like this being discussed so broadly shines a bad light on Google IMHO. Its appears like targeted news against Microsoft. It's not mich newsworthy defense in depth issue. If an adversary can modify the registry, they can do a lot more harm.
- jacksmith21006 8y agoWhy does MS struggle so much with security?
- jiveturkey 8y agoWhy does everyone struggle so much with security?
- jacksmith21006 8y agoChromeOS been secure since the get go. Just seems weird Google can do it and MS struggles so much. Now you get GNU/Linux out of the box but security intact.
- hs86 8y agoAre you aware that ChromeOS comes without the GNU userland?
- iofiiiiiiiii 8y agoThey do not struggle - Microsoft have one of the more sensible and well functioning security organizations in the software world. This just is not a very important bug.
- bitmapbrother 8y agoGoogle reported the issue to Microsoft on January 19. Microsoft confirmed the issue about three weeks later Microsoft should make a mental note that when you receive an email from a member of Google's Project Zero team you don't wait 3 weeks to respond.
- bootloop 8y agoAnswering an email and confirming an issue is not really the same thing.
- wdr1 8y agoMicrosoft should attempt to verify issues quicker than 3 weeks, particularly when all details are provided?
- bitmapbrother 8y agoIf it takes 3 weeks to confirm an issue reported to you by a Project Zero team member, especially when they provide you a detailed report on how to replicate the exploit, then you need to optimize your process.