4 ms·
Why 90 days? Why not 30, 14, or 7? Microsoft might have requested responsible disclosure for exploits affecting Windows, but what gave Google the right to set a
by avttre 8y ago
Why 90 days? Why not 30, 14, or 7?
Microsoft might have requested responsible disclosure for exploits affecting Windows, but what gave Google the right to set a deadline?
I feel the 2 US companies have a friendly competition with each other which can help secure their systems.
- saagarjha 8y agoNobody has any right to set a deadline. The 90 days is merely Google being courteous.
- fintler 8y agoFor something installed on so many devices, 90 days seems like an incredibly tight timeframe to change anything.
- pg_bot 8y ago3 months is more than enough time if you care about your customer's privacy and security.
- s2g 8y agoYOu are talking about a very large, complex, mission critical, and incredibly widely used piece of software. If they mess up a patch it's a big deal. If they break systems, introduce further bugs, etc... 90 days to understand the problem, fix the bug, verify the fix, plan the release, get it out to customers. There is a lot of work involved in such a thing.
- pg_bot 8y agoCorrect there is a lot of work to be done. It is not 90 days worth of work. If you think that is not enough time, you need to raise your standards.
- lawnchair_larry 8y agoPeople who think 90 days is not enough time don’t have insight into how long this actually takes and why it took so long. I don’t know where this meme came from but I know for certain that is not the reason that companies like Microsoft miss their deadlines.
- nurettin 8y agoDo you have any experience with complex systems where a security patch could possibly take more than three months to implement?
- oaiey 8y agoHe might have or not but I have. Not as complex but similar mission critical and distributed. 90 days is nothing as outlined. Once you go life or death situations, regulatory environment applies, backward compatability matters, ... Everything takes endless. It is not code, commit, test and deploy. Intake, Risk Analysis, project planning, approvals, alignments, etc. So many more processes. We should not fool ourselves that other platforms are better in that once you go for serious SLAs. Linux Kernel or user land patch might be fast, but RedHat delivery will take longer. Welcome to Enterprise development.
- Dylan16807 8y agoVery very little of enterprise is life or death, and windows is not suitable for life or death. When enterprise just falls on its face, I don't have much sympathy. "So many more processes" sounds like taking a handful of steps, splitting them up, and making each one require multiple days of memos back and forth. Can you provide any justification for this? Am I misreading?
- nurettin 8y ago>>Welcome to Enterprise development. That is assuming whoever you are replying to is foreign to enterprises.
- oaiey 8y agoIn that case - if you are not - congrats! Seems like you ended up in well organized places :)
- davidhakendel 8y agoI have that experience. Security patches take a long time. You need to ensure that mission critical operations are not impacted, that the private builds which had been supplied to customers are not impacted, that documentation gets updated, that laws and regulations are followed across the world and in specific regulated verticals, etc. Then customers need time to review the patches and follow through on their schedule of updating their devices.
- ge0rg 8y agoDon't forget that these 90 days are also 90 more days where this vulnerability can be exploited by attackers. Microsoft has set up a patch delivery infrastructure that's pretty effective and comparably fast by industry standards, if not deactivated by the people who got offended by the forced Windows 10 upgrade and feature creep.
- gmueckl 8y agoWell, Windows Update is forcing me to deactivate it in one machine bacause it continues to make it unusable. I have come to terms with most quirks of the forced updates, but in this particular situation Windows is nasty und uncooperative. Add to it Microsofts well established unwillingness to provide any useful diagnostic information and suddenly the only way to use the machine is to not update it.
- Laremere 8y agoPut another way: For something installed on so many devices, 90 days seems like an incredibly long time to leave so many devices vulnerable. Security fixes aren't a once and done thing. New exploits will be discovered that must be fixed. Missing deadlines for less severe exploits encourages getting better at sending security fixes out. Then, when more severe exploits are discovered, they can be patched in a reasonable amount of time. If extensions are always given, then deadlines become meaningless and "90 days" becomes "eh, 6 months given we can push for extensions."
- alkonaut 8y agoFor a bug that should take no more than a few days to patch and test 90 days seems like more than enough for a product with automatic security updates. For a bug with completely unknown scope and very difficult fixes (such as the recent intel issues) the story might be different. But 90 days here? Why would Microsoft need more than that?
- mjw1007 8y agoBecause of an "unforeseen code relationship", they say. What more could we want to know? It sounds like some other piece of MS software is relying on .NET not performing the checks that it should have been performing.
- smoyer 8y agoWindows attempt to always remain backwards compatible has left a huge tangled mess of dependencies. I applaud Microsoft's attempts at this but a slow cycle of breaking changes would allow a much better long-term system. Of course, that also means you have to be committed to some sort of long-term roadmap (something that appeared to be lacking between XP and Longhorn/Vista/7).
- thomasz 8y agoThe last time they did that was with the launch of vista. People were not pleased.
- lvh 8y agoIs Microsoft allowed to make arbitrary business decisions that prevent it from responding to security vulnerabilities or is backwards compatibility given a special pass? They own an operating system. We get to hold them responsible for whatever choices they make that impact security.
- Buge 8y agoThe right to freedom of speech means Google can say what they want when they want about the vulnerability, giving them the right to set a deadline. There are certainly companies doing much worse than setting 90 day deadlines. For example VUPEN, Hacking Team, and GrayKey selling undisclosed vulnerabilities to "good" governments, and other companies servicing the shadier governments[1]. [1] https://www.bloomberg.com/news/features/2017-01-18/the-post-snowden-cyber-arms-hustle https://www.bloomberg.com/news/features/2017-01-18/the-post-...
- pbhjpbhj 8y ago>The right to freedom of speech means Google ... Surely it means specific people employed by Google may "speak". Does the right extend to corporations?
- paddyoloughlin 8y agoCorporations are people. https://www.npr.org/2014/07/28/335288388/when-did-companies-become-people-excavating-the-legal-evolution https://www.npr.org/2014/07/28/335288388/when-did-companies-...
- protomyth 8y agoCorporations are made of people and you do not lose your rights because you form a corporation.
- pbhjpbhj 8y agoThat doesn't answer the question. Do corporations have the right to bear arms separate to the rights of the members of the corp - can Google keep an arsenal even if none of the people in it had a gun license?
- lawnchair_larry 8y agoKnowledge of where Microsoft forgot to enable a security check is not “bearing arms”. Imagine that world. I point out a mistake to you, and by reading or hearing it, you are suddenly holding a gun! We would have to criminalize coredumps :)
- lvh 8y agoWhat gives Microsoft the right to set the deadline? It’s their bug, and the bad guys aren’t going to stop using a bug because Microsoft has decided to be slow at patching.