14 ms·
Google Researcher Publishes Windows 10 Zero-Day Security Vulnerability
- Operyl 7y agoHis Twitter thread about it, complete with the usual complaining about the 90 day policy from the gallery: https://twitter.com/taviso/status/1138469651799728128 https://twitter.com/taviso/status/1138469651799728128 (I think the policy is fine, personally).
- PeekPoke 7y agoOrmandy being a cock again? Quelle surprise...
- dang 7y agoPersonal attacks aren't ok here. Would you mind reviewing the site guidelines? https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- michaelt 7y ago"Personally I think it's a bit harsh," Wright says, "every fix is different and they should allow for some flexibility in their deadline." As far as I can tell, (1) this is a denial-of-service bug, not a privilege escalation or remote root exploit, i.e. a low-severity bug; (2) it is unlikely any code depends on the infinite loop triggering, meaning this fix doesn't call for great architectural upheval; and (3) the deadline was already extended to 91 days, rather than the usual 90. If you'd give out deadline extensions for this bug you'd give them out for almost any bug, so you may as well not have deadlines at all.
- nocturnial 7y agoFor anyone wondering why the one (1) day extra, microsoft has a fixed patching schedule. The patches were released on june 11 patch tuesday. They needed the extra day to check if it was included in the june 11 patches.
- gpm 7y agoDoes anyone else think that microsoft's policy here is ridiculous? "We know your stuff is broken to the point of being insecure and a risk to your business because we screwed up when making it. We know how to fix it. We've done the work to fix it. No we won't actually fix it until a few days from now.
- CGamesPlay 7y agoNo. If you sold cars and realized that there were some buttons you could push on the AC unit that would cause it to catch fire, you wouldn’t remotely shut off my car to perform the repairs while I was driving down the highway. The customers who “need” patches have a business to run, and forcing their computer to reboot in the middle of the workday for some service that may not be exposed at all on their network would be a good reason to avoid Microsoft products for said customer.
- cf498 7y agoAre there actually businesses who just use the normal windows updater? (Ignoring smaller businesses without IT departments for a second). I assumed the forced patching at boot/reboot was a consumer version thing? A unforeseen update from microsoft can just shut down your business?
- CGamesPlay 7y agoThe same line of reasoning applies to IT departments as well, though. If you force corporate IT departments to spend all their time installing your daily updates, the cost of ownership of your product for the company goes way up and the department heads will start looking for cheaper alternatives. Exceptions could surely be made for critical vulnerabilities, especially those being exploited in the wild, but this is a low-severity DoS. As another commenter said, if you made this an off-schedule hotfix you would have to do it for basically every bug.
- technion 7y agoWhilst servers are in a different category, multiple Windows Updates have changed the way updates work. Look at the Dual Scan situation[0]. People who had central management applied one update and suddenly found desktops also accepting updates from the Internet. Then you've got the fact that "Professional Edition" was once a perfectly fine solution for businesses, but suddenly the ability to properly control updates like you suggest required Enterprise Edition. These aren't the only issues. There's always someone who points out that if you have basically unlimited free time you can stay on top of all of it, but at the end of the day a lot of businesses still find surprise updates happening. I just got a sales call for a third party business product with the tagline "Disable Updates automatically applying (Yes, REALLY!)" as a listed feature. Finally you can top it all off with the BYOD trend, where people often expect to run their own machines without management software. [0] https://www.thewindowsclub.com/dual-scan-windows-update https://www.thewindowsclub.com/dual-scan-windows-update
- adrianmonk 7y agoIt's just game theory. You have to have follow through, or people will learn that they can ignore you. Although the ethics are very different, think of a loan shark. What do they get out of breaking the kneecaps of a person who failed to pay their debt? It doesn't bring back the lost money. But it does show you are committed to following through with consequences. And that changes the behavior of people who might face those consequences.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- MattSteelblade 7y agoThe bug report https://bugs.chromium.org/p/project-zero/issues/detail?id=1804 https://bugs.chromium.org/p/project-zero/issues/detail?id=18...
- altmind 7y agoSeems to be a DoS against the application using cryptoapi. certutil <cer> seems to hang but can be killed without negative effects on the system. Ant timeouts in cryptoapi ops will prevent this. According to the report: Severity-low I'm really dont think forbes is a good media for publishing the digest like this - the public there is very broad and dont have the expertise to evaluate what've been presented.
- olliej 7y agoIt's not a zero day, it's a 91 day. Some bugs can be complex to do root cause, fix, and verify a bug. But 3 months for what appears to be a validation failure seems more than sufficient. Obviously we'll need to wait until the actual fix comes out to see if the fix was more substantial.
- _wmd 7y agoI've been around infosec for 21 years and this is still a 0day. That term has no strong definition, certainly not one that would allow precise interpretation as above, but in this case even a vague sense of what it means covers the situation easily: _users_ have had no time to patch
- olliej 7y agoZero day is almost always used in the context of “the bug was unknown and first seen during an attacks”. The alternative definition (that zero day means purely day of publicizing) would mean that if you had two bugs in a product and you notified the vendor of one. Then three months later published both, they would both be zero days, and should be treated as such. A 0day means publicizing a bug without the vendor themselves having the potential to have a fix. Very simply: if a virus comes out attacking a known but unfixed bug in MS software no one would call it a zero day. Every article would say it was a bug that Microsoft knew about but hadn’t fixed.
- Godel_unicode 7y agoAs GP said, lots of people use this amorphous term differently. Antivirus company ESET, for one, explicitly disagrees with your example: '...The name “zero-day” comes from the fact that no patch yet exists to mitigate the vulnerability being exploited.' https://www.welivesecurity.com/2015/02/11/security-terms-explained-zero-day-mean/ https://www.welivesecurity.com/2015/02/11/security-terms-exp...
- all_blue_chucks 7y agoCan confirm. "Zero day" means you've had zero days to patch. The term has been used this way since, IIRC, the late 1990s. See Phrack 53 for an example: http://www.textfiles.com/magazines/PHRACK/PHRACK53 http://www.textfiles.com/magazines/PHRACK/PHRACK53
- teh_klev 7y agoTavis Ormandy....sigh. As a hoster I truly despise this individual. Back in the dying days of Windows 2003 he did the same thing. We still had a small fleet of 2k3 servers on extended maintenance in our shared hosting environment. This prick saw fit to release details on a "zero day" after 90 days which caused us some serious pain and major loss of business. Sure MS should have moved faster to plug the hole, but you know, Windows is a helluva legacy code base, but this arrogant ass-hat still saw fit to effectively fuck us and a few other UK hosters by releasing the exploit details. Literally within 48 hours these boxes were pwned (via insecure/broken versions of Wordpress and other shit code agencies write - sadly as a shared hoster you simply can't control what 2000 users do on their shared hosted sites with PHP and ASP). It was a privilege escalation exploit, goddamn nothing we could do to prevent this. Ok, I get the "security through obscurity" argument, and that we shouldn't hide these exploits, but at that time there were no known exploits in the field....until Tavis told the world. He's got a chip on his shoulder about Microsoft and their past security practices (fair enough, I have too), but he seems to not give a shit about the impact of releasing a zero day, that perhaps only he knows about, on businesses trying to earn a crust. Not very responsible. Sorry for the bad language, but when you've been up for five days solid fire fighting this type of crap my respect for the likes of Ormandy (and MS for not moving fast enough) kinda goes out of the window. I expect many to disagree and perhaps revel in disrupting MS's platform, but there's a social and moral responsibility. What good does it do to release these exploits after some arbitrary amount of time Ormandy and crew have decided when it's likely only them at that time who understand them. Businesses live and die sometimes by these decisions, and the impact on their staff can be catastrophic.
- icelancer 7y agoI feel for your acute pain in the past, but: >> but he seems to not give a shit about the impact of releasing a zero day, that perhaps only he knows about, on businesses trying to earn a crust. Not very responsible You are ignoring the impact of constantly extending deadlines for companies that don't take security seriously within 90 days of notification. At some point, there must be consequences as a negative feedback signal to show that you mean business and won't just constantly push these back until you fix your negligence. The Project Zero guidelines must have teeth. And they do. And it causes acute pain, and they know it. It is to spur companies on to do the right thing. Without open disclosure first without time-barred restrictions, we never would have settled on "responsible disclosure" with embargoes and such. Companies and organizations need to know they will be held accountable.
- ClassyJacket 7y ago"As already mentioned, Project Zero has a 90 day disclosure deadline and this was applied to this vulnerability. It was first reported by Ormandy on March 13, then on March 26 Microsoft confirmed it would issue a security bulletin and fix for this in the June 11 Patch Tuesday run." How is that a zero day? Isn't it a 91-day? What is the meaning of zero day in this context if there were actually 91 days between reporting to Microsoft and public release?
- anaisbetts 7y agoUsers / IT Admins got zero-day'd, Microsoft didn't
- masklinn 7y agoSo not a zero-day.
- ghusbands 7y agoWords are used to communicate, and language is fluid and changes over time. Clearly, zero-day is being used and understood by many to mean simply "unpatched", and so that is a reasonable definition. If ever you're arguing that a significant proportion of people are using language incorrectly, you're probably on the wrong side of history.
- deleted 7y ago[deleted]
- boringuser1 7y agoLots of people pretending Google has Microsoft's best interests at heart.
- CydeWeys 7y agoWhere is this happening?
- brynet 7y agoLately OpenBSD has been consistently pushing out new security errata, with as quick as a ~3 day turnaround from finding/reporting to released fix, even for difficult issues; like Intel MDS. If OpenBSD can do that, why can't Microsoft.
- xyzzyz 7y agoBecause if OpenBSD pushes out broken patch, nobody will care, as this is business in usual in free software world, shit breaks, WITHOUT ANY WARRANTY and all that. On the other hand, if Microsoft does that, customers paying millions of dollars will get pissed. That said, 100+ days to push out a patch is indeed ridiculous.
- brynet 7y agoExcept OpenBSD isn't shipping broken patches.. so I'm struggling to see your point. There's a pretty substantial difference between 3 days and 90 days (or 100). And one could argue that any amount of days after the embargo ends, is plenty opportunity for their paying customers to remain vulnerable without having provided any fixes, regardless of whether it is broken or not.
- JamesBarney 7y agoI imagine Microsoft has a much longer test cycle than openbsd.
- yjftsjthsd-h 7y agoThat... Sounds like their problem. Like, I get that they have way more api surface, legacy code to support, etc... But they have a budget and manpower to match. If they can't test changes, that's their fault.
- JamesBarney 7y agoI think it's vastly easier to use budget and manpower to increase the scope of testing than it is to speed it up.
- noname120 7y agoCan we change the link to the original source[1]? The current article[2] is sensationalized and contains inaccuracies. [1] https://twitter.com/taviso/status/1138469651799728128 https://twitter.com/taviso/status/1138469651799728128 [2] https://www.forbes.com/sites/daveywinder/2019/06/12/warning-windows-10-crypto-vulnerability-outed-by-google-researcher-before-microsoft-can-fix-it/ https://www.forbes.com/sites/daveywinder/2019/06/12/warning-...
- helper 7y agoTavis didn't write the bug he just found it (through a lot of hard work). This was free security research given to Microsoft. He gave them a very reasonable amount of time before disclosing the bug (if the disclosure window was 180 days and MS missed it people would be complaining just the same as 90 days). There's no reason why someone else couldn't discover this bug and exploit it. I would rather know that I am vulnerable then be ignorant and assume my software was safe when it in fact was not. Thanks taviso for all the great security work you do. (Also 2004 me would like to thank you for your cool fvwm configs).
- oblio 7y ago> (Also 2004 me would like to thank you for your cool fvwm configs). So much time wasted^W invested in those FVWM configs... I could never get it working quite as magically as Tavis Ormandy or Thomas Adam made it look like.
- Aissen 7y agoTo anyone who still thinks a 90-days deadline (with up to 14 additional days for patch release alignment) isn't fair enough, I invite you to look at the timeline for this report: https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html https://blog.quarkslab.com/reverse-engineering-broadcom-wire... This is is remote code exec on any device. Yet without hard deadlines, vendors stall, lie, etc. This isn't the first example of this. There has been many throughout the past. Project Zero's policy is actually very well thought, and state of the art IMHO.
- oaiey 7y agoI think it is fair and necessary as an incentive to immediately start working on it. It is also right to publish them after 90 days. I just think it is not fair to blame or make fun of companies for failing on delivery within 90 days what happens here regularly (see: upvotes for the article). When developing a low risk application with a fancy DevOps infrastructure everyone expect bug fix delivery in hours or maximum the 2 weeks sprint. 90 days is not much time when patching operating systems or mission critical software. Windows is used in literally all regulated environments, from aircrafts to medical devices. The amount of necessary paper work and the amount testing to reduce risk is beyond what anyone not in that business can imagine.
- SmellyGeekBoy 7y ago> I just think it is not fair to blame or make fun of companies for failing on delivery within 90 days what happens here regularly (see: upvotes for the article). Are people upvoting just to "make fun" of Microsoft? I assumed it was for visibility or to share an interesting insight into the inner workings of the security industry.
- oaiey 7y agoYeah, but security incidents like that happen every month. We should be long bored of it.
- kriro 7y ago
- dagaci 7y agoWriting code and especially bug fixing issues with complicated code is not as deterministic, as most people imagine. And any developer knows that they should definitely expect the unexpected! but few seriously wonder whats going on when we agree to estimate for them. So getting up-tight and blaming engineers for having delays is just as random as having a 90 day deadline.
- leereeves 7y agoThe majority of users won't see this notice. They'll be more vulnerable because it was published and they still won't know it. Disclosing the details like this hurts innocent bystanders.
- Dylan16807 7y agoLeaving bugs unpatched hurts innocent bystanders. Disclosure schedules reduce time-to-patch by a lot. But only if they have teeth.
- leereeves 7y agoProject Zero just told everyone how to exploit a bug that won't be fixed for a month. Even if that is (arguably) better than "having no teeth", that doesn't make it a good idea. Perhaps they can find better teeth, a response that doesn't involve helping bad actors when vendors fail to patch quickly.
- Dylan16807 7y ago> Perhaps they can find better teeth Feel free to suggest! But wanting something to be true isn't enough. And I can assure you, everyone wants that.
- leereeves 7y agoWhy not publish the existence of the vulnerability without any details? That is the only information most people will get from the disclosure anyway. Only the black hats are helped by disclosing the details.
- protomyth 7y agoIt is curious that Google is perfectly fine keeping an Intel embargo for a long while when it affects them, but is very strict about disclosure when the exploit affects others.
- MaupitiBlue 7y agoJust more anticompetitive behavior from Google.
- auiya 7y agoWhy do you assume Google wouldn't be affected by a Windows bug? Have you forgotten about the compromise of their corp networks by a Chinese APT in 2008/9 which leveraged Windows as the attack surface? The reason for disclosures like this to expedite bug fixes is because they have skin in the game.
- protomyth 7y agoThere is a rather large difference between Google’s own OSes, software, and services; and the stuff Google uses. Google has the resources to mitigate problems with what they use from others much faster than most customers of the their competitors.
- cyberbase 7y agoNotices, pressure or teeth, should be effective and reduce harm... 1. Notify Manufacture w Details, Start 90 Day Clock. 2. 90 Days, Notify public of discovery and notice date, NO public details. Notify Reputable Security Vendors of details to prep defense of un-patched bug. 3. 180 days release limited details publicly and date of notices to MFG and Sec Vendors. THIS will build public pressure on whole ecosystem and limit impact.
- Operyl 7y agoAt step 2: any release of any information is enough to get people looking in the right general direction.
- syn0byte 7y agoIf you see a bridge or a building with cracks and signs of structural weakness, be sure not to tell anyone, you might start a panic. Instead directly contact the engineering firm and give them at least 90 days to rectify the issue before telling the public. If you experience a defect in your automobile that causes your steering to cut out intermittently do not alert other users of the same make and model. Instead contact the manufacturer and give them 90 days to fix the issue internally and mail you a new part. If a drug you are taking causes a serious reaction quietly contact the maker of the drug directly... See how incredibly stupid "reasonable disclosure" sounds in other industries?
- zelon88 7y agoI really can't wait until Microsoft does this to Google and Google sues them into the sunset. Something tells me big G wouldn't like a taste of it's own medicine in this department.
- Operyl 7y agoExcept .. Project Zero has released stuff affecting other Google teams before. It’s universal.
- jzzmnn 7y agoJune 12, 2019 Huge Cybersecurity Global Alert which proves Microsoft patches won't fix 2006-2019 front and backdoor vulnerabilities created by FVEY, Nine, Fourteen Spying Eyes Google belongs too.