5 ms·
Really, that Mozilla would let a reported RCE vulnerability simmer for two months until it bit someone would seem to reflect very poorly on their priorities and
by Felz 7y ago
Really, that Mozilla would let a reported RCE vulnerability simmer for two months until it bit someone would seem to reflect very poorly on their priorities and competence. Can anyone postmortem why it took so long now that it's fixed?
- tedunangst 7y agoFirefox likes to bundle security fixes into .0 releases. 67.0 was released May 21 (and went to nightly/beta whatever May 13) and 68.0 won't be released for a few more weeks.
- ErikAugust 7y agoDo you know why? Isn’t a security fix a bug fix?
- tedunangst 7y agoNope. Security vulns are not regressions!
- tru3_power 7y agoI’m confused what do you mean? Fixing security vulns can often times lead to regressions since overtime users become dependent on a behavior that relies on a insecure behavior.
- staticassertion 7y agoSecure behaviors should generally trump API guarantees.
- bscphil 7y agoYour parent comment didn't say security fixes couldn't lead to regressions, they said security vulns themselves aren't regressions.
- luch 7y agoAnd how do you qualify "Meltdown" and it's notorious bad fix "Total Meltdown" in that case ? To me, the bug fix introduced a clear regression, allowing an even more powerful vuln in the process.
- xmprt 7y agoIs there a good reason for this? I would think that a security issue should be addressed and patched into user's computers as soon as possible, especially something like RCE.
- roca 7y agoSecurity fixes carry the usual risk of regressions (even more than the average bug, when the fix limits something that used to "work"). Therefore they need just as much bake time as other kinds of changes. Also, shipping security fixes in stand-alone updates makes it much easier for attackers to identify security-critical changes (especially if they have access to source code, which they do for Firefox) and reverse-engineer the flaw. Firefox developers often land critical fixes with somewhat obscured commit messages to increase the work required by attackers to identify the critical security fixes in the torrent of commits that go into each regular release. Obviously this only makes sense while the bug is believed to be unknown to attackers. If Mozilla believes the bug is being exploited, they can and do issue an emergency update.
- forkerenok 7y ago> Firefox developers often land critical fixes with somewhat obscured commit messages to increase the work required by attackers to identify the critical security fixes in the torrent of commits that go into each regular release. Wow, that's fascinating. Do you have any interesting reads to point to in this regard?