5 ms·
I guess I just don't read it the same way. Maybe it's just because I already knew about the issue, but it seems obvious the security issue existed before they w
by trotsky 16y ago
I guess I just don't read it the same way. Maybe it's just because I already knew about the issue, but it seems obvious the security issue existed before they were informed of it. A security issue that was fixed within minutes of its creation wouldn't be getting device wiped, cleaners pushed, market changes made.
When you get security alerts from other vendors, do yours typically include the first known date of vulnerability or do they include the date it was first reported, or just the CVE assignment date? When redhat/apple/microsoft push a security update do they list the sites or programs that were known to be abusing the bugs? Not that I've seen. Hell it is rare to see anyone even listing the first date that they were being actively exploited.
All of that would be better, of course, but it hardly seems reasonable to call google out when they're acting at least as responsibly as all their competitors.
- deleted 16y ago[deleted]