8 ms·
They closed my bug as "fixed" but didn't give any details. I'll have a look at it again when the next beta / final build of silverlight 5 comes out. In the WebG
by bjacob 15y ago
They closed my bug as "fixed" but didn't give any details. I'll have a look at it again when the next beta / final build of silverlight 5 comes out. In the WebGL WG we are very confident that this can't be fixed without working with GPU vendors on new robustness features in the drivers.
- kenjackson 15y agoThis seems like an odd way to go about doing an open standard. Don't you usually want to let vendors work on getting things working and then come back and standardize based on best practices? It would seem like the WG should work with MS and Adobe to get Silverlight and Flash working really well. Get it out in peoples hands for a year or two. And then come back and say, "OK, we generally get 3D on the web now. Now lets standardize it." It really feels like this WG is in a race to hurry to get something out the door as fast as possible.
- kkowalczyk 15y agoIt seems to me the guy who reported the issue to Microsoft is doing the only thing that he can effectively do to help them. WebGL is a standard developed in an open way. If someone wants to contribute, including Microsoft, they can send an e-mail to a mailing list and that will reach other people working on WebGL and hopefully a productive conversation would ensue. Microsoft choose not to do that. Instead they issued a blanket statement to the whole world that WebGL is insecure. They made no effort to improve the security of WebGL and didn't leave any opening for the discussion. They just communicated a decision. Silverlight or IE engineers are not easily reachable and cannot be engaged in an open, technical dialogue the way WebGL folks can. The only venue that Microsoft provides to give feedback and bug reports is their connect website. This is the venue that Benoit used because it was the only venue available to him, as an individual. No one, including WebGL engineers, has special powers to engage Microsoft in discussion about their products. No one needs special powers to engage WebGL folks in discussion about WebGL. So you really have your power structure backwards. Notice also how this bug report is constructive: it shows a specific problem that Microsoft can fix. Notice how Microsoft's FUD wasn't constructive: they just labeled WebGL insecure using non-specific (therefore non-fixable) arguments.
- tptacek 15y agoThe only venue that Microsoft provides to give feedback and bug reports is their connect website. This is the venue that Benoit used because it was the only venue available to him, as an individual. That's not at all true, is it? http://www.microsoft.com/security/msrc/report.aspx http://www.microsoft.com/security/msrc/report.aspx
- kkowalczyk 15y agoNitpicking. Either way, usually using this way to report (what Microsoft claims) is a security bug would be more stand up way to do it but in this specific case, given Microsoft's FUD designed to kill WebGL (with the consequence of Flash and Silverlight having an upper hand wrt. 3d graphics in the browser), doing it publicly was the right call. It nicely shows Microsoft's double standards which is important to the overall discussion.
- tptacek 15y agoGoogle and Mozilla would not consider it "nitpicking" if I posted a security flaw to a public bug tracking site, then claimed "that's the only place to send them". All three of those vendors went out of their way to establish and communicate the method needed to safely publish security flaws in their products. The appearance of this report is that the reporter ignored that process out of spite. Is that the message the Web GL people are intending to send? I doubt it. Moreover, who's being punished here? Microsoft? Actions like this score PR points for Microsoft. It's users who pay the price of casual disclosure. I know that because that's what Google effectively says with their disclosure policy, and what Mozilla says with theirs. I think this was a bad call.
- nkassis 15y agoI don't get it, this software (Silverlight 5) is still in development. It's not meant to be used in production. If there is a flaw it should be reported. I would too have thought Microsoft Connect was the right place to report it. I don't see why it has to be hidden. ContextIS released their Firefox image stealing bug in public and it was quickly fixed by Mozilla within a week. I think this worked pretty well as far a security release goes. And this was for software already released to the public.
- magicalist 15y agowhy would you wait for microsoft or adobe to implement it? what you describe is exactly what has been happening for two years now, just with multiple browser makers working on independent experimental implementations.
- yuhong 15y agoMaybe it is the difference between Direct3D and OpenGL. I don't know enough to be sure, though.
- mmastrac 15y agoCould you explain how this particular example works?
- bjacob 15y agoIt just renders 10,000 rectangles of the size of the browser window, which by itself is enough to DOS; to make it a bit worse, it also uses a large texture and adresses it with very little respect for memory locality ;-) The C# code is here: http://people.mozilla.org/~bjacob/SilverLight5DOSJustLikeWebGL/HelloWorld3D/MainPage.xaml.cs http://people.mozilla.org/~bjacob/SilverLight5DOSJustLikeWeb... And the pixel shader: http://people.mozilla.org/~bjacob/SilverLight5DOSJustLikeWebGL/ShaderLibrary/Effects/Shaders/Color.ps.hlsl http://people.mozilla.org/~bjacob/SilverLight5DOSJustLikeWeb... EDIT: I forgot to mention that this is very similar to the WebGL DOS example, https://cvs.khronos.org/svn/repos/registry/trunk/public/webgl/sdk/tests/extra/lots-of-polys-example.html https://cvs.khronos.org/svn/repos/registry/trunk/public/webg...