7 ms·
I think there is something to notice about having a hard fixed timeline for everyone. See from the bug: https://code.google.com/p/google-security-research/iss
by xxyyzz3d 12y ago
I think there is something to notice about having a hard fixed timeline for everyone. See from the bug:
https://code.google.com/p/google-security-research/issues/detail?id=123 https://code.google.com/p/google-security-research/issues/de...
> Microsoft confirmed that they are on target to provide fixes for these issues
in February 2015. They asked if this would cause a problem with the 90 day
deadline.
< Microsoft were informed that the 90 day deadline is fixed for all vendors and
bug classes and so cannot be extended. Further they were informed that the 90 day
deadline for this issue expires on the 11th Jan 2015.
> Microsoft confirmed that they anticipate to provide fixes for these issues in
January 2015.
So basically Microsoft asked for an extra month, and they said no, which forced them to move quicker, and fix it a month earlier. Without picking any side of the debate, you can still see what effect the non-negotiation of timeline has on getting patches out as soon as possible.
- freehunter 12y agoWhich sounds like blackmail to me. What did Microsoft have to put aside to move this up in their schedule? Maybe now the release date for Microsoft's new browser slips, giving Google the upper hand? Should corporations force their competitors to move like this? "If you don't drop everything, we're going to release vulnerability details about your product"? I work in information security and patches are important, I understand. But it worries me that what we're basically seeing here is corporate warfare using security vulnerabilities. What gives any company the right to publish vulnerabilities about their competitors, especially when it has the chance to impact their competitor's performance? Does Pepsi have the right to demand Coke rotate the tires on their trucks within 90 days or they will publish the recipe for Coca Cola?
- teraflop 12y agoWhat a disingenuous comparison. It's not "accede to our demands or we'll publish this information"; it's "we're publishing this information in 90 days whether you like it or not." If we ask "what gives any company the right to publish vulnerabilities about their competitors?" it's only a short step to asking "what gives journalists the right to publish scathing negative reviews?" The answer is the same: freedom of speech. It's a fact of life that if you want to fix security bugs, that takes time away from working on other things. If you don't like it, fix the bugs faster, or pay more attention to security from the get-go. Microsoft should be thanking Google for finding the bug in the first place.
- freehunter 12y agoIt doesn't matter if Google publishes it after the patch. It matters if the publish before. If they publish before the patch, even knowing when the patch will come out, that's enforcing their demands or making MS suffer the consequences. Google knew Microsoft had a patch. Google published it anyway, because their competitor didn't work fast enough, for Google's definition of "fast enough". Journalists are not directly competing with tech companies. Google is. Imagine the next bug they find in Windows, and they publish it saying "ChromeOS doesn't have this bug!". They already use their search to push their browser, why not use their bug reporting to push their OS? When does free speech stop and anti-competitive behavior start? Would Google publish their own vulnerability if they were unable to fix it in 90 days?
- teraflop 12y ago> If they publish before the patch, even knowing when the patch will come out, that's enforcing their demands or making MS suffer the consequences. So? As a general rule, people (and companies) have the right to say things like "I'll do X if you do Y" or "I'll do X unless you do Y". It becomes blackmail under certain circumstances, like where you're threatening to harm someone illegally, or demanding money for covering up a crime. In this case, Google picked a 90-day disclosure timeline which seems to be considered generally reasonable by the security community, so I don't see how they're doing anything wrong by sticking firmly to it. > Google published it anyway, because their competitor didn't work fast enough, for Google's definition of "fast enough". Yup, sounds like competition to me. > Imagine the next bug they find in Windows, and they publish it saying "ChromeOS doesn't have this bug!". Yup, sounds like competition to me. Maybe I'm just being dense but it would help if you could explain why you think this is "anti-competitive." To me, forbidding a company from trying to demonstrate that its product is more secure than its competitors' is anti-competitive. > Would Google publish their own vulnerability if they were unable to fix it in 90 days? Maybe, maybe not. Presumably since Microsoft has so many employees and cares so much about security, it has its own team of researchers dedicated to finding bugs in Chrome, right? Or is it Google's responsibility to find everyone's bugs, and then give them as much time as they want to fix them?
- delinka 12y agoIn what world does the recipe for Coca Cola in any way influence the maintenance of a fleet of trucks? Google's policy is responsible disclosure. Wavering on the well-known deadline would become a political headache. If you give a mouse a cookie... Two days becomes a week; a week becomes half of a month; half a month becomes a full month. Perhaps if Google is feeling generous, they could not disclose a vulnerability to a vendor until a later time (for example, if a vulnerability is found just before a well-known extended holiday or something) thus automatically "extending" the expiration of the quiet period. But that still leaves us, the users, more vulnerable for longer if the bad guys were already aware of the problem. On a slight tangent, Microsoft's policy to not release security patches as soon as they're available (and instead wait until "patch Tuesday") harms us all. They don't have to forcibly push the fixes, but immediate availability would be a tremendous improvement.
- freehunter 12y agoWhich they're doing with Windows 10. Consumers get them now, business get them on Tuesday. Have you ever deployed patches to a couple thousand machines? It's not something you want to do every night.
- delinka 12y agoWhen to deploy patches to my thousands of machines is my administration problem, not Microsoft's. Giving me the tools to make these decisions puts more power to protect my company into my hands. Denying patches to me simply to fit a schedule denies me flexibility and, potentially, security.
- WorldWideWayne 12y agoMicrosoft first has to test and deploy the patch to their servers, not yours. At the level they're operating, a schedule seems like an obvious requirement for releasing patches.
- delinka 12y ago
- dwild 12y agoYou act like security vulnerabilities aren't important. If Google found that security vulnerability, how much black hat already found it or are going to find it in the next 90 days? Sadly we can't know, that's why we need to set a schedule, there's no soon enough.