Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The only venue that Microsoft provides to give feedback and bug reports is their connect website. This is the venue that Benoit used because it was the only venue available to him, as an individual.

That's not at all true, is it?

http://www.microsoft.com/security/msrc/report.aspx



MSRC is generally used to report security bugs for released products only. They do now patch some prerelease products, though.


Microsoft even started a branch for researching (and methodically disclosing) bugs in other vendors products.

https://twitter.com/k8em0/status/83302574681374721

This makes sense when you think about it. They likely get the crash dumps from Mozilla's beta testers too. They definitely have a better handle on determining their exploitability.

Nobody has more experience with video driver bugs than Microsoft.


That's also not true.


Nitpicking. Either way, usually using this way to report (what Microsoft claims) is a security bug would be more stand up way to do it but in this specific case, given Microsoft's FUD designed to kill WebGL (with the consequence of Flash and Silverlight having an upper hand wrt. 3d graphics in the browser), doing it publicly was the right call. It nicely shows Microsoft's double standards which is important to the overall discussion.


Google and Mozilla would not consider it "nitpicking" if I posted a security flaw to a public bug tracking site, then claimed "that's the only place to send them". All three of those vendors went out of their way to establish and communicate the method needed to safely publish security flaws in their products.

The appearance of this report is that the reporter ignored that process out of spite. Is that the message the Web GL people are intending to send? I doubt it.

Moreover, who's being punished here? Microsoft? Actions like this score PR points for Microsoft. It's users who pay the price of casual disclosure. I know that because that's what Google effectively says with their disclosure policy, and what Mozilla says with theirs.

I think this was a bad call.


I don't get it, this software (Silverlight 5) is still in development. It's not meant to be used in production. If there is a flaw it should be reported. I would too have thought Microsoft Connect was the right place to report it. I don't see why it has to be hidden. ContextIS released their Firefox image stealing bug in public and it was quickly fixed by Mozilla within a week. I think this worked pretty well as far a security release goes. And this was for software already released to the public.


You too would have been wrong. Here's what Mozilla says about the same issue:

IMPORTANT: Anyone who believes they have found a Mozilla-related security vulnerability can and should report it by sending email to the address [email protected]. For more information read the rest of this document.

Here's what Google says about it:

If you believe you have discovered a vulnerability in a Google product or have a security incident to report, email [email protected].

Here's what Apple says about it:

To report security issues that affect Apple products, please contact: [email protected]

Here's what Cisco says (they even provide a toll-free phone number!):

Individuals or organizations that are experiencing a product security issue are strongly encouraged to contact the Cisco PSIRT. Cisco welcomes reports from independent researchers, industry organizations, other vendors, customers, and any other sources concerned with product or network security. Please contact the Cisco PSIRT directly using one of the following methods

You can Google for virtually any major vendor, in the form [report XXX security vulnerability], and get instructions on how to report flaws to them.

Posting flaws to public bug tracking systems is just about the worst conceivable way to do it. Public bug trackers are not always (or even usually) monitored by product security teams. As a result, for many vendors, you can find vulnerabilities in their bug trackers they don't even know about, and nobody else does either, because they were reported to a black hole. You're actually better off writing an angry blog post than putting in the public bug tracker.


I've reported a bug or multiple bugs to all of those guys, and for the record, Microsoft has been by far the most proactive and aggressive at wanting to get the details to their researchers the fastest.


Ok I'll great you the fact that for security issues trying to contact them privately is probably their preference. But in this case where talking about a bug that causes a machine crash. I don't know but does that even constitute a security flaw? This is more a major software flaw then a security bug. If all bug that makes browsers crash were sent to that security report email, they would be overwhelmed quickly. If it could be used to exploit the machine I'd be with you and would suggest that the bug be reported through the vendors security channel.


> You're actually better off writing an angry blog post than putting in the public bug tracker.

That's too often true of all bugs.


The proof-of-concept is really just painting 10,000 rectangles the size of the window. It's that stupid. It has nothing to do with shaders or anything fancy. As long as you allow painting many large triangles as a single GPU command, you have the vulnerability. If you don't allow that, then you're not fast.

Everybody has known forever about that vulnerability in 3D APIs. So there was not much of a point using a private reporting mechanism. However, Microsoft took this well-known universal vulnerability and presented it as something specific to WebGL. There was no point in replying privately to that.


Sure. Plenty of people also deliberately don't use "official" channels. Look at the Metasploit people, who I respect a lot. I'm not saying it has to be done that way. I'm saying that the guy who says "it got posted to the public bug tracker because there's no other place for an individual to send security flaws" is wrong. Doesn't know what he's talking about.

There's also nothing wrong with that. Why should everyone need to know the ins and outs of vulnerability research? But probably he should dial back the stridency.


The repro was a crash, which by itself, is not an exploit and it was reported against a beta software that is not deployed widely. There is no end-user installable silverlight 5 plugin and in fact a developer would be breaking Silverlight 5 license if he put a Silverlight 5 app on a publicly accessible web page (http://drc.ideablade.com/xwiki/bin/view/Documentation/code-s..., see "go live" terms).

At the risk of generalizing a bit, what bothers me about your comments specifically and security people in general, is that once something gets labeled with "security issue" label it apparently becomes a black-and-white issue (and I apologize to security people who don't do that).

WebGL shouldn't be implemented. Reporting non-exploit crash in software that is not available except to developers that don't run other people's code gets put (implicitly) into the same bucket as 0-day exploit for widely deployed software.

As a security person you know damn well that not every crash report deserves following security disclosure protocol, especially given that addressable target is effectively null in this case. Chrome's security guidelines explicitly spell out a difference between a crash and a security bug: http://www.chromium.org/Home/chromium-security/reporting-sec... and they don't consider every crash a security issue http://www.chromium.org/for-testers/bug-reporting-guidelines...

The severity of problem exposed is nowhere close to what security disclosure protocols are designed for i.e. it's not an exploit.

But you're content with labeling it a "security flaw" and not doing any further analysis of severity or impact and your condemnation of that particular bug report is based on this binary mislabeling.


You wrote "The only venue that Microsoft provides to give feedback and bug reports is their connect website." That was simply, overtly, directly, incontrovertably false.

Now, because you are a message board geek, instead of saying "oh, interesting, I didn't know that, thanks for letting me know", you've given me 6 grafs of random stuff about security people, black-and-white, you-didn't-even-read-the-report, 0-day-not-crash-whatever. I don't care. You were wrong, that wasn't the way to report a security issue. It's either a security issue --- which your original argument depends on it being --- or it's not. If it's a security issue, posting it on a public bug tracking server was the wrong call.

Glad to clear that up for you. Feel free to the last word.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: