Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this.

Maybe there's a similar story with OS X, but there doesn't seem to be a public record of it.



> [...] and discloses a zero-day.

90-day, you mean. It's only zero-day if they had zero days to come up with a solution. That's what "zero-day" means.


But that doesn't sound nearly as cool or media hype-able.


I meant to say that there would be zero days between when I could patch my (hypothetical) Windows machine, and when people could start hacking it. The Wikipedia article you linked elsewhere seems ambiguous, e.g. "It is called a "zero-day" because the programmer has had zero days to fix the flaw (in other words, a patch is not available)." Microsoft has had something up to 90 days to produce such a patch, but hasn't for whatever reason.


[deleted]


http://en.wikipedia.org/wiki/Zero-day_attack

> It is called a "zero-day" because the programmer has had zero days to fix the flaw


Did you read what you just linked? Specifically, the part after the open parenthesis? The bit about the patch not being available?

> It is called a "zero-day" because the programmer has had zero days to fix the flaw (in other words, a patch is not available).

Please try again.


Actually, 0-day refers to the time since public disclosure.


If that would be the case then we would have another term for the thing I just described, because that's the worst case scenario.

Anyhow, the Wikipedia article disagrees with you, too. Got any sources for your definition?


I really dislike your description because while it is technically true it heavily implies that they decided on dates on a per-bug case, when they decided on a flat 90 days.


Then again, 90 days contains 2.5 of their fix cycles. If the vulnerability really is serious, and they can't fix it in that time line, they should exit the business.


Google roughly supports one version of their product on 2 OSs.

Microsoft supports all versions of all their products for 10years+ after release, integrated with a combination of all other products they have shipped in that same time-frame.

Needless to say, Microsoft needs to do more QA on their bug-fixes before they can safely release it to all customers without the risk of causing new issues.

It's easy for Google to be big in the mouth when they don't bother to support their existing customers properly.

Speaking of being big in the mouth: Did you know that Google isn't back-porting security fixes to older versions of Android either (only 2 last minor releases)? I guess supporting more than 40% of your user base is too much work.</sarcasm>

Guess which side my sympathy is leaning to in this case.


> Needless to say, Microsoft needs to do more QA on their bug-fixes before they can safely release it to all customers without the risk of causing new issues.

IIRC Microsoft also releases pre-versions of their patches to select customers so sysadmins can test the patch doesn't cause issues on their deployments.


As noted in the bug, it is not just writing a fix but writing one that works against all supported configurations that is the cause of a delay.


> others that Microsoft would just put off fixes forever if Google didn't do this.

People wouldn't think that if MS didn't have a long history of doing exactly that.


What security fixes has Microsoft put off forever?


They are obviously much better about this now but back when IE was the browser du jour there were tons of bugs that took ages for them to fix.

http://blog.washingtonpost.com/securityfix/2007/01/critical_...


Often they would dismiss a bug until someone exploited it to make a worm.


No, I think the "issue" is that Apple doesn't talk to the media, while Microsoft immediately complained to some big tech sites about it, which then wrote the story from Microsoft's point of view.


"Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this."

... and yet others think that both of those statements are true :)


3 months is a long ass time to produce a patch.


Even if we're talking about such a massive roll-out to millions of machines, with various versions of the OS running on various hardware? I don't know how easy or not the actual patch is to produce, but it's not out of the realm of possibilities that they did run into a compatibility issue that they wanted more time to sort out. Think of the outcry and damage to their business if they rolled out a patch that accidentally broke some installations.


Yes, even then. Imagine if the bug had been found by security researchers who believe in full disclosure. You think it's reasonable for Microsoft to allow dozens of rootkits and viruses to proliferate for more than three months, for botnets to grow to hundreds of millions in size? Microsoft's release process is broken.


Sure, three months is a long time to fix an issue, but what does Microsoft have to gain by taking longer to fix an issue of this severity than it believes it needs to? If Microsoft released the fixes when they were going to, and Google then released the details of the issues and when they first reported them, Google could still make a stink about Microsoft's turn-around time on critical security bugs, and there wouldn't be any gap between global notification of the issues and a readily available fix for them.

Put another way, Google may have just notified the world of black-hat hackers of an issue they weren't otherwise aware of, an issue that demonstrably will not be patched for some time. If that is the case, then Google just recklessly endangered people's computers in the interest of raising awareness of Microsoft's poor turn around time on these issues. There is also the very real chance that this issue was already known by the black-hat community, in which case there isn't nearly as much lost by reporting here, but that's a gamble Google is making in order to make a point.


IIRC they do issue out-of-schedule patches if a vulnerability is severe enough and/or being actively exploited.


And if we're talking about a true 0-day being exploited in the wild? Microsoft is still unable to get a patch out in less than 90 days time? That's flat unacceptable. They need to be more responsive than that.


Think what you want, but IMO 90 days (even rounded to the nearest patch Tuesday) is plenty of time to fix the critical security issue. Clearly Microsoft is acting weird here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: