TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Google Goes Public with Unpatched Microsoft Edge and IE Vulnerability

369 pointsby uber1geekabout 8 years ago

16 comments

rattrayabout 8 years ago
Looks like they thought this would get fixed:<p>&gt; I will not make any further comments on exploitability, at least not until the bug is fixed. The report has too much info on that as it is (I really didn&#x27;t expect this one to miss the deadline).<p>Worth mentioning that &quot;Goes Public&quot; implies there was a human who pulled the trigger; it was a bot:<p>&gt; This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.<p>...<p>&gt; Deadline exceeded -- automatically derestricting
评论 #13756919 未加载
评论 #13755434 未加载
评论 #13755413 未加载
andreyfabout 8 years ago
This is not the first time Google has disclosed unpatched vulns in Microsoft product [1]. Anyone know any more?<p>What&#x27;s up with them not being able to patch on time? How is <i>90 days</i> not enough to get a patch out the door? That&#x27;s a quarter, for goodness&#x27; sake!<p>1. <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12841672" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12841672</a>
评论 #13756667 未加载
评论 #13759023 未加载
评论 #13756920 未加载
评论 #13755377 未加载
评论 #13755343 未加载
评论 #13755498 未加载
george_ciobanuabout 8 years ago
&quot;Project Zero&#x27;s disclosure deadline policy has been in place since the formation of our team earlier in 2014. It&#x27;s the result of many years of careful consideration and industry-wide discussions about vulnerability remediation. Security researchers have been using roughly the same disclosure principles for the past 13 years (since the introduction of &quot;Responsible Disclosure&quot; in 2001), and we think that our disclosure principles need to evolve with the changing infosec ecosystem. In other words, as threats change, so should our disclosure policy.<p>On balance, Project Zero believes that disclosure deadlines are currently the optimal approach for user security - it allows software vendors a fair and reasonable length of time to exercise their vulnerability management process, while also respecting the rights of users to learn and understand the risks they face. By removing the ability of a vendor to withhold the details of security issues indefinitely, we give users the opportunity to react to vulnerabilities in a timely manner, and to exercise their power as a customer to request an expedited vendor response.&quot;<p>From <a href="https:&#x2F;&#x2F;www.engadget.com&#x2F;2015&#x2F;01&#x2F;02&#x2F;google-posts-unpatched-microsoft-bug&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.engadget.com&#x2F;2015&#x2F;01&#x2F;02&#x2F;google-posts-unpatched-m...</a>
评论 #13756898 未加载
johnsmith21006about 8 years ago
Google owns a decent chunk of CloudFlare. They shared the flaw as they should last week.<p>I see nothing close to Google trying to get MS. Instead it is what should be done.<p>Mow me with things like Scrougle and MS replaced YouTube as with their own i probably would not be so nice.<p>Look at Amazon will not allow Chromecast to be sold on their site. Personally i would have removed Amazon from their search engine but not Google.<p>Look at Uber. If i was Google i would use my power to destroy but not Google.<p>Feel how ever you want about Google but let&#x27;s at least be fair.
评论 #13755821 未加载
ErikAugustabout 8 years ago
Project Zero is taking names lately. I wonder if other firms will &quot;retaliate&quot; with their own Project Zero-style security teams.
评论 #13755309 未加载
评论 #13755339 未加载
评论 #13755440 未加载
评论 #13757304 未加载
评论 #13755481 未加载
nunezabout 8 years ago
I&#x27;m glad they aren&#x27;t playing around with the 90 day limit.
评论 #13755395 未加载
评论 #13757629 未加载
lettersdigitsabout 8 years ago
&gt; This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.<p>Is this a common pattern in the bugs world ? publicizing a critical bug after 90 days of no response ?
评论 #13757443 未加载
certifiedloudabout 8 years ago
I guess when they say 90 days they really mean it.
ipsinabout 8 years ago
The bug doesn&#x27;t make it clear; was this issue reported to Microsoft?<p>I wasn&#x27;t sure if I missed a sign of notification, or if vendors are automatically cc&#x27;d&#x2F;whitelisted on restricted bugs for their products.
rattrayabout 8 years ago
How is Microsoft&#x27;s track record on security generally these days?
评论 #13756582 未加载
评论 #13755410 未加载
thehardsphereabout 8 years ago
How often do these deadlines get missed?
评论 #13755286 未加载
JepZabout 8 years ago
Is it normal that IE and Edge bugs are getting reported to the chromium bug tracker?
评论 #13756420 未加载
Havocabout 8 years ago
As undemocratic-y as it sounds these big corps should really talk to each other more...
jwilkabout 8 years ago
Please use the original title.
评论 #13762624 未加载
plandisabout 8 years ago
Was Microsoft even notified about this? I didn&#x27;t see any indication on the linked page.
euyynabout 8 years ago
Can we have the title of the post conform more to that of the thing it links to?
评论 #13759774 未加载