TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Google's Project Zero exposes unpatched Windows 10 lockdown bypass

225 pointsby _o_about 7 years ago

10 comments

andrewguentherabout 7 years ago
To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn&#x27;t going to help protect customers, what&#x27;s the point in granting an exception?<p><a href="https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=1514#c3" rel="nofollow">https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=15...</a>
评论 #16890470 未加载
评论 #16891013 未加载
nikicabout 7 years ago
The only &quot;dick move&quot; involved here is the fact that zdnet wrote this article. Minor security issue lapses standard disclosure deadline? Who cares. Instead we get this attempt to sensationalize this into some kind of big Google vs. Microsoft rivalry.
评论 #16891496 未加载
ge0rgabout 7 years ago
Original source: <a href="https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=1514&amp;q=" rel="nofollow">https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=15...</a>
评论 #16890383 未加载
bitmapbrotherabout 7 years ago
<i>Google reported the issue to Microsoft on January 19. Microsoft confirmed the issue about three weeks later</i><p>Microsoft should make a mental note that when you receive an email from a member of Google&#x27;s Project Zero team you don&#x27;t wait 3 weeks to respond.
评论 #16892820 未加载
dewizabout 7 years ago
Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests
评论 #16890533 未加载
评论 #16891181 未加载
评论 #16891011 未加载
评论 #16891736 未加载
jacksmith21006about 7 years ago
Why does MS struggle so much with security?
评论 #16902608 未加载
评论 #16898604 未加载
avttreabout 7 years ago
Why 90 days? Why not 30, 14, or 7? Microsoft might have requested responsible disclosure for exploits affecting Windows, but what gave Google the right to set a deadline?<p>I feel the 2 US companies have a friendly competition with each other which can help secure their systems.
评论 #16890493 未加载
评论 #16890386 未加载
评论 #16890972 未加载
finchiskoabout 7 years ago
I think there are so many point of views here. I&#x27;m not going to defend Google nor Microsoft, but imagine you&#x27;re paid by Google to work on security issues. What would be the metric to prove your existence, if there is no public awareness of your work, like this zdnet article? Project Zero IMO from time to time need to show they exists and doing great job. I think that could be one of reasons, why they resists to prolong standard 90 day period.
评论 #16891182 未加载
kerngabout 7 years ago
Read about the details. Wow, having a bug like this being discussed so broadly shines a bad light on Google IMHO. Its appears like targeted news against Microsoft. It&#x27;s not mich newsworthy defense in depth issue. If an adversary can modify the registry, they can do a lot more harm.
foepysabout 7 years ago
Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 <i>months</i> to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could&#x27;ve cost Google&#x27;s customers tens of millions in misplaced ad campaigns.<p>1: <a href="https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=1514#c3" rel="nofollow">https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=15...</a><p>2: <a href="http:&#x2F;&#x2F;www.tomanthony.co.uk&#x2F;blog&#x2F;google-xml-sitemap-auth-bypass-black-hat-seo-bug-bounty&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.tomanthony.co.uk&#x2F;blog&#x2F;google-xml-sitemap-auth-byp...</a>
评论 #16890395 未加载
评论 #16890402 未加载
评论 #16890397 未加载
评论 #16890392 未加载