TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Google Goes Public with Unpatched Microsoft Edge and IE Vulnerability

369 点作者 uber1geek大约 8 年前

16 条评论

rattray大约 8 年前
Looks like they thought this would get fixed:<p>&gt; I will not make any further comments on exploitability, at least not until the bug is fixed. The report has too much info on that as it is (I really didn&#x27;t expect this one to miss the deadline).<p>Worth mentioning that &quot;Goes Public&quot; implies there was a human who pulled the trigger; it was a bot:<p>&gt; This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.<p>...<p>&gt; Deadline exceeded -- automatically derestricting
评论 #13756919 未加载
评论 #13755434 未加载
评论 #13755413 未加载
andreyf大约 8 年前
This is not the first time Google has disclosed unpatched vulns in Microsoft product [1]. Anyone know any more?<p>What&#x27;s up with them not being able to patch on time? How is <i>90 days</i> not enough to get a patch out the door? That&#x27;s a quarter, for goodness&#x27; sake!<p>1. <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12841672" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12841672</a>
评论 #13756667 未加载
评论 #13759023 未加载
评论 #13756920 未加载
评论 #13755377 未加载
评论 #13755343 未加载
评论 #13755498 未加载
george_ciobanu大约 8 年前
&quot;Project Zero&#x27;s disclosure deadline policy has been in place since the formation of our team earlier in 2014. It&#x27;s the result of many years of careful consideration and industry-wide discussions about vulnerability remediation. Security researchers have been using roughly the same disclosure principles for the past 13 years (since the introduction of &quot;Responsible Disclosure&quot; in 2001), and we think that our disclosure principles need to evolve with the changing infosec ecosystem. In other words, as threats change, so should our disclosure policy.<p>On balance, Project Zero believes that disclosure deadlines are currently the optimal approach for user security - it allows software vendors a fair and reasonable length of time to exercise their vulnerability management process, while also respecting the rights of users to learn and understand the risks they face. By removing the ability of a vendor to withhold the details of security issues indefinitely, we give users the opportunity to react to vulnerabilities in a timely manner, and to exercise their power as a customer to request an expedited vendor response.&quot;<p>From <a href="https:&#x2F;&#x2F;www.engadget.com&#x2F;2015&#x2F;01&#x2F;02&#x2F;google-posts-unpatched-microsoft-bug&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.engadget.com&#x2F;2015&#x2F;01&#x2F;02&#x2F;google-posts-unpatched-m...</a>
评论 #13756898 未加载
johnsmith21006大约 8 年前
Google owns a decent chunk of CloudFlare. They shared the flaw as they should last week.<p>I see nothing close to Google trying to get MS. Instead it is what should be done.<p>Mow me with things like Scrougle and MS replaced YouTube as with their own i probably would not be so nice.<p>Look at Amazon will not allow Chromecast to be sold on their site. Personally i would have removed Amazon from their search engine but not Google.<p>Look at Uber. If i was Google i would use my power to destroy but not Google.<p>Feel how ever you want about Google but let&#x27;s at least be fair.
评论 #13755821 未加载
ErikAugust大约 8 年前
Project Zero is taking names lately. I wonder if other firms will &quot;retaliate&quot; with their own Project Zero-style security teams.
评论 #13755309 未加载
评论 #13755339 未加载
评论 #13755440 未加载
评论 #13757304 未加载
评论 #13755481 未加载
nunez大约 8 年前
I&#x27;m glad they aren&#x27;t playing around with the 90 day limit.
评论 #13755395 未加载
评论 #13757629 未加载
lettersdigits大约 8 年前
&gt; This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.<p>Is this a common pattern in the bugs world ? publicizing a critical bug after 90 days of no response ?
评论 #13757443 未加载
certifiedloud大约 8 年前
I guess when they say 90 days they really mean it.
ipsin大约 8 年前
The bug doesn&#x27;t make it clear; was this issue reported to Microsoft?<p>I wasn&#x27;t sure if I missed a sign of notification, or if vendors are automatically cc&#x27;d&#x2F;whitelisted on restricted bugs for their products.
rattray大约 8 年前
How is Microsoft&#x27;s track record on security generally these days?
评论 #13756582 未加载
评论 #13755410 未加载
thehardsphere大约 8 年前
How often do these deadlines get missed?
评论 #13755286 未加载
JepZ大约 8 年前
Is it normal that IE and Edge bugs are getting reported to the chromium bug tracker?
评论 #13756420 未加载
Havoc大约 8 年前
As undemocratic-y as it sounds these big corps should really talk to each other more...
jwilk大约 8 年前
Please use the original title.
评论 #13762624 未加载
plandis大约 8 年前
Was Microsoft even notified about this? I didn&#x27;t see any indication on the linked page.
euyyn大约 8 年前
Can we have the title of the post conform more to that of the thing it links to?
评论 #13759774 未加载