TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Google's Project Zero exposes unpatched Windows 10 lockdown bypass

225 点作者 _o_大约 7 年前

10 条评论

andrewguenther大约 7 年前
To people calling this a dick move by Google, I encourage you to look at the actual issue in Monorail. The reason given for not extending the deadline was that the issue is not particularly severe, and there are also similar bypass issues which are currently unpatched. If it isn&#x27;t going to help protect customers, what&#x27;s the point in granting an exception?<p><a href="https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=1514#c3" rel="nofollow">https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=15...</a>
评论 #16890470 未加载
评论 #16891013 未加载
nikic大约 7 年前
The only &quot;dick move&quot; involved here is the fact that zdnet wrote this article. Minor security issue lapses standard disclosure deadline? Who cares. Instead we get this attempt to sensationalize this into some kind of big Google vs. Microsoft rivalry.
评论 #16891496 未加载
ge0rg大约 7 年前
Original source: <a href="https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=1514&amp;q=" rel="nofollow">https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=15...</a>
评论 #16890383 未加载
bitmapbrother大约 7 年前
<i>Google reported the issue to Microsoft on January 19. Microsoft confirmed the issue about three weeks later</i><p>Microsoft should make a mental note that when you receive an email from a member of Google&#x27;s Project Zero team you don&#x27;t wait 3 weeks to respond.
评论 #16892820 未加载
dewiz大约 7 年前
Google, you have 90 days to stop tracking web users, then Windows will start asking desktop users if they would like to block tracking by filtering DNS requests
评论 #16890533 未加载
评论 #16891181 未加载
评论 #16891011 未加载
评论 #16891736 未加载
jacksmith21006大约 7 年前
Why does MS struggle so much with security?
评论 #16902608 未加载
评论 #16898604 未加载
avttre大约 7 年前
Why 90 days? Why not 30, 14, or 7? Microsoft might have requested responsible disclosure for exploits affecting Windows, but what gave Google the right to set a deadline?<p>I feel the 2 US companies have a friendly competition with each other which can help secure their systems.
评论 #16890493 未加载
评论 #16890386 未加载
评论 #16890972 未加载
finchisko大约 7 年前
I think there are so many point of views here. I&#x27;m not going to defend Google nor Microsoft, but imagine you&#x27;re paid by Google to work on security issues. What would be the metric to prove your existence, if there is no public awareness of your work, like this zdnet article? Project Zero IMO from time to time need to show they exists and doing great job. I think that could be one of reasons, why they resists to prolong standard 90 day period.
评论 #16891182 未加载
kerng大约 7 年前
Read about the details. Wow, having a bug like this being discussed so broadly shines a bad light on Google IMHO. Its appears like targeted news against Microsoft. It&#x27;s not mich newsworthy defense in depth issue. If an adversary can modify the registry, they can do a lot more harm.
foepys大约 7 年前
Denying the deadline extension to May 8th [1] is quite a dick move by Google, considering that it took them 6 <i>months</i> to fix the extremely harmful sitemap ranking bug in their search engine[2]. And after they fixed the bug, they only paid peanuts to the researcher for a bug that could&#x27;ve cost Google&#x27;s customers tens of millions in misplaced ad campaigns.<p>1: <a href="https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=1514#c3" rel="nofollow">https:&#x2F;&#x2F;bugs.chromium.org&#x2F;p&#x2F;project-zero&#x2F;issues&#x2F;detail?id=15...</a><p>2: <a href="http:&#x2F;&#x2F;www.tomanthony.co.uk&#x2F;blog&#x2F;google-xml-sitemap-auth-bypass-black-hat-seo-bug-bounty&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.tomanthony.co.uk&#x2F;blog&#x2F;google-xml-sitemap-auth-byp...</a>
评论 #16890395 未加载
评论 #16890402 未加载
评论 #16890397 未加载
评论 #16890392 未加载