Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Tuesday February 20 2018, @03:44PM   Printer-friendly
from the responsible-disclosure dept.

Google's Project Zero has disclosed a vulnerability in the Microsoft Edge web browser that bypasses the browser's Arbitrary Code Guard (ACG). Project Zero disclosed the bug 14 days after the end of the usual 90-day period, but it apparently wasn't enough time for Microsoft to patch it:

Google's Project Zero initiative tasks its security researchers with finding flaws in various software products developed by the company itself as well as other firms. Back in 2016, it revealed a serious vulnerability present in Windows 10, and reported a "crazy bad vulnerability" in Windows in 2017. Now, the firm has disclosed another security flaw in Microsoft Edge, after the Redmond giant failed to fix it in the allotted time.

[...] According to the Microsoft Security Response Center (MSRC), the problem turned out to be more complex than initially believed, due to which it was given an additional 14-day grace period by Google. Although the company missed this deadline in its February Patch Tuesday too - which forced Google to make the flaw public - Microsoft is confident that it will resolve the issue by March 13, aligning the shipment of the fix with the Patch Tuesday in March.

Also at The Verge and BetaNews.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0, Disagree) by Anonymous Coward on Tuesday February 20 2018, @04:15PM (8 children)

    by Anonymous Coward on Tuesday February 20 2018, @04:15PM (#640702)

    That's a nice business you got going there, be a shame if something were to happen to it...

    The embargo window is there to make sure that the vendor gets their act together and actually fixes things instead of being a black hole of bug-reports. In this case, Google acted irresponsibly because the intent of the embargo was satisfied: MSFT has been trying to get a fix working but hasn't succeeded in that yet. They could have worked with MSFT to make sure they aren't dragging their feet and actually continue on pushing a fix out but there was no reason for Google to disclose this (or not extend the embargo) aside from being dicks and doing it for a browser that is their direct competitor.
    Google acted irresponsibly in this case and there is no excuse!

    Starting Score:    0  points
    Moderation   0  
       Disagree=1, Total=1
    Extra 'Disagree' Modifier   0  

    Total Score:   0  
  • (Score: 5, Funny) by takyon on Tuesday February 20 2018, @04:24PM (5 children)

    by takyon (881) <takyonNO@SPAMsoylentnews.org> on Tuesday February 20 2018, @04:24PM (#640706) Journal

    So the embargo window is there for a reason... but Google actually ending the embargo (albeit with a 14 day extension) is bad.

    What should they do instead? Extend the window repeatedly forever? Then it's no longer a window, it's windows.

    --
    [SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
    • (Score: 2, Funny) by realDonaldTrump on Tuesday February 20 2018, @04:36PM (4 children)

      by realDonaldTrump (6614) on Tuesday February 20 2018, @04:36PM (#640713) Homepage Journal

      So many people who have computer, they have it for windows. For solitaire, for so many things. They love the solitaire, so interesting! Great job, Bill! Great job, Satya!

      • (Score: 3, Funny) by realDonaldTrump on Tuesday February 20 2018, @06:07PM (3 children)

        by realDonaldTrump (6614) on Tuesday February 20 2018, @06:07PM (#640759) Homepage Journal

        It's a day ending in "Y" so dumb & unfair downmodders are "reading." They're not reading. Because the STORY and the other TWEET are about windows! But I tweet about windows, suddenly it's "OFFTOPIC." Not because of what I wrote. Because of who I am!!!!

        • (Score: 2) by DannyB on Tuesday February 20 2018, @08:20PM

          by DannyB (5839) Subscriber Badge on Tuesday February 20 2018, @08:20PM (#640818) Journal

          Microsoft should make new Surface laptops powered by Clean Coal. Beautiful Clean Coal.

          --
          To transfer files: right-click on file, pick Copy. Unplug mouse, plug mouse into other computer. Right-click, paste.
        • (Score: 4, Interesting) by captain normal on Tuesday February 20 2018, @08:27PM (1 child)

          by captain normal (2205) on Tuesday February 20 2018, @08:27PM (#640821)

          The story and TFA are about a vulnerabilkity in MS's Edge brower that was discovered by Google's Project Zero. All the posts up to yours are about that toipic. Your post is not. So to me that seems your post could qualify as "Off topic".
          If you were down moded, it probably has nothing to do with who you are (or pretend to be). Likely it was because you didn't contribute to the actual discussion.

          --
          When life isn't going right, go left.
          • (Score: 0) by Anonymous Coward on Wednesday February 21 2018, @06:16AM

            by Anonymous Coward on Wednesday February 21 2018, @06:16AM (#641052)

            Oh man, it's Captain Normal, the arch-nemesis of Donald Trump!

  • (Score: 5, Insightful) by requerdanos on Tuesday February 20 2018, @04:52PM (1 child)

    by requerdanos (5997) Subscriber Badge on Tuesday February 20 2018, @04:52PM (#640723) Journal

    In this case, Google acted irresponsibly because the intent of the embargo was satisfied: MSFT has been trying to get a fix working but hasn't succeeded in that yet. They could have worked with MSFT to make sure they aren't dragging their feet and actually continue on pushing a fix out but there was no reason for Google to disclose this (or not extend the embargo)

    Microsoft is a large enough, not-100%-trustworthy enough organization for a judgment call like that to be fraught with uncertainty. Even now, the patch isn't out, and one may be in the works and may not; all we have are words.

    What has certainty is the disclosure program, which is pretty effective. That's a reason that might seem petty and spiteful, might even be petty and/or spiteful, but which was made in line with a policy that has a proven track record of improving security industry-wide.

    • (Score: 0) by Anonymous Coward on Tuesday February 20 2018, @05:12PM

      by Anonymous Coward on Tuesday February 20 2018, @05:12PM (#640733)

      OP here...
      You know what, you're not going to hear this often on the 'tubes, but the way you put it, I think you're right. I hereby recall my original post...