All security issues should be addressed as soon as they can be.
Absolutely. But if they're down the list from more important security issues?
All security issues should be addressed as soon as they can be.
Absolutely. But if they're down the list from more important security issues?
Provided that employees arent biased to non Google products. If they find a critical flaw in Microsoft/Apple vs Google. I am not sure they reporting is going to exactly be fair in the public disclosure.
A group tasked to police itself isnt really the policing itself. Sorry dont buy it.
Apple and Microsoft should both start doing this too with Google software.
Why not do it with their own software, as opposed to worry about others.
...
Not every bug can be fixed in an arbitrary amount of time. 90 days is arbitrary and so is 14 days. We have had some bugs in our company's software that have gone unfixed for YEARS, despite dozens of people trying to fix them. Trying to find out 'why' or 'where' the bug occurs sometimes takes most of the time, fixing it sometimes just takes minutes after that.
However, on the flip side, if there are no 'deadlines' then there is no 'incentive' to get the bug fixed.
...
Do you think it would have been better for Google to report the vulnerabilities to CERT or IETF? I ask because Google gives companies 2X the window of CERT (45 days) and 3X the window of IETF (30 days). Honest question: Would you be as upset if CERT or IETF exposed the vulnerabilities? With them it would have been exposed up to 2 months before Project Zero did.
....
Yup, 90 days is plenty. As a consumer I don't even want it to take 90 days. And if a company, let alone a billion dollar behemoth can't do it in that time, then there are problems with the system they designed and/or the processes they have in place, and those should be fixed as soon as possible.
Why should we as consumers have sympathy about a company that we paid money to for not addressing security issues as soon as possible? How does any consumer think that which is against their own interests?
----------
They found an issue and it should be fixed. Why do people care why they found it or anytbing like that? The only thing that really matters to a consumer is that the issue was found and should be fixed as soon as possible.
Again if 3 months isn't enough time to fix it and test it then there are bigger issues they should resolving with their product and/or process or organization so that 3 months would be more than enough. From a consumer point of view even a month is too long.Imagine this.
You're a swing seller.
Then someone comes - your competitor that is - saying "your swing twists if you lean to the right, fix it by tommorow or I'll tell everyone about your flaw" all the while his swing also do the same or even worse.
You try to find the problem and found it, you fixed it but you haven't tested it yet. You're forced to release the fix and then the next day people complain the swing doesn't run smooth. Solving one problem leads to another.
Or if you couldn't found it, bad people comes and for whatever reason apply the flaw and broke the customer swings. While by normal use, there would be no problem and no bad people would break the swings.
----------------------
Point is, yes it's good to be found, but to release it publicly is another matter.
With limited time, there might be no time of them to test the fix and if other bugs occur.
And if they couldn't complete in time, they just invite hackers to attack the security breach
The technical know-how to figure out some of these security holes exists in about a dozen people in the world. Some of these bugs have been around since the 1970s (40 years)!
You must work for Fox News. You love to put words into people's mouths.
They're not incapable - maybe it's just not as important to them financially.
Training, hiring the most expert people in the field of cybersecurity, giving them the time and resources to fix the bugs....
Maybe Google is doing more here, but we don't know...
maybe Apple has fixed 1,000 internal bugs while Google points out 10. But we only hear about the 'Google 10' because Google makes it public for P/R.
I said SOME security holes require expertise to find, so they ALL can't be found just by hunting-and-pecking. Maybe that's all Google has managed to do - find the low-lying bugs, while Apple and Microsoft found hundreds and thousands more, but they don't want to trumpet like a peacock and tell everyone.
The problem I see that is that Google is highly immature when it comes to long-term support for products.
Microsoft and (to a lesser extent) Apple support products and operating systems for long periods of time. This is especially important in enterprise. For all the grief that people give Microsoft and Apple for breaking support between releases, they overall do an acceptable job. There are programs written in 1995 that can still be run without issue on a 2014 Microsoft operating system. And I really think Apple is going in this direction, as well, because they want a piece of the enterprise pie.
This has not been the case for Google. I work in enterprise IT, and we have tried to rely on Google products. So many times, they have pulled the rug out from under us with little warning like it was not a big deal. Google products come and go. And features come and go. And it happens way too quickly. By the time we train users on a Google feature and the users feel comfortable using it, it's gone. Google has screwed us so many times.
Even their e-mail platform constantly changes, and again, no warnings are given. We are looking, as we speak, of moving to a more stable platform. Google is not good for enterprise.
Even Chrome is unstable for enterprise. Deployment is completely different from Internet Explorer and Firefox. For IE and Firefox, you can just configure them how you want and then deploy the image to users. In Chrome, you can only use Group Policy to set Chrome settings. This is a recent change that they just sprung on enterprise with no real warning. So, enterprise deployed broken Chrome settings for a while before realizing Google made the change.
My point is that Google doesn't realize that many security bugs cannot be fixed on the fly. Fixing that bug might break all sorts of other things. That doesn't matter to Google because Google doesn't care. Many enterprises would rather live with a security bug for a while and have a proper fix that doesn't break other things than get an immediate fix. Google hasn't figured this out. It's why many enterprises that were previously putting many services on Google's platform are now looking for a way out.
Putting all that other unrelated Google stuff aside, 90 days isn't even close to being "on the fly".
Lot's of assumptions across the board and not much more.First of all, nothing I said is "unrelated." I typed it to contribute to my point. Sorry if the point went over your head.
Second, ninety days is extremely fast. Is it unreasonably short? That's debatable. But don't think for a second that it's a generous amount of time.
I am guessing that you have never worked on a large development project. Providing a fix will almost inevitably break something, and figuring out how those dominoes fall is difficult and takes time. In fact, they very well could give it lots of time and still not figure out all the effects that it will cause. What if the bug had existed for many years and there were third-party products that depend on the bug to work correctly? Those products will be broken as soon as the bug is fixed.
In addition, even if all the situations are figured out, customers (especially enterprise) has to be alerted. This means creating documentation to let customers know what the implications are and what their options are, if any, for work-arounds.
These are generally not considerations for Google because Google gives not the first damn about enterprise.
So no, ninety days is pretty quick.
Wait, so you think that I'm making "lots of assumptions" and yet you're the one that is assuming that "something must be wrong" because ninety days may not be sufficient enough time to fix a complicated issue?Lot's of assumptions and nothing more. If 90 days isn't enough then the underlying system should be changed or there are issues with it to begin with.
Wait, so you think that I'm making "lots of assumptions" and yet you're the one that is assuming that "something must be wrong" because ninety days may not be sufficient enough time to fix a complicated issue?
Yeah, I'm not taking you seriously and won't be replying to you, anymore.