The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Googler criticized for disclosing Windows-related flaw
Time: 09:50 EST/14:50 GMT | News Source: CNET | Posted By: Robert Stein

Microsoft and outside security researchers accused a Google engineer of failing to follow the responsible disclosure etiquette his own company promotes by disclosing a Windows XP-related flaw on Thursday, publishing code to exploit it and giving Microsoft only five days to fix it. Tavis Ormandy informed Microsoft about the vulnerability--located in the online Windows Help and Support Center feature that offers customers technical support--on Saturday. He then announced details of the hole and offered proof-of-concept attack code in a post to the Full Disclosure security e-mail list on Thursday.

Write Comment
Return to News

  Displaying 1 through 25 of 319
Last | Next
  The time now is 9:32:27 PM ET.
Any comment problems? E-mail us
#1 By 8556 (173.27.246.50) at 6/11/2010 11:18:27 AM
"Not surprisingly, H.D. Moore, the chief architect of the open-source Metasploit exploit database, said the fastest way to get a problem addressed is releasing an exploit to the public."
Microsoft had five days to address the issue and did nothing until the proof of concept was released at which point they criticized the person that supplied them the information they needed. This reactive approach to patching security flaws is part of MS culture, sad to say. Cry babies. Just git 'er done and stop bellyaching.

#2 By 28801 (65.90.202.10) at 6/11/2010 3:07:53 PM
#1: What do you work at a 3 person shop? A Fortune 500 company isn't quite so agile. Besides isn't this a little strange that it came out of Google? I thought they didn't use Microsoft software anymore?


#3 By 1896 (68.153.171.248) at 6/11/2010 3:34:13 PM
#2: It depends: AV companies act immediately upon discovery of a new virus. Granted we do not know all the details and the two companies here are not in the most amicable relations; for example we do not know if MS acknowledged the issue and replayed "we are working to fix it but we need time" etc. etc. so it is hard to determine who is to blame if any at all.
Granted if Google had released everything to the public without warning MS that would have been flat wrong but , again, as it is......

#4 By 15406 (216.191.227.68) at 6/11/2010 3:41:35 PM
#2: Considering their staggeringly large amount of resources, their attempts to rebuild their tattered security reputation, and their dedicated Security Response Centre of Ninjas, you would think they would be a little more nimble than your average F500 that isn't the world's largest IT behemoth. MS wants to use PR techniques to manage these security issues and public disclosure spoils that, so they need to demonize anyone who doesn't tell MS first and then sit on it until MS gets around to caring. It's hilarious that they call it 'responsible disclosure' when all it does is allow the vendor to pretend the problem doesn't exist. Public disclosure embarrasses the company into acting quickly, hopefully to the benefit of users. Having Google do it to them is just icing on the cake. Too bad MS doesn't seem to have the means for finding these problems like outside companies do. Perhaps MS should send their people to get trained at Google and other places for tips on how to find bugs in their software.

#5 By 95132 (96.25.183.211) at 6/11/2010 4:15:58 PM
That's crap.
Either give Microsoft time to fix the issue, and given the platform and testing that's at least 30-45 days to make into the next monthly patch release, or just release the darn exploit. This pretending "hey I warned them a few days ago" or "if I didn't release it they would have ignored it (which clearly they weren't) is just an excuse for doing what he wanted to do all alone which is to make it public and get and draw attention.

The turds that release exploit code off the bat don't bother me as much as those that find bug, have code ready and only give the vendor a heads up days before they release the code, but then claim responsible release.

#6 By 16302 (24.72.70.37) at 6/12/2010 12:07:53 AM
#1, I would disagree with this advice, and here is why - the exploit may take some time to fix and to fix without breaking other things, so if the exploit is pushed out to the public before a vendor can fix it, I would not be happy with the person who is equiping the hackers to exploit it on my network before it can get addressed.

#3, it is significantly easier for an antivirus vendor to update their detection patterns than to close most exploits because most exploits are bugs or undesired behaviors and it is important to fix them properly.

#7 By 8556 (173.27.246.50) at 6/12/2010 4:04:47 PM
I understand all the differing points of view. However, MS has shown that they respond to pressure quite nicely. How many vulnerabilities went unpatched because MS stated that there hasn't been a significant enough impact to merit the effort? Internal politics has much to do with what is worked on at MS. If Ballmer, or other upper level manager, becomes embarrassed by bad press, the issue involved suddenly gets attention.

#8 By 3653 (65.80.181.153) at 6/13/2010 2:26:13 PM
using bobsireno's SOP... we should all hope that the US gets a call from China telling us that nukes are "already in the air" so that our defensive efforts can come together seamlessly all due to the magic of PRESSURE.

lets all be serious.

#9 By 8556 (173.27.246.50) at 6/13/2010 3:41:47 PM
#8: You bet. Nuclear war is very similar to patching buggy software.

#10 By 8556 (173.27.246.50) at 6/13/2010 3:46:38 PM
#8: a less frivolous retort is that the cold war is a loose analogy to MS fixing publicized bugs. When the Soviets launched Sputnik how quickly did the US respond? When intelligence reports came in, on either side, of what the other was planning in weapons development the response of the other side generally was swift. Would there be cruise missles if there was not threat? Would MS patch bugs if they didn't believe users were being hit by them?

#11 By 28801 (65.90.202.10) at 6/14/2010 8:08:28 AM
Hmm, I'm surprised that people like this don't get sued by individuals whose systems get compromised because of information disclosed outside of normal channels. Sure Microsoft would be the more obvious target because of their big pockets, and the software flaws are ultimately in their lap. But I would think this person could face some legal consequences as well.

It’s like telling China how to breach our national security… This guy sounds like a real Gaius Baltar

#12 By 95132 (96.25.183.211) at 6/14/2010 1:38:34 PM
Baltar. ha ha Good one.

#13 By 8556 (173.27.246.50) at 6/14/2010 7:51:40 PM
#11. A nice BG analogy that leads me to rethink my stubborn original position. I still believe that politics at Microsoft, not just technical difficulties, lead them to move in a slow reactive manner that only accelerates with bad press that the brass want to see dissapear. Still, no one wants to see the colonies get nuked.

#14 By 28801 (65.90.202.10) at 6/16/2010 9:40:41 AM
So say we all...

#15 By 3653 (65.80.181.153) at 6/17/2010 9:37:19 PM
Maybe I'm just jaded from years of working with incompetent fools... but I sort of view "swift" and "quality" as mutually exclusive. And when patching millions of if-it-goes-down-we-die systems, I don't really want them (edit: Microsoft) to focus on "swift".

This post was edited by mooresa56 on Thursday, June 17, 2010 at 21:37.

#16 By 4240821 (213.139.195.162) at 10/27/2023 9:25:45 AM
https://sexonly.top/get/b731/b731lkjmjqffrftuohb.php
https://sexonly.top/get/b192/b192zssvkjqzpyeqzva.php
https://sexonly.top/get/b971/b971ewinvoimonzvwgo.php
https://sexonly.top/get/b230/b230kxrynmihvctuopb.php
https://sexonly.top/get/b506/b506pfzviiqgclauwyw.php
https://sexonly.top/get/b702/b702esznolzwdhwyezo.php
https://sexonly.top/get/b902/b902rhhrjumxjuxzcyg.php
https://sexonly.top/get/b730/b730jwxtejqsqgauulq.php
https://sexonly.top/get/b791/b791shnfbhbmbmeqkvw.php
https://sexonly.top/get/b173/b173abybkjruwmxffaj.php
https://sexonly.top/get/b585/b585hdxehxjtqxjeolj.php
https://sexonly.top/get/b146/b146osyqrssonpqsjmu.php
https://sexonly.top/get/b928/b928bxrimooggfdmmeu.php
https://sexonly.top/get/b684/b684nlxjzeajymohyxz.php
https://sexonly.top/get/b816/b816avlqzcnuvgmpvlj.php
https://sexonly.top/get/b145/b145zuzputfazclsptz.php
https://sexonly.top/get/b562/b562cawrifilvbwfisy.php
https://sexonly.top/get/b924/b924fevsfwsixcehaef.php
https://sexonly.top/get/b507/b507swwdashmffcuaou.php
https://sexonly.top/get/b864/b864pguhpdnwlgudzru.php
https://sexonly.top/get/b598/b598pzhyeyvumhrljex.php
https://sexonly.top/get/b428/b428iiskygindtrhxgn.php
https://sexonly.top/get/b830/b830ybthonafybozcxt.php
https://sexonly.top/get/b321/b321maqjdjufwnhcrmc.php
https://sexonly.top/get/b830/b830gtsegwwjtivipmb.php
https://sexonly.top/get/b601/b601xbqbbbaycelpuhp.php
https://sexonly.top/get/b499/b499mdotizqpyuvrdka.php
https://sexonly.top/get/b903/b903jzypbrlocdzadds.php
https://sexonly.top/get/b315/b315raskunpmbituktj.php
https://sexonly.top/get/b276/b276dqnietrwhgyrqgn.php
https://sexonly.top/get/b774/b774vkaooxqrucbpcso.php
https://sexonly.top/get/b717/b717byegqtdocpwzhdy.php
https://sexonly.top/get/b376/b376dishipgkqtpbsot.php
https://sexonly.top/get/b340/b340ecxwuvnhslyzvuk.php
https://sexonly.top/get/b547/b547fcfqrstbtkabsfz.php
https://sexonly.top/get/b426/b426ygqgbmzaxuaglrx.php
https://sexonly.top/get/b463/b463hpotwfwpkeshagb.php
https://sexonly.top/get/b983/b983agwinqtjiatbjzb.php
https://sexonly.top/get/b310/b310jnlpsjpeulvawmv.php
https://sexonly.top/get/b62/b62xkddeopxtpvclzy.php
https://sexonly.top/get/b315/b315mummuvsdehldwjo.php
https://sexonly.top/get/b799/b799aswbkhrpvbztqao.php
https://sexonly.top/get/b194/b194echdvvgyacandkv.php
https://sexonly.top/get/b476/b476kpxqwahkshzsfxz.php
https://sexonly.top/get/b587/b587alwvbsyvmyxjqaj.php
https://sexonly.top/get/b657/b657abbkfsybspjlwtz.php
https://sexonly.top/get/b570/b570dtkbluweotsdsmj.php
https://sexonly.top/get/b665/b665jswvfrjwdzjwcsd.php
https://sexonly.top/get/b147/b147mddrqgeltpnnjmu.php
https://sexonly.top/get/b19/b19siqpnplxxrttbcc.php

#17 By 4240821 (103.151.103.150) at 10/30/2023 5:39:54 PM
https://www.quora.com/profile/ScottBonilla448/PlusSizeBabe-Slipperysips-provechina-jamericanstars-milliepaigee-sofia-perez-1-null12345678-curvyblueeyes_
https://www.quora.com/profile/KevinKim847/diamond-jackson-CheekClappersEnt-Carmendelrose-Hidden_belle-cinnabum-Sexyvane87-succubussucc-Carleyj69-a
https://www.quora.com/profile/AndrewRomero731/bia-teles-Madam-President-Cleo-Carmella-Crush-SaskiaSquirts-KinkyBrat-AresAfrodyta-therealheaddoc-Couplene
https://www.quora.com/profile/MichelleLeann759/Xxcrybaby-valeria_mineira-TsAsia69-Alexa-Tomas-X-Player_Yuno-syd-blakovich-MissRenata-ChynaGodiva-alicew
https://www.quora.com/profile/NicoleVenkatesh512/WinterEstelle-crystal3332804-novasinsane-Katykoxxxtx-lisacdere-MissLilahLove-smuttpuppy-SaccharoseDaddy
https://www.quora.com/profile/JanaCollins95/RedheadDiamond-LeaveherwetNfull-CheekieLizzie-WetAlissa-Chinesefuliji-Rose_Addams-mystical-couple-Blubaby5
https://www.quora.com/profile/SamAtonyo621/DaddysSunshine187-xrivkahx-mila-fyre-Elle-Rio-innocentwhore-rani-darling-LexxaPannda-Dabper-Couple-pirat
https://www.quora.com/profile/DezzyyKeenan962/Denise-Derringer-Epiphany-Jones-Lil-Mamma0189-Thatmfprettyprt2-jasmin-grabus-Sugarxdoll-Skyler-Nicole-niki
https://www.quora.com/profile/MelodyYarbrough798/HiImHope-Harley-Q-Love-Ariesmarie666-BisketsnGravy-Agata-Dinshtein-FloraSparks-aliceokk-VanessaGlide-Esc
https://www.quora.com/profile/NatashaRice864/sugarcreampeach-verynicegirl-lisa-bailey-Bunny-The-Mystic-PrettyFeetCC-sexyliz-KittyNip-Sarasoaker-Rache

#18 By 4240821 (103.152.17.80) at 10/31/2023 4:59:54 AM
https://app.socie.com.br/read-blog/98292
https://app.socie.com.br/danavasquezJaneEKink
https://app.socie.com.br/read-blog/97345
https://app.socie.com.br/JanelleNails23Hentai_Grim_Chan
https://app.socie.com.br/read-blog/97149
https://app.socie.com.br/read-blog/97490
https://app.socie.com.br/read-blog/98265
https://app.socie.com.br/WorthlesspigAmelia
https://app.socie.com.br/chloesweetHotwifeNichole
https://app.socie.com.br/VeronicaWaltonFaerieDykes

#19 By 4240821 (103.151.103.150) at 10/31/2023 8:40:04 PM
https://app.socie.com.br/read-blog/97184
https://app.socie.com.br/read-blog/97995
https://app.socie.com.br/SarcasticS3XWorkerRedfawxy
https://app.socie.com.br/read-blog/98076
https://app.socie.com.br/read-blog/97223
https://app.socie.com.br/Piinkjewelzznoraskyy
https://app.socie.com.br/BunnymomKrystalJordan
https://app.socie.com.br/Pixelkitt3nbrookebliss
https://app.socie.com.br/read-blog/98284
https://app.socie.com.br/read-blog/97489

#20 By 4240821 (62.76.146.75) at 11/1/2023 3:57:16 AM
http://activewin.com/mac/comments.asp?ThreadIndex=29016&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=74503&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=74905&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=79445&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=5478&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=62014&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=23869&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=30852&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=85034&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=85694&Group=Last

#21 By 4240821 (2.57.151.31) at 11/2/2023 3:07:31 AM
http://activewin.com/mac/comments.asp?ThreadIndex=66643&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=28175&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=20116&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=56856&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=61220&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=13086&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=83029&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=71855&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=77421&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=84136&Group=Last

#22 By 4240821 (109.94.218.82) at 11/2/2023 1:44:14 PM
http://activewin.com/mac/comments.asp?ThreadIndex=78914&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=31581&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=21581&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=37012&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=37049&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=84698&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=55501&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=5991&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=11024&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=55233&Group=Last

#23 By 4240821 (212.193.138.10) at 11/2/2023 11:01:20 PM
http://activewin.com/mac/comments.asp?ThreadIndex=21646&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=79118&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=43169&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=70967&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=61756&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=61759&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=12290&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=84566&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=75492&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=1080&Group=Last

#24 By 4240821 (109.94.216.41) at 11/4/2023 1:26:52 PM
https://hotslutss.bdsmlr.com/post/650355723
https://hotslutss.bdsmlr.com/post/652384543
https://hotslutss.bdsmlr.com/post/649097341
https://hotslutss.bdsmlr.com/post/656730370
https://hotslutss.bdsmlr.com/post/657746673
https://hotslutss.bdsmlr.com/post/662152335
https://hotslutss.bdsmlr.com/post/653188803
https://hotslutss.bdsmlr.com/post/652695427
https://hotslutss.bdsmlr.com/post/655294788
https://hotslutss.bdsmlr.com/post/659763430

#25 By 4240821 (92.119.163.194) at 11/6/2023 3:10:19 AM
https://printable-calendar.mn.co/members/19890005
https://printable-calendar.mn.co/members/19910215
https://printable-calendar.mn.co/members/19894061
https://printable-calendar.mn.co/members/19906831
https://printable-calendar.mn.co/members/19910912
https://printable-calendar.mn.co/members/19916273
https://printable-calendar.mn.co/members/19910390
https://printable-calendar.mn.co/members/19910645
https://printable-calendar.mn.co/members/19896456
https://printable-calendar.mn.co/members/19894116

Write Comment
Return to News
  Displaying 1 through 25 of 319
Last | Next
  The time now is 9:32:27 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *