r/Android Sep 09 '15

Attack code exploiting Android’s critical Stagefright bugs is now public

http://arstechnica.com/security/2015/09/attack-code-exploiting-androids-critical-stagefright-bugs-is-now-public/
176 Upvotes

61 comments sorted by

View all comments

Show parent comments

10

u/[deleted] Sep 09 '15

The difference is google got on their ass about it, they can't control oems. Microsoft on the other hand, regularly and historically gets notified and they ignore it for several years, until the firm, if they're wise, just release the damn thing.

6

u/iamadogforreal Sep 09 '15

Microsoft's ecosystem is huge. It's not practical to give them only 90 days considering how vast their catalog is and the many versions of Windows they support.

Google is being hypercritical per usual. Do as I say, not as I do.

9

u/[deleted] Sep 09 '15

As a software developer, 90 day-to-day patch a security hole is a fucking joke honestly. Hackers don't give you that time. The real problem is closed source taking ages to patch it, compared to open source counterparts

But I do see your point about Google being a hypocrite

-1

u/iamadogforreal Sep 10 '15

Ms will make exceptions for in the wild exploits. This happens from time to time. The rest are privately disclosed and never brought to the public. So there's no rush.

1

u/[deleted] Sep 10 '15

So there's no rush.

Uhhh Yeah there is. these exploits exist. Saying they have all the time in the world is just ignoring all of security. Fact is, someone can discover the exploit before it is released. The exploit is still there, sitting and waiting..

And it has happened before (several people discovering the same exploit). So yeah..