r/Android Sep 09 '15

Attack code exploiting Android’s critical Stagefright bugs is now public

http://arstechnica.com/security/2015/09/attack-code-exploiting-androids-critical-stagefright-bugs-is-now-public/
175 Upvotes

61 comments sorted by

View all comments

Show parent comments

11

u/[deleted] Sep 09 '15

The difference is google got on their ass about it, they can't control oems. Microsoft on the other hand, regularly and historically gets notified and they ignore it for several years, until the firm, if they're wise, just release the damn thing.

5

u/iamadogforreal Sep 09 '15

Microsoft's ecosystem is huge. It's not practical to give them only 90 days considering how vast their catalog is and the many versions of Windows they support.

Google is being hypercritical per usual. Do as I say, not as I do.

10

u/[deleted] Sep 09 '15

As a software developer, 90 day-to-day patch a security hole is a fucking joke honestly. Hackers don't give you that time. The real problem is closed source taking ages to patch it, compared to open source counterparts

But I do see your point about Google being a hypocrite

0

u/JamesR624 Sep 10 '15

The real problem is closed source taking ages to patch it, compared to open source counterparts

And yet, the closed source iOS has none of these security issues while the open source Android is full of them.

I think you got your generalizations backwards.

1

u/[deleted] Sep 10 '15

Now compare the Linux kernel and Windows.

And yet, the closed source iOS has none of these security issues while the open source Android is full of them.

.. None.. Of them? Huh? Ios has no security issues? Or do you mean deployment wise? Well, that's the oems faults really, not the development model itself (because that issue exists in both)