User security is the top priority for most companies (or at least that's what they want us to believe), but interpretations of "good practices" in this matter can differ so much that two companies end up at odds. That's the case with Google and Microsoft, which are entering a new acid phase in their relationship over a bug in Windows 8.1 and the way Mountain View revealed it to the public.

Google and Microsoft at War Over a Bug
Windows 8.1

What Is Project Zero?

Before we begin, we need a bit of extra context: last July, the Mountain View giant presented Project Zero. The goal of this initiative is to identify bugs in products that are not related to Google but are of great interest in making the Web a little safer, such as operating systems and browsers. Project Zero reports these bugs to developers almost immediately and automatically establishes a "confidentiality agreement" with a 90-day validity, to give enough time to create patches. Once those 90 days are up, Project Zero releases to the public all the technical data about the bug, including the elements needed to reproduce it.

Issue 123 of Project Zero

What brings us here is the so-called Issue 123 of Project Zero, which deals with a privilege escalation vulnerability in the User Profile Service under Windows 8.1, in its 32-bit and 64-bit versions. The original report was written last October 13, but Redmond never prepared the corresponding hotfix. That caused Project Zero to publish something similar to a "0-day" in Windows 8.1.

Google and Microsoft at War Over a Bug
Microsoft didn't take kindly to the way Project Zero published the Windows 8.1 vulnerability.

Microsoft's Response

Needless to say, Microsoft is furious. Chris Betz, senior director of the Microsoft Security Response Center, took some time out to share his opinion about Project Zero's publication on one of the official blogs. First, he explains that Microsoft "disagrees" with the strategy of sharing all the information about bugs in an attempt to speed up correction processes, and that they believe in coordinated vulnerability disclosure. Betz also indicates that despite formally asking Google to delay the publication of the bug, the company decided to ignore this, even knowing that there were barely two days left before the hotfix appeared in Windows Update (today is the classic "Patch Tuesday"). To top it off, Betz basically accuses Google of putting Microsoft in a "gotcha" situation, instead of protecting users' interests.

The Other Side of the Coin

On the other side, we find that Google reported the bug for the first time on September 30, meaning Microsoft had more than 90 days to resolve the problem. Although some preconditions are necessary to take advantage of it, that doesn't diminish the vulnerability's importance, which generates the always-feared privilege escalations. Personally, I think it's a failure on both sides. Betz does everything possible to explain why they took so long to create the patch, but if a multinational corporation with Microsoft's resources needs more than a quarter of a year to fix a bug, it has a problem. And on Google's side, if barely 48 hours were enough to avoid this whole scandal, Mountain View should reevaluate its decisions in the future.