It all started with the publication of a bug associated with Windows 8.1 in Google's Project Zero a couple of days before Microsoft distributed the fix. This led to a harsh response from Redmond, implying that Google seeks to embarrass its rival by risking user security. What did Project Zero do? It published two more bugs. The first only reveals basic information, but the second will not have an official patch until February.
The battlefield has been defined. Project Zero continues publishing information about bugs in different versions of Windows before Microsoft can fix them. Ironically, the platform meant to improve security in products outside Mountain View has become a distributor of 0-day vulnerabilities (or should we say “90-day” without patches?). Project Zero tries to protect itself with a small message at the bottom of each entry, highlighting that the process is automatic once the embargo days are exhausted. Still, the feeling for the user is like two rams butting heads for hours. And there's no short-term solution here.
What brings us here today are issues 127 and 128. The first has been classified by both parties as “no risk”, since it only exposes a limited amount of information related to a system's power configuration. In other words, Microsoft confirmed that it's not even serious enough to create a security bulletin, and consequently there will be no patch. The second is more complicated, as it involves a flaw in verifying user identity, which could cause encryption problems in shared data. The most interesting thing about Issue 128 is that Microsoft was going to publish the hotfix in the last “Patch Tuesday”, but discovered some compatibility issues during testing, causing its suspension until the second Tuesday of February. This delay caused the patch to fall outside Project Zero's 90-day threshold.
Microsoft's new statement appears to be a bit more moderate than the previous one. According to available information, no cyberattack has exploited these bugs, but Microsoft added that to use Issue 128, the attacker would need to exploit another vulnerability first. The point is that both companies' stances haven't changed, and opinions on the Web are polarizing quickly. On one side, many indicated that Google gives twice as much time as CERT when publishing bugs, and that Microsoft should speed up its timelines. On the other, they insist Project Zero is doing more harm than good, that the famous “Don't be evil” is forgotten, and Microsoft should return the favor by analyzing Android. Will we see a third round?
Ars Technica