Barney's Blog

Blog archive

Google Passes the Buck

There is a zero-day exploit that impacts Google's Chrome browser -- but it is definitely not Google's fault. Says who? Google.

Google is probably right, but blaming Adobe for this hole is bad PR. Microsoft doesn't play it this way, and doesn't slam third parties for such flaws.

OK, here is the skinny and then I'll get back to sarcasm: The flaw lets jerks slide past the Chrome sandbox and basically do whatever they want with your computer. I'm not sure how such a violation is totally Adobe's fault.

And while Microsoft releases monthly patches (and well-publicized explanations), Google disclosed the problem through Twitter. Adding to the misery, the tweets used an acronym I've never heard of. Here is one message from Chris Paoli's fine report: "It's a legit pwn, but if it requires Flash, it's not a Chrome pwn," wrote Chris Evans, Google's information security engineer and tech lead, in a Tweet this morning. "Do Java bugs count as a Chrome pwn too, because we support NPAPI?"

Am I stupid not knowing what ‘pwn' or “NPAPI” mean or is Evans a moron assuming that I do?

Does Google need to grow a pair as Microsoft has, or am I tragically biased? Biased and reasonable responses equally welcome at [email protected].

Posted by Doug Barney on 05/13/2011 at 1:18 PM


Featured

comments powered by Disqus

Subscribe on YouTube