Barney's Blog

Blog archive

Google Passes the Buck

There is a zero-day exploit that impacts Google's Chrome browser -- but it is definitely not Google's fault. Says who? Google.

Google is probably right, but blaming Adobe for this hole is bad PR. Microsoft doesn't play it this way, and doesn't slam third parties for such flaws.

OK, here is the skinny and then I'll get back to sarcasm: The flaw lets jerks slide past the Chrome sandbox and basically do whatever they want with your computer. I'm not sure how such a violation is totally Adobe's fault.

And while Microsoft releases monthly patches (and well-publicized explanations), Google disclosed the problem through Twitter. Adding to the misery, the tweets used an acronym I've never heard of. Here is one message from Chris Paoli's fine report: "It's a legit pwn, but if it requires Flash, it's not a Chrome pwn," wrote Chris Evans, Google's information security engineer and tech lead, in a Tweet this morning. "Do Java bugs count as a Chrome pwn too, because we support NPAPI?"

Am I stupid not knowing what ‘pwn' or “NPAPI” mean or is Evans a moron assuming that I do?

Does Google need to grow a pair as Microsoft has, or am I tragically biased? Biased and reasonable responses equally welcome at dbarney@redmondmag.com.

Posted by Doug Barney on 05/13/2011 at 1:18 PM


Featured

  • Office Mobile Apps To End as Microsoft Highlights New Office App

    Microsoft plans to end support for Windows 10 Mobile applications on Jan. 12, 2021, according to a Friday announcement.

  • Is Microsoft Finally Reinventing Office?

    Microsoft is testing out a new technology called "Fluid Framework." It could mean that Brien's dream of one Office app to rule them all might soon become reality.

  • Azure Active Directory Connect Preview Adds Support for Disconnected AD Forests

    Microsoft on Thursday announced a preview of a new "Cloud Provisioning" feature for the Azure Active Directory Connect service that promises to bring together scattered Active Directory "forests."

  • Microsoft Defender ATP Gets macOS Investigation Support

    The endpoint and detection response (EDR) feature in Microsoft Defender Advanced Threat Protection (ATP) has reached the "general availability" stage for macOS devices.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.