Slashdot Mirror


Opera Screeches at Mozilla Over Security Disclosure

The Register is reporting that Mozilla's handling of a recent security exploit that affected both browsers has drawn an unhappy response from the Opera team. "Claudio Santambrogio, an Opera desktop developer, said the Mozilla team notified it of a security issue only a day before publishing an advisory. This gave the Norwegian software developers insufficient time to make an evaluation. [...] Santambrogio goes on to attack Mozilla's handling of the issue, arguing that it places Opera users at unnecessary risk."

61 of 208 comments (clear)

  1. All Things Considered... by neonmonk · · Score: 5, Insightful

    At least Mozilla told them of the issue. I personally don't think it's their ultimate responsibility. Definitely obligated to do something... but imagine the kind of action Opera would have if Microsoft found the security flaw.

    1. Re:All Things Considered... by allcar · · Score: 5, Insightful

      I agree that they probably fulfilled their minimum obligation, but it would be great to see a much higher degree of co-operation between the vendors of minority browsers. By all means attack MS in this way, but play nice amongst the good guys.

    2. Re:All Things Considered... by moderatorrater · · Score: 5, Insightful

      I don't see it as an attack. It sounds like Opera didn't respond to Mozilla's notification at all. In addition, it's not Mozilla's obligation to make sure that Opera's secure, and it is their obligation to be open with the community to the extent that they can be while still being secure. Sometimes waiting to disclose can bite you in the end like it did with php a few months back. Add to that the bullshit excuse that you can't evaluate a security risk in one day and I think that Opera's just lashing out because they're embarrassed that they have a security flaw.

    3. Re:All Things Considered... by pthisis · · Score: 5, Insightful

      I agree that they probably fulfilled their minimum obligation, but it would be great to see a much higher degree of co-operation between the vendors of minority browsers. By all means attack MS in this way, but play nice amongst the good guys.

      Full public disclosure of security bugs is generally considered the best way to get rapid fixes, and was the entire reason that places like BugTraq were founded. Following standard protocol is not an "attack". Vendors like to assume that you're just maliciously publishing things that would be no problem for their users until you did so. That's untrue.

      Many bugs are well-known by black hats before they are found by the good guys. The safest thing for users is to assume that all severe bugs are well-known by the bad guys; when you disclose publically, you give the users a chance to protect themselves even if the software is not yet fixed. I'm not sure of the details of this exploit, but they may be able to protect themselves by limiting their surfing to well-known trusted sites, using an alternate browser, or turning off javascript or whatever. In other cases, some sort of external wrapper or proxy, tighter firewall rules, limiting access to DMZs, or other external steps can help prevent big security problems even without a full vendor fix available yet. It may even be worth it to some users just to forgo using an application for a few days until it's fixed.

      Keeping silent until the vendor fixes things might just hurt the user's security situation, and certainly doesn't give the user the option of evaluating the risk and determining whether it's worth ignoring it or not--it forces them to make their usage decision without good information.

      --
      rage, rage against the dying of the light
    4. Re:All Things Considered... by saltydog56 · · Score: 3, Insightful

      Attack? How did any of the Mozilla devs attack Opera - from what I can see no public mention was ever made about Opera having the same issue.

      Further, why would you encourage others to "attack MS in this way?" - that is stupid and unprofessional. I am a committed Linux user, in my free time I build and test each kernel snapshot as it is released. Why, because I love to get into the guts of the system.

      Am I a Windows lover? Not really, but I do bring up an XP image from time to time as a guest on my Linux system. I have an older IBook running OSX which is the central core of my music system.

      I even have a system up and running IBM's MVS 3.8 for those days when I really miss the old days of mainframes punch cards.

      Each of these systems has its good points and its bad points, I stick with Linux because I CAN get into the guts of the system. I keep my thumb on the pulse of all these Operating Systems because I love being close to the hardware.

      That said I have NEVER seen any vendor come out and invite an attack on a rival OS by detailing a security hole in public. Balmer may be a fool with his rants on Microsoft's perceived superiority but even he doesn't come out and discuss the details of anyones security issues.

      So why would you encourage it?

    5. Re:All Things Considered... by Anonymous Coward · · Score: 4, Insightful

      > it's not Mozilla's obligation to make sure that Opera's secure

      True, but surely Mozilla has a moral obligation to ensure that other browsers (and ultimately, users) have as much time as possible to prepare for when the exploit becomes public domain?

    6. Re:All Things Considered... by WhatAmIDoingHere · · Score: 3, Insightful

      Yes, because it means that people look HARDER for the bugs in both browsers and release information about them to the public faster, meaning they'll be patched MUCH faster than a bug report sent through some behind the scenes emails.

      --
      Not a Twitter sockpuppet... but I wish I was.
    7. Re:All Things Considered... by mdwh2 · · Score: 2, Insightful

      Fair enough. I think there are arguments to make on both sides - but whichever one's point of view is, both sides are reasonable positions I think. I just don't understand why one side of the argument here seems to get such contempt, just because Opera's involved.

    8. Re:All Things Considered... by bigdavesmith · · Score: 4, Insightful

      Agreed, and I think it's a very poor way to handle the situation, from Opera's side. If I were Mozilla, and got this kind of junk after reporting the bug to them, next time around I wouldn't even bother. Someone at Opera owes someone at Mozilla an apology.

    9. Re:All Things Considered... by SETIGuy · · Score: 4, Insightful

      > it's not Mozilla's obligation to make sure that Opera's secure

      True, but surely Mozilla has a moral obligation to ensure that other browsers (and ultimately, users) have as much time as possible to prepare for when the exploit becomes public domain? That obligation is trumped by Mozilla's moral obligation to make sure that people who use Mozilla are not vulnerable to an exploit.
    10. Re:All Things Considered... by nigelo · · Score: 5, Insightful

      Am I missing something?

      The problem was reported in November and fixed in early February.

      Clearly, this is longer than one day.
      Following the links in other posts to the mozilla issue tracking, it apparently took a while to fix.

      The Opera guys would have liked a little more heads-up than one day, that's all, and that doesn't seem unreasonable to me.

      Why all the high-and-mighty whining about 'if they really cared they would have fixed it'?

      --
      *Still* negative function...
    11. Re:All Things Considered... by aussie_a · · Score: 2, Insightful

      So you think Mozilla told Opera within 24 hours of finding out themselves? If not, then how is Mozilla's users made vulnerable by telling Opera earlier?

    12. Re:All Things Considered... by olehenning · · Score: 2, Insightful

      I don't see how that obligation stands in the way of responsible disclosure. How would it take Mozilla any longer to fix the problem if they tell Opera about it in good time? Don't get me wrong. I'm not saying that Mozilla has done something extremely wrong here. I'm just saying they could have done it better, followed responsible disclosure properly and given Opera developers time to fix it before they went for full disclosure.

    13. Re:All Things Considered... by eam · · Score: 2, Interesting

      Considering that their browser is open source, how do they release the fix and still hold back on the details?

    14. Re:All Things Considered... by Fordiman · · Score: 2, Informative

      Why is Mozilla responsible for Opera's poor QA? It may be that one of the MozDev's, late in the game, was poking around and said, "Hey, guys. Did you notice this exploit works in Opera too? We should phone 'em up."

      --
      110100 1101000 1101000 1100110 0 1101111 1101000 1100011 1
    15. Re:All Things Considered... by Ilgaz · · Score: 2, Insightful

      I agree that they probably fulfilled their minimum obligation, but it would be great to see a much higher degree of co-operation between the vendors of minority browsers. By all means attack MS in this way, but play nice amongst the good guys. There are very advanced developers at Opera too, remember these guys manage to code a 90 KB J2ME single binary which may work in hundreds of millions of mobile phones (Opera Mini) or a browser small enough to run on various kinds of Symbian smart phones.

      Also these guys are browser developers, same job...

      I am near sure they see some potential issues on Mozilla source sometimes and silently inform them about them. If this happened, I can understand their frustration about a hit from "nice guys".

      Of course, these are guesses only and I don't even run Opera until they release 9.26/9.50 final on OS X Leopard.
  2. First... by hsdpa · · Score: 5, Funny

    to fix the exploit wins!

    --
    :(){ :|:& }:;
  3. Oh bitch, bitch, bitch! by Enuratique · · Score: 3, Interesting

    Listen, would you rather they give you no advanced warning? Like chivalry, professional courtesy is all but dead these days. What are they supposed to do? Wait until you get your ass in gear to address the issue? Perhaps letting the weakness be known might actually give you the incentive to make it a top priority bug fix - which is good for everyone.

    --
    A black hole is where God divided by 0
    1. Re:Oh bitch, bitch, bitch! by smittyoneeach · · Score: 2, Funny

      s/bitch/advertise/

      --
      Get thee glass eyes, and, like a scurvy politician, seem to see things thou dost not.--King Lear
  4. Sheesh... by TripMaster+Monkey · · Score: 3, Interesting
    From TFA:

    Claudio Santambrogio, an Opera desktop developer, said the Mozilla team notified it of a security issue only a day before publishing an advisory. This gave the Norwegian software developers insufficient time to make an evaluation. "They did not wait for us to come back with an ETA for a fix: they kept their bug reports containing the details of the exploits closed to the public for a few days, and now opened most of them to everybody," Santambrogio writes.

    I'm finding it a bit difficult to feel bad for Opera. Exactly how long does it take to "evaluate" a security issue, especially when someone else goes to the trouble of finding it in the first place, and then notifies you of the issue?

    Opera had ample opportunity to roll out a fix...but they dragged their feet (as is their habit). This time, their habit got them burned. Perhaps next time they'll take a notification of a security issue more seriously.
    --
    ____

    ~ |rip/\/\aster /\/\onkey

    1. Re:Sheesh... by xactoguy · · Score: 5, Informative

      From the Opera developers' description it appears that the Mozilla foundation could have handled things more professionally - Opera was only notified the day before a public advisory was published, and since that time the Mozilla foundation have opened most of the bug reports containing exploitation details to the general public. Judging from the emoticons on Opera's blog, the latter action by the Mozilla foundation is the primary issue here, not that they published the advisory.

      --


      And so we go, on with our lives
      We know the truth, but prefer lies
      Lies are simple, simple is bliss
    2. Re:Sheesh... by drinkypoo · · Score: 4, Insightful

      Opera was only notified the day before a public advisory was published, and since that time the Mozilla foundation have opened most of the bug reports containing exploitation details to the general public. Judging from the emoticons on Opera's blog, the latter action by the Mozilla foundation is the primary issue here, not that they published the advisory.

      I think we all know already that disclosing the exploit is what brings the motivation to fix the hole.

      The fact that they hid the bug reports at all should be enough to make the Opera kids grateful. After all, the Mozilla foundation operates in a pretty open and transparent fashion. The most honest (and destructive) way to go would be to never hide the bug reports.

      But just to cover that old ground once again; when code changes, diffs happen automatically, and people know just precisely what changed. You can be sure that some of those people are malicious hackers looking for new ways to screw us all; there's good money in it. So by hiding the details of the exploit, you make sure that only the more skillful and malicious hackers have the exploit. Does that sound like a good idea to you?

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    3. Re:Sheesh... by NMagic · · Score: 5, Insightful

      You know, looking at Mozilla's release, they didn't seem to mention anything to anybody about Opera having a problem too. Looks more like Opera screwed themselves.

    4. Re:Sheesh... by Jeff+DeMaagd · · Score: 2, Insightful

      But allowing only one day is excessive. Can you track down and fix security problems in your software within one day of notification?

      I think we all know already that disclosing the exploit is what brings the motivation to fix the hole.

      You haven't given a specific example of Opera needlessly hiding an exploit.

    5. Re:Sheesh... by moderatorrater · · Score: 4, Insightful

      Unless for some reason they use the same engines, what's the problem with this practice? Opera's security isn't Firefox's responsibility. The fact that they notified opera at all went above and beyond what they needed to do, and asking firefox to be less open with their community is asking them to risk their image for the sake of opera and its users. Unless I'm missing something here, Firefox was being polite and Opera's throwing a world class hissy fit.

    6. Re:Sheesh... by pthisis · · Score: 5, Insightful

      But never hiding bugs is silly. For example, if you provide an strace of ssh crashing, you'd want to mark that private at least.

      Maybe, maybe not. You never know what the black hats already know; as a _user_ of ssh, if you disclose then I can take steps to limit damage--e.g. if I'm allowing full ssh access from outside my network (so that employees can work on the go), I may decide that the small benefit of doing so doesn't merit the risk. I'd rather turn off external ssh access for a few days until there's a fix.

      When you hide the bug, you're hiding the ability for the users to take steps to protect themselves. You're forcing me to run with exposed systems for several days, and hoping that nobody "bad" knows about the bug. And you're making that judgement for your users rather than giving them the ability to make that call themselves; that's almost impossible given that the judgement might hinge heavily on whether I'm a large financial institute or a personal blog site that backs up daily. Just guessing that most users are happy with your security through obscurity is bound to be wrong in some cases, and those cases are likely to be some of the more financially significant ones.

      (That's on top of the pressure to issue a real fix that full disclosure brings. Before things like BugTraq, it was common for people to sit on severe security bugs for literally _years_.)

      --
      rage, rage against the dying of the light
    7. Re:Sheesh... by drinkypoo · · Score: 5, Interesting

      But allowing only one day is excessive. Can you track down and fix security problems in your software within one day of notification?

      Now, wait a second. If I am developing software package "A", and you develop competing package "B", and I find a hole in A and fix it, then just for laughs test to see if your product has the same hole and then I am kind enough to let you know that it does, then I announce that there is a hole in A, how am I responsible for the security of B at all? I've done you a favor by performing the test and giving you a heads up in the first place! I don't owe you anything.

      I think we all know already that disclosing the exploit is what brings the motivation to fix the hole. You haven't given a specific example of Opera needlessly hiding an exploit.

      I'm not sure what you think that has to do with anything. The Mozilla foundation didn't even announce to the public that there was a hole in Opera. The announcement is that there is a hole in Firefox. Why not try reading the advisory? There is NOTHING in there about Opera's susceptibility. You can't even view the bug report without a Mozilla bugzilla account with the proper access - I just logged into my account, and that doesn't include me, so it's not like even the report is generally available. Also, as per the advisory:

      These bugs are variations on earlier problems reported by Charles McAuley and Michal Zalewski which were fixed in Firefox 2.0.0.4, as well as an issue reported by hong which was fixed in Firefox 2.0.0.8.

      So it seems as though the Opera team has had some warning about problems similar to these in the past - along with the rest of the world.

      Could I find and fix a bug in one of my pieces of software in a day? Probably, because all of them are very simple. If I had a development team and a security response team (they do have one of those, don't they?) then I bet "I" could find and fix known security problems in larger software products in a day, too.

      Actually, a number of security holes in the Linux kernel have been found, announced, and fixed on the same day, now that I think of it.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    8. Re:Sheesh... by Jugalator · · Score: 2, Insightful

      When you hide the bug, you're hiding the ability for the users to take steps to protect themselves. Yes, it's definitely a case of finding an equilibrium when being curteous in giving software developers around the world affected by the same vulnerability a reasonable time to adapt.
      --
      Beware: In C++, your friends can see your privates!
    9. Re:Sheesh... by BZ · · Score: 2, Informative

      I just checked, for what it's worth. This bug has never had the security flag removed.

  5. I must be missing something here... by moderatorrater · · Score: 4, Insightful

    As far as I can tell, Firefox had a flaw, they fixed it and notified Opera that they had the same flaw the day before Firefox's fix was announced. Sounds to me like the only thing that Firefox did wrong was notice that it affected Opera at all, because if they hadn't Opera would have been left with egg on their face and nothing to bitch about.

    1. Re:I must be missing something here... by Jester998 · · Score: 5, Funny

      Clearly, the Mozilla team should be performing full regression testing on every bug they fix against every browser known to man. What if the bug affects NCSA Mosaic?

      Hmm, there's something wrong with my sarcasmeter, it seems to be off the scale...

    2. Re:I must be missing something here... by sholden · · Score: 5, Insightful

      So mozilla should have left their users open to the big for longer, by delaying the fix so that Opera can catch up?

      Or are you saying they should have released the fix and not mention what it was fixing - making it less likely people would apply the fix (plus it's open source not saying what it's fixing doesn't really keep it secret)?

      Note that mozilla never mentioned Opera in the advisory anyway.

      So what you're really saying is that Mozilla should pass all it's security fixes past Opera and IE and Safari and Konqueror and etc and not release them until all of those competitors have said "OK we've fixed it too".

    3. Re:I must be missing something here... by i.of.the.storm · · Score: 3, Funny

      (Sorry, I couldn't resist) His sarcasmeter- it's OVER 9000!!!!!!!!!

      --
      All your base are belong to Wii.
    4. Re:I must be missing something here... by Otter · · Score: 3, Insightful
      Clearly, the Mozilla team should be performing full regression testing on every bug they fix against every browser known to man.

      I think the point is that they *did* know that this particular vulnerability affected Opera and took their time about telling them.

      It still doesn't seem like a huge deal, but on the other hand if you read what the Opera guy actually wrote, it also doesn't seem like a huge deal. "Screeches" seems a bit excessive.

    5. Re:I must be missing something here... by saltydog56 · · Score: 5, Insightful

      You know, maybe I am blind, or perhaps just a little slow today, but I looked at the actual advisory (did you?) and I see no mention of the fact that the same bug impacted the Opera browser.

      What I seem to get from the article is that a problem was found with Firefox, a fix was developed, and sometime prior to wrapping things up and deploying the fix, someone at Mozilla cared enough about the Internet environment we all share to do a quick regression test of Opera and when a problem was discovered, they PRIVATELY notified the Opera team.

      What more could you ask for in the way of good citizenship?

    6. Re:I must be missing something here... by Sentry21 · · Score: 2, Funny

      Oh, a sarcasm detector. That's useful.

  6. overreaction by kongit · · Score: 2, Insightful

    While I do not know all of the details behind this I suspect that Mozilla did not have to notify Opera of any bug, in other words they did it as a heads up but were not obligated, I could be wrong though. The article is rather short and does not explain anything. For all I know Mozilla gave Opera the info as soon as they knew it, I highly doubt this, but just from the article it is hard to tell. While Mozilla could have waited, I would bet that people with malevolent intent are not overly concerned with the small Opera user base. I think that the over all the risk to the end user of the Opera browser is not much, and that the developer needs a chill pill. I know that Mozilla is not perfect, but I think that they had a good reason for releasing details about the problem. I do not know the reason, but knowing that there is a problem and that there is an update might make people more inclined to update to the safer version. So Opera fix the problem on your browser too, guess what you can look at Firefox's source code to see how the Mozilla developer's fixed theirs, and the developer with an pineapple stuck up somewhere needs to take a laxative or something.

    1. Re:overreaction by Fweeky · · Score: 4, Interesting

      I don't see how expressing dipleasure at something on a blog is an overreaction. "Screeching" is stretching it pretty fucking far, since it's basically saying what happened. Where in the blog entry is there screeching, perhaps the bold on "responsible", or maybe the ":("? Wouldn't it be better to link to the blog entry directly and not some dumb opinionated elreg article? Really, did you even read the original source before deciding "the developer needs a chill pill"?

      At the end of the day, Mozilla would have acted better by keeping the exploits closed for a few more days, as they would hope anyone else would do for them. By not doing so, they upset people, and others expressing that upset is perfectly understandable. There's no mass outcry at Opera, no press release or open letter saying the Mozilla team are dicks, there's a few words saying what happened and a couple of emoticons on a developer blog entry.

  7. See this? by imipak · · Score: 3, Funny

    >>>>> . It's the world's smallest violin...

  8. the alternative being...? by rsw · · Score: 4, Insightful

    Let's imagine that the Mozilla developers had modified the release notes for 2.0.0.12 so that it wasn't obvious what they'd fixed. Would that have been any better? Of course not. I can grab the code, diff against 2.0.0.11, take note of the changes, and presumably figure out why they were made. Now I can craft a working exploit against 2.0.0.11. After testing it on Firefox, what's the first thing I might try? How about... see if other browsers have the same problem?

    So keeping in the fix but not mentioning it in the release notes is out. What, then... not patch the flaw? Yeah. Right.

    Opera might be a nifty browser, but apparently its authors are whiny bitches.

    -=rsw

  9. Apologies! by Jester998 · · Score: 3, Funny

    As a Firefox user, I'd like to apologize to Opera users (both of you) for leaving you exposed.

    Next time we'll just let you figure it out on your own.

  10. Streisand effect? by Epsillon · · Score: 4, Interesting

    Seems if they'd kept their whiny mouths shut, nobody would have realised from the vulnerability disclosure that the issue affects Opera. Now EVERYONE knows, from the kiddie scripting 'sploits to the IT manager planning the software deployment for the next few months, who is now seeing why closed-source Opera isn't really such a great choice after all. Even the CVE entry doesn't disclose Opera's vulnerability to this bug. Still, it makes good comedy if nothing else...

    --
    Resistance is futile. Reactance buggers it up.
    1. Re:Streisand effect? by Hatta · · Score: 2, Insightful

      Exactly. Not only does this story bring to light the fact that there's a bug in Opera, but it illustrates how Opera prefers to handle security bugs: by covering them up.

      --
      Give me Classic Slashdot or give me death!
  11. Opera users by Tumbleweed · · Score: 2, Funny

    it places Opera users at unnecessary risk

    Yeah, both of them.

    1. Re:Opera users by bmartin · · Score: 2, Insightful

      I don't see why this is so funny. Opera's not that bad, and it does offer some things that aren't available by default in Firefox. Sure, it doesn't have the 400 extensions that FF does, but you don't have to screw around with it much. Opera has some really nifty features enabled OOTB that most people would overlook otherwise. It's also fast and it does a really good job with adhering to web standards.

      Yours is really a flamebait comment, and if there were a considerable number of Opera users with moderation points out there, I'm sure they'd overlook objectivity and mod you down.

      --
      "You could almost look at defense of Microsoft as a form of the Stockholm syndrome." -neapolitan
  12. Oprah screeches at Godzilla over Security! by jameskojiro · · Score: 5, Funny

    Best episode of Oprah ever!

    --
    Tsukasa: All I really want, is to be left alone...
  13. Was there an obigation? by deadmongrel · · Score: 2

    Why is Mozilla obligated to wait and release an advisory because Opera couldn't get off their asses fast enough to respond to something. Also, opera users were already at risk and not just because of the advisory.

    Offtopic: Did that opera guy ever swim from US to Norway? speak about obligations.

  14. Whats the big deal, just go fix it by KevMar · · Score: 2, Interesting

    Whats the big deal. Just go fix it.

    I know you don't have any people committed to different projects.
    I know you have your code at a stable point so its easy to slip in a change
    I know this only takes one guy 5 min to go change a few lines of code
    I know its ready to ship the moment its changed
    I know you coded it right and didn't break anything else

    Remember this is open source. so you should be able to fix all security issues quickly. I bet someone else had already done it for you. Just ask someone for it.

    Whats the point of being open source if you don't do what the community expects of you.

    END RANT

    OK, i bet the underlying issue is they expected to have a Little time. Emails went out to a few people that would look at and identify how big of an issue it was. Once they reported back, only the resources needed would be pulled off other projects to fix this.

    The next day they see the advisory without warning and now they scramble to figure it out. Probably pulled a lot of people off other stuff that they didn't need to in order to rush out a minimally tested release.

    --
    Im a gamer, not a grammer major. This post is full of spelling and grammer mistakes.
  15. ...it places Opera users at unnecessary risk? by iamacat · · Score: 3, Funny

    I would say it places Opera users at unnecessary risk of becoming Firefox users :-)

  16. Crap article by Tridus · · Score: 4, Insightful

    Somebody posting to Slashdot says that somebody at The Register says that an Opera blogger screeches about Mozilla. Even for Slashdot, this is a pretty weak title.

    What they actually say is that they only had a day between notification and public disclosure. He's actually happy that Mozilla told them at all (hence the :) ), but not happy that there was only a day before it was made public. Nobody is particularly happy when they only have a day from learning there's a security hole to everybody else learning about it, thats not enough time to get a fix rolled out, so this is hardly surprising.

    I know Mozilla can do no wrong around here, but come on. Even the Mozilla devs would be happier getting more then one day before public disclosure of a security hole.

    --
    -- "So they told me that using the download page to download something was not something they anticipated." - Bill Gates
    1. Re:Crap article by martin-boundary · · Score: 2, Insightful
      The security hole has been there for a long time. It didn't just appear in a puff of smoke when the Mozilla devs discovered it.

      Not announcing it means that the black hats get to use it for longer, and that's bad for millions of users. By contrast, delaying the announcement merely saves two or three develpers some embarrassment, at the cost of increased damage to everybody else.

      However you look at it, the benefits of delayed announcements don't add up.

  17. Re:insightful?? by Epsillon · · Score: 4, Interesting

    They've had twelve days to fix it. Have they? If you RTFA, you'll see not only have they not, they've expended a greater amount of energy trying to whip up support for their malcontent with Mozilla. So, in reply, yes it does seem that they would rather cover this up than fix the issue in a timely manner. Their actions scream it, even if TFA doesn't.

    --
    Resistance is futile. Reactance buggers it up.
  18. Re:Could a coder please weigh in? by Allador · · Score: 4, Insightful

    The problem usually isnt coding time. It's organizational response and resource allocation issues.

    For example, Opera is on a very differen timezone from the US, so initial publication may happen overnight from the POV of the Opera staff.

    So then a day starts. When people start their day, they have a pile of things to respond to. The incoming messsages have to be triaged. Someone has to make a decision that this is important enough to escalate or take action on.

    Then you have to find people with the capability to test whether its a real problem. This may take a couple hours. People go on vacation, get sick, etc.

    Then you have to take the time to do the research, test whether this is a real problem, what versions it affects, etc. This takes a couple hours.

    Then yuou have to stop a coder from working on something else, bring them up to speed on the problem (if its not the same person doing the testing), and get them started on the fix.

    Then even with a fix you have to do regression tests. Not sure about Opera, but many mature apps have full test suites that can take a couple hours.

    Then you have to write release notes, update the web page, do a new deploy package, and update your update servers to notify Opera that there is a new update.

    As you can see, very little of the time here is coding.

    Many large orgs have taken steps to create a 'short path of decision making' to streamline this process, always have one coder on call who can do this work, etc. But even then if anything is out of whack or the wrong person is sick or on vacation or on another urgent item, a whole day could pass without response.

  19. Re:Fanboys by mdwh2 · · Score: 3, Insightful

    Yeah, it's not like Firefox has any fanboys...

    So I took a look at the last story about Firefox bugs. And guess what - you have people criticising the person for making the bug public in a way not helpful to the developers. And do I hear "crybaby"? No, instead it gets modded up to +4.

  20. Re:insightful?? by Rudolf · · Score: 3, Informative
    where does it say they had twelve days to fix it?

    From TFA:

    Mozilla fixed the flaw, along with other more serious bugs, with the release of Firefox 2.0.0.12 on 7 February. Opera, which is yet to plug the moderate risk flaw, objected to the Mozilla team publishing an advisory on the issue.
    Claudio Santambrogio, an Opera desktop developer, said the Mozilla team notified it of a security issue only a day before publishing an advisory.


    Opera was notified the day before the February 7 release - that would be February 6. Today is February 18. Is that not 12 days?

  21. Re:insightful?? by Epsillon · · Score: 2, Informative

    where does it say they had twelve days to fix it?
    God's teeth, man! Have you really read the article? The vulnerability was reported to Opera a day before Fx 2.0.0.12 was released with full disclosure of Fx and Seamonkey bugs (no mention whatsoever of Opera) on the 7th. It is now the 18th. 18th - 6th = 12. Instead of keeping schtum and coding a fix, they chose to shoot themselves in the foot by disclosing that Opera had this vulnerability and it was the big, bad Mozilla Foundation's fault that it was disclosed because they fixed the browser that has 27% market share and growing [1] in Europe and told people what they had fixed. Nowhere did Mozilla, or anyone else, mention that Opera was vulnerable. I didn't even know, despite being subscribed to a number of vulnerability reporting lists, until they opened their mouths and took a swipe at Mozilla. I know now, of course. Why do you think that is?

    The whole point of this entire debacle is that Opera themselves disclosed this and, by complaining about full disclosure, showed their true colours when it comes to vulnerabilities in their flagship browser. Mozilla reported the vulnerability in a professional manner to a competitor to whom they owe nothing but felt ethically it was the right thing to do, then fixed their own product. Opera's actions in this matter show me quite clearly what they would have preferred to do but perhaps I'm just a raving zealot or a tin-foil hatter seeing conspiracies where none exist. There again, perhaps not. Feeling lucky? I hope you are, since you're betting, with apparently very little information, that Opera fixes the bugs in its software instead of simply sitting on reports from security experts trying to do the right thing. Security experts and competitors who may just think twice before submitting findings to Opera in the future.

    [1] 94% of statistics are pulled from someone's behind. Suffice to say a significant portion of the web browsing public use Fx. My analog shows it to be much, much higher but my web server hosts predominantly open source software, so that's to be expected.
    --
    Resistance is futile. Reactance buggers it up.
  22. Re:Could a coder please weigh in? by PlusFiveTroll · · Score: 2, Insightful

    Yep, it sucks to be big. If the person that found the exploit logs on to IRC and posts it, instead of mailing the authors of the code, how much time do you think they have before a new trojan or malicious attack websites are setup. I'd make a guess it's under an hour. As the application developer you have to take what you're given. Your enemy is not going to give you any quarter. They are not going to wait around for you to patch your apps and distribute them. The ball is in the blackhats hand, all you can hope to do is react fast enough.

  23. screeches? by sentientbrendan · · Score: 3, Insightful

    >Opera Screeches at Mozilla Over Security Disclosure

    Common, can we get article titles and summaries that don't *immediately* tell us about how we should feel about an article before even telling us the circumstances?

    I mean, give me a break, this is a lower standard of reporting than even fox news uses. For *once* I'd like to see a slashdot editor try to be objective, and let the reader make up our own mind instead of trying to spoon feed us our opinions.

    1. Re:screeches? by n6kuy · · Score: 2, Funny

      > Common, can we get article titles and summaries
      > that don't *immediately* tell us about how we should
      > feel about an article before even telling us the circumstances?

      What?
      You want me to RTFA before drawing conclusions?
      You must be new here....

      --
      If you disagree with me on social issues, then it's pretty clear that you are a narrow-minded bigot.
  24. But you've missed the point... by Half-pint+HAL · · Score: 5, Insightful

    That obligation is trumped by Mozilla's moral obligation to make sure that people who use Mozilla are not vulnerable to an exploit.

    No one is suggesting that Mozilla should have delayed the fix (in order to hold back disclosure).

    No, it would have been open and responsible and good if someone at Mozilla had thought to send an email to the Opera dev team a week or two ago saying:

    Roses are red, violets are blue
    We're fixing this exploit and think you should too.
    Lots of Love,
    Your secret big red monster Valentine.

    No need to coordinate releases, but given that it took them a while to patch it, they should assume it'll take Opera a wee while to, and in the meantime they're leaving members of the public open to exploit.

    Members of the public that used to use Firefox, but had to stop because Mozilla never fixed the memory leak and these users were using old machines (NT4, 32 meg RAM) and Open Source was supposed to mean never being obsolete, but it was only the non-open, free Opera browser that offered me a fully-patched, fully working browser.

    HAL.

    --
    Got them moderator blues I blieve I walk out the do', With these mod-points I been gettin', I 'most never post no mo'
  25. TFA didn't mention Opera at all... by Ikar_rb · · Score: 2, Interesting

    I call BS on Opera's complaint. I just read Mozilla's security advisory, and it makes no mention of Opera. So sorry- Mozilla checked and saw Opera was vulnerable to the same exploit and shot them a heads up to let them know about it. Mozilla has ZERO obligation to the Opera folks, so that was being nice. If their advisory had mentioned Opera, there would be something to complain about. As it stands, all Opera's complaint accomplished was advertising to the world that their browser was vulnerable and unpatched. Smart people indeed.