Page is a not externally linkable
- Code, Content, and Presentation
-- HTML
---- Microsoft Prepares "Out of Band" Patch for Internet Explorer


encyclo - 1:56 am on Jan 23, 2010 (gmt 0)


This patch has certainly been rushed.

OK, I'll take it all back, because MS knew of Aurora exploit four months before Google attacks [theregister.co.uk]:

Microsoft first knew of the bug used in the infamous Operation Aurora IE exploits as long ago as August, four months before the vulnerability was used in exploits against Google and other hi-tech firms in December, it has emerged. (...) BugSec's bulletin states that it reported the bug to the software giant on 26 August.

So MS has had months to prepare their patch. Of course, this means that "my biggest concern" is not the patch quality, but the five months that MS sat on their hands before being forced into releasing a solution, only due to the pressure of bad publicity.

Google-haters might suggest that Google's timing also served to discredit IE security compared to Chrome. I mean, Google probably knew the patch was ready and expected in February, so why not hurt MS by jumping the gun on an IE zero-day? I'll let others flesh out the conspiracy theory ;)


Thread source:: http://www.webmasterworld.com/html/4063811.htm
Brought to you by WebmasterWorld: http://www.webmasterworld.com