Live data from Hacker News

About the security content of Security Update 2018-001

support.apple.com

1–10 of 18 posts

Re: About the security content of Security Update 2018-001

#7

For anyone unfamiliar with Project Zero, it's a team at Google dedicated to finding security vulnerabilities across the internet (and in software in general, it seems) https://security.googleblog.com/2014/07/announcing-project-z...

Some high profile exploits they either discovered or played a big role in:

- SHAttered(?)

- Row hammer

- Cloudbleed

- Lastpass exploit

- Meltdown & Spectre

Re: About the security content of Security Update 2018-001

#8
post #5

What is with this title ? It's a result of two CVEs.

In the support article Apple is crediting one of the CVEs “CVE-2018-4206: Ian Beer of Google Project Zero”

Title could still be better than it is, I think. Original title is much better. Things like attribution can be done fine in the comments if that's not in the title.

Furthermore, Project Zero was involved in only one of the CVEs anyway then. Why not put the other credit in the title too? CVE-2018-4187: Zhiyang Zeng (@Wester) of Tencent Security Platform Department, Roman Mueller (@faker_)

Post reply on HN