Earlier quoted context omitted.
In the support article Apple is crediting one of the CVEs “CVE-2018-4206: Ian Beer of Google Project Zero”
Title could still be better than it is, I think. Original title is much better. Things like attribution can be done fine in the comments if that's not in the title. Furthermore, Project Zero was involved in only one of the CVEs anyway then. Why not put the other credit in the title too? CVE-2018-4187: Zhiyang Zeng (@Wester) of Tencent Security Platform Department, Roman Mueller (@faker_)
About the security content of Security Update 2018-001
11–18 of 18 posts
Re: About the security content of Security Update 2018-001
#12Google's PR machine strikes again, robbing Tencent of their due.
Re: About the security content of Security Update 2018-001
#13Re: About the security content of Security Update 2018-001
#14For anyone unfamiliar with Project Zero, it's a team at Google dedicated to finding security vulnerabilities across the internet (and in software in general, it seems) https://security.googleblog.com/2014/07/announcing-project-z...
Some high profile exploits they either discovered or played a big role in: - SHAttered(?) - Row hammer - Cloudbleed - Lastpass exploit - Meltdown & Spectre
Re: About the security content of Security Update 2018-001
#15For anyone unfamiliar with Project Zero, it's a team at Google dedicated to finding security vulnerabilities across the internet (and in software in general, it seems) https://security.googleblog.com/2014/07/announcing-project-z...
Some high profile exploits they either discovered or played a big role in: - SHAttered(?) - Row hammer - Cloudbleed - Lastpass exploit - Meltdown & Spectre
> This result is the product of a long term collaboration between the Cryptology Group at Centrum Wiskunde & Informatica (CWI) - the national research institute for mathematics and computer science in the Netherlands - and the Google Research Security, Privacy and Anti-abuse Group. [...]
Re: About the security content of Security Update 2018-001
#16People need some kind of pointer about _why_ they might want to read a security update statement.
Granted the original title should have included Tencent's name too.
Re: About the security content of Security Update 2018-001
#17Earlier quoted context omitted.
Some high profile exploits they either discovered or played a big role in: - SHAttered(?) - Row hammer - Cloudbleed - Lastpass exploit - Meltdown & Spectre
Would be good to also highlight the other finders of some of these issues, but this view shows that Google Project Zero is a well executed PR machine taking away the focus of other security researchers. The title of this thread is similarly misleading.
Re: About the security content of Security Update 2018-001
#18Earlier quoted context omitted.
Some high profile exploits they either discovered or played a big role in: - SHAttered(?) - Row hammer - Cloudbleed - Lastpass exploit - Meltdown & Spectre
Why a question mark behind SHAttered? > This result is the product of a long term collaboration between the Cryptology Group at Centrum Wiskunde & Informatica (CWI) - the national research institute for mathematics and computer science in the Netherlands - and the Google Research Security, Privacy and Anti-abuse Group. [...]