Live data from Hacker News

Google warns about two iOS zero-days 'exploited in the wild'

zdnet.com

1–10 of 89 posts

Re: Google warns about two iOS zero-days 'exploited in the wild'

#3
I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional.

I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public.

How fast do you think I would get sued if I found a zero day in a Google product, told Google to fix it, shove the bounty, and then went public 30 days later?

Re: Google warns about two iOS zero-days 'exploited in the wild'

#5
post #3

I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…

Has this ever happened with Google or is it pure speculation?

Re: Google warns about two iOS zero-days 'exploited in the wild'

#6
post #3

I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…

They're using iPhones themselves inside of the company, trusting the devices as part of their Beyond Corp security mechanism, so they have an interest in the software trusted to their company network being as secure as possible.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#7
post #3

I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…

I hold the more unpopular opinion the "Responsible" Disclosure is anything but, and everything should be fully disclosed in real time

If I was running project zero I would not even give them the 30/90 days

Full Disclosure is the best way

Re: Google warns about two iOS zero-days 'exploited in the wild'

#8
post #3

I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…

They're using iPhones themselves inside of the company, trusting the devices as part of their Beyond Corp security mechanism, so they have an interest in the software trusted to their company network being as secure as possible.

And we don't?

I want my phone to be as secure as possible because I use it for work, but of course, since it's not brand new I can't get updates.

Re: Google warns about two iOS zero-days 'exploited in the wild'

#9
post #3

I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…

> the most valuable company on Earth

Please edit to say "one of the most valuable companies on Earth," as it is absolutely not the most valuable (Market Cap). In fact, it's currently less than Apple. ($781B / $803B)

Re: Google warns about two iOS zero-days 'exploited in the wild'

#10
post #3

I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…

Do you have any actual examples of this happening?

It should be relatively easy to prove, by showing a disclosure from Project Zero without an accompanying acknowledgment/post from the company...

So far, most of what I've seen has been good for security. Not least the whole Spectre/Meltdown mess.

Post reply on HN