Google warns about two iOS zero-days 'exploited in the wild'
1–10 of 89 posts
Re: Google warns about two iOS zero-days 'exploited in the wild'
#2Kudos to Google.
Re: Google warns about two iOS zero-days 'exploited in the wild'
#3I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public.
How fast do you think I would get sued if I found a zero day in a Google product, told Google to fix it, shove the bounty, and then went public 30 days later?
Re: Google warns about two iOS zero-days 'exploited in the wild'
#4If your threat model depends on something like this, plan for it.
As long as there are computers, there will be zero-days.
Re: Google warns about two iOS zero-days 'exploited in the wild'
#5I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…
Re: Google warns about two iOS zero-days 'exploited in the wild'
#6I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…
Re: Google warns about two iOS zero-days 'exploited in the wild'
#7I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…
If I was running project zero I would not even give them the 30/90 days
Full Disclosure is the best way
Re: Google warns about two iOS zero-days 'exploited in the wild'
#8I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…
They're using iPhones themselves inside of the company, trusting the devices as part of their Beyond Corp security mechanism, so they have an interest in the software trusted to their company network being as secure as possible.
I want my phone to be as secure as possible because I use it for work, but of course, since it's not brand new I can't get updates.
Re: Google warns about two iOS zero-days 'exploited in the wild'
#9I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…
Please edit to say "one of the most valuable companies on Earth," as it is absolutely not the most valuable (Market Cap). In fact, it's currently less than Apple. ($781B / $803B)
Re: Google warns about two iOS zero-days 'exploited in the wild'
#10I hold the unpopular opinion that Google Project Zero is pretentious and unprofessional. I mean here we have the most valuable company on Earth, specifically scoping out competing software and hardware constantly looking for zero day vulnerabilities. They don't submit to the bug bounty, so if they have a disclosure that you disagree with you better agree quick because they'll just go public. How fast do you think I w…
It should be relatively easy to prove, by showing a disclosure from Project Zero without an accompanying acknowledgment/post from the company...
So far, most of what I've seen has been good for security. Not least the whole Spectre/Meltdown mess.