Live data from Hacker News

A walk through Project Zero metrics

googleprojectzero.blogspot.com

1–10 of 62 posts

Re: A walk through Project Zero metrics

#2
I dislike many aspects of google, but project zero is not one of them and has greatly improve the overall security of the industry.

Also their blogs describing how security exploits work are always super interesting

Re: A walk through Project Zero metrics

#4
post #3

Is it meaningful to include "Linux" as a discrete vendor? How would you compare an OSS project to a company like Microsoft or Google?

The Linux Kernel is a product and the Linux Foundation is it‘s vendor. I would assume they mean Them. Especially when they had Red Hat and Cannonical in „other“

Re: A walk through Project Zero metrics

#6
that iOS vs Android table kinda makes no sense as they said

iOS 76, Android Samsung 10, Android Pixel 6

>The first thing to note is that it appears that iOS received remarkably more bug reports from Project Zero than any flavor of Android did during this time period, but rather than an imbalance in research target selection, this is more a reflection of how Apple ships software. Security updates for "apps" such as iMessage, Facetime, and Safari/WebKit are all shipped as part of the OS updates, so we include those in the analysis of the operating system. On the other hand, security updates for standalone apps on Android happen through the Google Play Store, so they are not included here in this analysis.

so kinda what's the point of putting that column there? people will use it as an argument that Android is safer :P

Re: A walk through Project Zero metrics

#7

that iOS vs Android table kinda makes no sense as they said iOS 76, Android Samsung 10, Android Pixel 6 >The first thing to note is that it appears that iOS received remarkably more bug reports from Project Zero than any flavor of Android did during this time period, but rather than an imbalance in research target selection, this is more a reflection of how Apple ships software. Security updates for "apps" such as iM…

There are advantages and disadvantages to bundling applications with the core OS; having these security bugs become part of the OS release vehicle (along with the heavyweight process that implies) seems like a disadvantage. With respect to the table, I think there’s a decent argument either way.

Re: A walk through Project Zero metrics

#8
This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under the fiction that it's OK for Google to be the only major vendor doing this work.

(I'm of course not saying P0 shouldn't target Google, just that Google shouldn't have to be publicly accountable to Google P0).

Re: A walk through Project Zero metrics

#9
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

Why not? It really strengthens the message.

Re: A walk through Project Zero metrics

#10
post #8

This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…

Could you expand more on why?

At least to me, it seems like there's no downside to publicly tracking responses from Google itself. Ideally P0 should operate mostly independently.

Agreed that there should be more P0 like efforts from other companies though. The more the merrier.

Post reply on HN