This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…
Why not? It really strengthens the message.
A walk through Project Zero metrics
11–20 of 62 posts
Re: A walk through Project Zero metrics
#12This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…
Why not? It really strengthens the message.
Re: A walk through Project Zero metrics
#13Earlier quoted context omitted.
Why not? It really strengthens the message.
I don't think it does strengthen the message, unless you think Google does such a good job responding to P0 that they're setting a standard Microsoft, Apple, and Adobe have to adhere to, and I think that's pretty debatable (the really important thing P0 does to set a standard is the 90 day deadline).
Re: A walk through Project Zero metrics
#14This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…
Could you expand more on why? At least to me, it seems like there's no downside to publicly tracking responses from Google itself. Ideally P0 should operate mostly independently. Agreed that there should be more P0 like efforts from other companies though. The more the merrier.
Google is, of course, ethically obligated to rigorously test its own products, and if P0 has expertise that the other security orgs at Google lacks, it's ethically obligated to train that expertise on Google products. I'm just saying that Google isn't ethically obligated to include itself in its vendor tracking statistics.
Re: A walk through Project Zero metrics
#15This will sound very weird, but I kind of hate that they include Google among the vendors they report to, provide a deadline and grace period for, and track responses from. It's actually not their responsibility to do anything like that; if Microsoft and Apple are unhappy that P0 is targeting them, they should respond by standing up their own P0 teams and hammering Google, rather than having everyone operate under th…
Re: A walk through Project Zero metrics
#16Earlier quoted context omitted.
Could you expand more on why? At least to me, it seems like there's no downside to publicly tracking responses from Google itself. Ideally P0 should operate mostly independently. Agreed that there should be more P0 like efforts from other companies though. The more the merrier.
I guess I'd start by saying I don't see the advantage to P0 operating independently. Threads about P0 often devolve into debates about conflicts of interest, but there's no conflict here; every vendor has in principle the right to conduct lawful vulnerability research against other vendors, including competitors, and there's no ethical standard that dictates what those vendors should choose to target. Google is, of c…
Re: A walk through Project Zero metrics
#17Re: A walk through Project Zero metrics
#18What was the most serious vulnerability or set of vulnerabilities identified by Project Zero?
Re: A walk through Project Zero metrics
#19Earlier quoted context omitted.
Could you expand more on why? At least to me, it seems like there's no downside to publicly tracking responses from Google itself. Ideally P0 should operate mostly independently. Agreed that there should be more P0 like efforts from other companies though. The more the merrier.
I guess I'd start by saying I don't see the advantage to P0 operating independently. Threads about P0 often devolve into debates about conflicts of interest, but there's no conflict here; every vendor has in principle the right to conduct lawful vulnerability research against other vendors, including competitors, and there's no ethical standard that dictates what those vendors should choose to target. Google is, of c…
Re: A walk through Project Zero metrics
#20For all software & hardware vendors, this will help raise the standards & revenue but it will also raise the barrier to entry for new entrants as sole developers or small teams will have to consider more than the basic function of their app/project/hw. Legislation like GDPR already means some projects may never get to fly today as regulatory burden is too great, and the bug front is another domain which is maturing adding to the burden.